Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationHard

A company is deploying a new internal web application that uses a custom TCP port 8080. Internal users need to access this application, but a penetration test revealed that the default 'allow-all-internal' rule historically used for internal traffic is too broad. The security team wants to create a specific security policy rule for this application, ensuring it's only accessible via its intended application and port, and that all security profiles are applied. Which combination of 'Application' and 'Service' objects should be used in the new security policy rule?

  1. AApplication: 'any', Service: 'service-tcp-8080'
  2. BApplication: 'custom-web-app' (a custom App-ID), Service: 'service-tcp-8080'
  3. CApplication: 'web-browsing', Service: 'application-default'
  4. DApplication: 'web-browsing', Service: 'service-tcp-8080'
Show answer & explanation

Correct answer: C. Application: 'web-browsing', Service: 'application-default'

For internal web applications on non-standard ports, 'web-browsing' as the application and 'application-default' as the service is often the best choice. This allows App-ID to correctly identify the HTTP/HTTPS traffic as 'web-browsing' even on port 8080 and ensures all relevant security profiles (like URL Filtering, Threat Prevention) are applied, providing granular control beyond just port-based access. Creating a custom App-ID is more complex and usually reserved for truly unique, non-standard protocols, not just a standard web app on a custom port.

Why the other options are wrong

  • A. Using 'any' for the application is too broad and defeats the purpose of granular App-ID control, potentially allowing other applications on port 8080 that are not intended.
  • B. While a custom App-ID ('custom-web-app') could work, it's generally overkill for a standard web application simply running on a non-standard port. 'web-browsing' with 'application-default' achieves the same security benefits with less configuration overhead for standard web traffic.
  • D. Using 'web-browsing' with 'service-tcp-8080' is problematic. If the firewall sees traffic on port 8080 and the service is explicitly set to that port, App-ID might not be able to fully identify it as 'web-browsing' if the application isn't explicitly tied to that port, or it might not apply all 'web-browsing' specific security profiles as effectively as 'application-default' would allow.

App-ID with Application-Default for Custom Ports

When a standard application (like HTTP/HTTPS) runs on a non-standard port, configuring the security policy with the specific App-ID (e.g., 'web-browsing') and the 'application-default' service object ensures the firewall correctly identifies the application and applies all relevant security profiles.

  • Leverages App-ID's deep packet inspection for accurate identification.
  • Enables full security profile enforcement even on non-standard ports.
  • Avoids creating unnecessary custom service objects or custom App-IDs for standard protocols.

Memory trick: App-ID Knows, Port Doesn't Show.

More Security Policy Configuration questions