A network administrator is reviewing the packet flow on a Palo Alto Networks firewall and notices that some packets are being dropped due to a 'deny' action in a security policy. At which stage of the packet flow does the firewall typically apply security policies to determine whether to allow or deny traffic?
- AFast Path
- BSession Setup
- CSlow Path
- DIngress Stage
Show answer & explanationAnswer & explanation
Correct answer: B. Session Setup
Security policies are applied during the 'Session Setup' stage of the packet flow. When the first packet of a new session arrives, the firewall performs a comprehensive lookup against its security policies. If a policy matches and allows the traffic, a session is established and subsequent packets for that session can be fast-pathed. If a policy matches and denies the traffic, the session is not established, and the packet (and subsequent packets) are dropped.
Why the other options are wrong
- A. The Fast Path is for subsequent packets of an already established session, bypassing full policy lookup and reducing latency.
- C. The Slow Path is where deep packet inspection and advanced security services (like Antivirus, WildFire) are applied, but the initial allow/deny decision based on security policy is made earlier.
- D. Ingress stage involves initial checks like zone, interface, and basic sanity checks, but not the full security policy evaluation for allow/deny.
Palo Alto Packet Flow - Session Setup
During the Session Setup stage of the Palo Alto Networks packet flow, the firewall performs a comprehensive lookup against its security policies and creates a session if traffic is allowed, or drops it if denied.
- Occurs for the first packet of a new connection.
- App-ID, Content-ID, User-ID are applied.
- Determines allow/deny based on security policies.
Memory trick: First, Setup the Session, then Speed on the Fast Path.