Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationEasy
A network security administrator is configuring a new security policy rule to allow internal users to access a newly deployed internal web application. The application uses a non-standard TCP port 8080. Which service object should the administrator use in the security policy rule to ensure only this specific application traffic is permitted?
- Aservice-http
- Bany
- Capplication-default
- Dtcp-8080
Show answer & explanationAnswer & explanation
Correct answer: D. tcp-8080
To allow traffic on a specific non-standard port for a new application without relying on App-ID or allowing all traffic, a custom service object defining that port is the most precise method. 'application-default' would use App-ID recognized ports, and 'any' would be too broad.
Why the other options are wrong
- A. 'service-http' typically refers to TCP port 80, not 8080, and would not match the application's port.
- B. Using 'any' would permit all types of traffic on any port, which is not specific enough for the requirement.
- C. 'application-default' allows traffic only on the standard ports associated with applications identified by App-ID, which might not include a non-standard port 8080 without a custom App-ID.
Custom Service Objects
Custom service objects define specific port and protocol combinations for use in security policies, allowing granular control over non-standard application traffic.
- Used for applications running on non-standard ports.
- Overrides App-ID's default port recognition for specific rules.
- Provides granular control over allowed traffic.
Memory trick: Service objects define the specific 'door' and 'language' for traffic.