Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsEasy

A network security administrator is configuring a new Palo Alto Networks firewall to protect a data center. The administrator needs to ensure that only legitimate HTTP and HTTPS traffic is allowed, while blocking other applications attempting to use ports 80 and 443. Which security policy best practice should be applied?

  1. AConfigure a security policy with 'service' set to 'application-default' and 'application' set to 'web-browsing' and 'ssl'.
  2. BConfigure a security policy with 'service' set to 'tcp/80, tcp/443' and 'application' set to 'any'.
  3. CConfigure a security policy with 'service' set to 'any' and 'application' set to 'web-browsing' and 'ssl'.
  4. DConfigure a security policy with 'service' set to 'application-default' and 'application' set to 'any'.
Show answer & explanation

Correct answer: A. Configure a security policy with 'service' set to 'application-default' and 'application' set to 'web-browsing' and 'ssl'.

To ensure that only legitimate HTTP and HTTPS traffic is allowed on their standard ports, the 'service' should be set to 'application-default'. This allows the firewall to identify the actual application regardless of the port it's trying to use and enforce the policy accordingly, preventing port hopping or misuse. The 'application' should be explicitly set to 'web-browsing' and 'ssl' to restrict traffic to these specific applications.

Why the other options are wrong

  • B. Setting 'service' to 'tcp/80, tcp/443' and 'application' to 'any' would allow any application to use these ports, completely bypassing application identification.
  • C. Setting 'service' to 'any' would allow any application to use ports 80/443 if the 'application' matches, defeating the purpose of strict application control.
  • D. Setting 'application' to 'any' would allow any application to pass if the service port matches its default, which might not be what the administrator intends for specific ports like 80/443.

Application-Default Service

The 'application-default' service setting in a Palo Alto Networks firewall security policy ensures that an application is allowed only on its standard, well-known ports, preventing port hopping or non-standard port usage.

  • Enforces application identity based on standard ports.
  • Prevents applications from using non-standard ports to evade policies.
  • Used in conjunction with specific application definitions for granular control.

Memory trick: Always Default to the App's True Nature, not just the port.

More Core Concepts questions