Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationHard

A security engineer has configured a security policy rule to allow SSH access to internal servers from a jump box. However, the engineer also wants to prevent any other applications from using the SSH port (TCP 22) to bypass the firewall. What is the most effective way to achieve this using App-ID and service objects?

  1. ASet 'Application' to 'ssh' and 'Service' to 'service-tcp-22'.
  2. BSet 'Application' to 'any' and 'Service' to 'service-tcp-22'.
  3. CSet 'Application' to 'ssh' and 'Service' to 'application-default'.
  4. DSet 'Application' to 'ssh' and 'Service' to 'any'.
Show answer & explanation

Correct answer: C. Set 'Application' to 'ssh' and 'Service' to 'application-default'.

To prevent application bypass, you must use App-ID. Setting 'Application' to 'ssh' ensures only SSH traffic is allowed. Then, setting 'Service' to 'application-default' further restricts the 'ssh' application to its standard port (TCP 22), effectively preventing other applications from using port 22 even if they try to masquerade as SSH or use the port for non-SSH traffic.

Why the other options are wrong

  • A. While specifying 'service-tcp-22' for the service object works, 'application-default' is more robust as it's directly tied to the application's standard ports and prevents misconfigurations if the standard port were to change (though unlikely for SSH). It's also the best practice recommended by Palo Alto Networks.
  • B. Using 'Application: any' allows *any* application on port 22, defeating the purpose of App-ID to prevent bypass.
  • D. Using 'Service: any' would allow the 'ssh' application on *any* port, which isn't the requirement for restricting to port 22.

App-ID and Application-Default Service for Strict Enforcement

Combining a specific App-ID with the 'application-default' service setting provides the strictest enforcement, ensuring only the intended application runs on its standard ports, preventing protocol and port evasion.

  • App-ID identifies the true application regardless of port.
  • 'application-default' service restricts the identified application to its standard ports.
  • This combination prevents other applications from using standard ports to bypass security.
  • It's a foundational best practice for granular application control.

Memory trick: App-ID with default service is the lock and key, ensuring traffic is what it's meant to be.

More Security Policy Configuration questions