Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationHard

A network security engineer is tasked with optimizing the security policy rulebase for performance. The engineer identifies several rules that allow traffic for common applications like 'web-browsing' and 'ssl' to various destinations, but these rules do not apply any security profiles. Which best practice should the engineer follow to improve performance without compromising security for this type of traffic?

  1. AChange the action to 'deny' for these rules to explicitly block unwanted traffic.
  2. BMove these rules to the top of the rulebase to ensure quick matching.
  3. CAdd the 'any' application to these rules and apply a Security Profile Group.
  4. DConfigure these rules to use the 'application-default' service and apply relevant security profiles.
Show answer & explanation

Correct answer: D. Configure these rules to use the 'application-default' service and apply relevant security profiles.

For common applications like 'web-browsing' and 'ssl', using 'application-default' for the service automatically maps to the correct ports (80/443 respectively), preventing the need for the firewall to perform service-mapping lookups. Combining this with relevant security profiles ensures inspection while optimizing performance by reducing processing overhead. Moving rules without security profiles to the top would be a security risk.

Why the other options are wrong

  • A. Changing to 'deny' would block legitimate traffic, which is not the goal of optimization.
  • B. Moving rules without security profiles to the top is a security risk, as malicious traffic could pass uninspected quickly.
  • C. Adding 'any' application is a security risk; it allows all applications over the specified ports, losing the benefit of App-ID. Applying a Security Profile Group is good, but 'any' application is not optimal.

App-ID and Application-Default Service

Using 'application-default' as the service in a security policy rule allows App-ID to automatically determine the correct ports and protocols for the identified application, optimizing rule processing.

  • Enhances security by ensuring traffic matches the correct application.
  • Improves performance by reducing firewall lookup overhead.
  • Works best when combined with security profiles for inspection.

Memory trick: Optimize Rules: App Default, Profile Strong.

More Security Policy Configuration questions