Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsHard

A security engineer is troubleshooting an issue where a remote user, connected via GlobalProtect, is unable to access internal resources. The user authenticates successfully and receives an IP address from the VPN pool. The firewall logs show that traffic from the user's assigned IP address is being dropped with a 'deny' action, but the security policy allowing access is configured correctly for the user group. Which of the following is the most likely cause of this issue?

  1. AIncorrect NAT policy configuration on the firewall.
  2. BThe user's HIP profile is not matching the security policy's requirements.
  3. CThe DHCP server is not assigning the correct DNS servers to the VPN client.
  4. DThe GlobalProtect gateway is not configured with the correct tunnel interface.
Show answer & explanation

Correct answer: B. The user's HIP profile is not matching the security policy's requirements.

Even if a user authenticates successfully and is part of the correct group, a Host Information Profile (HIP) check can still deny access if the endpoint does not meet specific security posture requirements defined in the security policy. The 'deny' action in the logs, despite a matching 'allow' policy for the user group, strongly suggests a HIP mismatch.

Why the other options are wrong

  • A. NAT issues would typically manifest as connectivity problems to specific destinations, not a general 'deny' for internal resources when the user is already connected.
  • C. Incorrect DNS would cause name resolution failures, not a firewall 'deny' action on the data plane.
  • D. An incorrect tunnel interface would prevent VPN establishment or IP assignment, which is not the case here.

GlobalProtect HIP Check

A feature of GlobalProtect that assesses the security posture of an endpoint (Host Information Profile) and enforces policies based on its compliance.

  • Evaluates endpoint security posture
  • Can include OS, antivirus, patch level checks
  • Used to enforce conditional access policies

Memory trick: Remote access needs more than just a key; the door checks your whole outfit.

More Core Concepts questions