Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsEasy

A network administrator is reviewing the packet flow on a Palo Alto Networks firewall and notices that some packets are being dropped due to a 'deny' action in a security policy. At which stage of the packet flow does the firewall typically apply security policies to determine whether to allow or deny traffic?

  1. AFast Path
  2. BSession Setup
  3. CSlow Path
  4. DIngress Stage
Show answer & explanation

Correct answer: B. Session Setup

Security policies are applied during the 'Session Setup' stage of the packet flow. When the first packet of a new session arrives, the firewall performs a comprehensive lookup against its security policies. If a policy matches and allows the traffic, a session is established and subsequent packets for that session can be fast-pathed. If a policy matches and denies the traffic, the session is not established, and the packet (and subsequent packets) are dropped.

Why the other options are wrong

  • A. The Fast Path is for subsequent packets of an already established session, bypassing full policy lookup and reducing latency.
  • C. The Slow Path is where deep packet inspection and advanced security services (like Antivirus, WildFire) are applied, but the initial allow/deny decision based on security policy is made earlier.
  • D. Ingress stage involves initial checks like zone, interface, and basic sanity checks, but not the full security policy evaluation for allow/deny.

Palo Alto Packet Flow - Session Setup

During the Session Setup stage of the Palo Alto Networks packet flow, the firewall performs a comprehensive lookup against its security policies and creates a session if traffic is allowed, or drops it if denied.

  • Occurs for the first packet of a new connection.
  • App-ID, Content-ID, User-ID are applied.
  • Determines allow/deny based on security policies.

Memory trick: First, Setup the Session, then Speed on the Fast Path.

More Core Concepts questions