Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium
A network security engineer is configuring a new security policy rule on a Palo Alto Networks firewall. The requirement is to allow internal users to access an external web application that uses a non-standard TCP port 8443 for HTTPS traffic. Which service object should be used in the security policy rule to ensure proper application identification and security profile enforcement for this traffic?
- Aa custom service object for TCP 8443
- Bapplication-default
- Cservice-http
- Dservice-https
Show answer & explanationAnswer & explanation
Correct answer: B. application-default
Using 'application-default' as the service object allows the firewall to correctly identify the application (HTTPS) regardless of the port it's running on, and then apply relevant security profiles. This ensures that even though it's on a non-standard port, the traffic is treated as HTTPS.
Why the other options are wrong
- A. While a custom service object would allow TCP 8443, it would bypass App-ID's ability to identify the application as HTTPS, potentially leading to incorrect security profile application or lack of granular control.
- C. service-http is for standard HTTP traffic on port 80 and would not match HTTPS on 8443.
- D. service-https is for standard HTTPS traffic on port 443 and would not match HTTPS on 8443.
Application-Default Service
The 'application-default' service object in a Palo Alto Networks security policy rule instructs the firewall to use App-ID to determine the application and its default port, rather than relying solely on the port specified in the service object.
- Enables App-ID to identify applications running on non-standard ports.
- Ensures accurate application of security profiles.
- Recommended practice for most application-based security rules.
Memory trick: Default Application, Not Just Port Location.