Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationHard

A security technician is troubleshooting an issue where users are unable to access an external cloud-based application, even though a security policy rule is configured to allow 'web-browsing' and 'ssl' applications from the internal network to the 'any' zone. The firewall logs show that the traffic is being allowed by the rule, but the application remains inaccessible. Upon further inspection, the application's unique App-ID is 'cloud-app-X'. What is the MOST likely reason for the application being inaccessible?

  1. AThe 'application-default' service is not selected in the security policy rule, preventing correct port mapping.
  2. BThe 'web-browsing' and 'ssl' App-IDs are too broad and are not catching the specific 'cloud-app-X' application.
  3. CThe firewall requires a Data Filtering profile to be attached to the security policy rule for cloud applications.
  4. DThe security policy rule needs to include a specific URL Filtering profile to allow the cloud application's domain.
Show answer & explanation

Correct answer: B. The 'web-browsing' and 'ssl' App-IDs are too broad and are not catching the specific 'cloud-app-X' application.

Palo Alto Networks firewalls identify applications using App-ID, which is more granular than just port numbers. While 'web-browsing' and 'ssl' App-IDs cover generic HTTP/HTTPS traffic, many specific cloud applications have their own unique App-IDs. If the unique App-ID 'cloud-app-X' is not explicitly allowed in the security policy rule, the firewall will not recognize and correctly handle the application traffic, even if general web traffic is allowed.

Why the other options are wrong

  • A. The 'application-default' service is used with App-ID to dynamically determine the correct ports. However, if the App-ID itself ('cloud-app-X') is not listed in the rule, then even 'application-default' wouldn't help, as the firewall wouldn't know which application's default ports to apply.
  • C. Data Filtering profiles are for preventing sensitive data loss, not for enabling basic application access.
  • D. While URL filtering is important, the logs show the traffic is being 'allowed by the rule', implying the initial policy match is occurring. The issue is likely with App-ID's granular recognition, not a URL block.

App-ID Granularity

Palo Alto Networks App-ID provides granular application identification beyond port numbers, allowing specific applications (even cloud-based ones) to be controlled with precision in security policies.

  • Identifies applications based on signatures, decryption, and heuristics.
  • More granular than port-based rules.
  • Specific App-IDs may be required for distinct cloud applications.
  • App-ID runs before policy rule matching.

Memory trick: App-ID is like a specialized detective: it knows the specific 'fingerprint' of each application, even if they share the same 'door' (port).

More Security Policy Configuration questions