Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsMedium

A network administrator observes that user traffic originating from the internal network and destined for the internet is being correctly identified by App-ID, but the associated Security Policy rule is not being matched. Upon inspection, it is noted that the Security Policy rule uses an 'Application' of 'web-browsing' and a 'Service' of 'application-default'. Which of the following is the most likely reason for the rule not matching?

  1. AThe web-browsing traffic is using a non-standard port that is not part of the 'application-default' service.
  2. BThe firewall does not have a valid license for App-ID.
  3. CThe security policy rule is placed below a broader 'any' rule that is matching the traffic first.
  4. DThe firewall is configured with an incorrect Security Zone for the internal interface.
Show answer & explanation

Correct answer: A. The web-browsing traffic is using a non-standard port that is not part of the 'application-default' service.

When an application (like web-browsing) uses a non-standard port, and the security policy specifies 'application-default' for the service, the rule will not match because 'application-default' only covers the standard ports for that application. If App-ID correctly identifies the application but the port is non-standard, the 'application-default' service will filter it out.

Why the other options are wrong

  • B. App-ID is a core feature and doesn't require a separate license for basic functionality; it's already identifying the traffic.
  • C. While rule order is critical, the scenario implies the rule is *not matching* for a specific reason, and 'application-default' is a common pitfall for non-standard ports.
  • D. Incorrect security zone would prevent any traffic from matching, not just specific application traffic.

Application-Default Service

In Palo Alto Networks security policies, 'application-default' for the service field restricts the rule to match traffic only if the identified application is using its standard port(s).

  • Tied to App-ID.
  • Only matches traffic on standard ports for the identified application.
  • Useful for enforcing application-specific port usage.

Memory trick: Default service? Only standard ports, no sports!

More Core Concepts questions