A network administrator is configuring a new Palo Alto Networks firewall. The requirement is to allow internal users to access external web servers on standard HTTP/HTTPS ports, but block all other outbound traffic. Which of the following security policy rule configurations would achieve this with the principle of least privilege?
- ASource Zone: Trust, Destination Zone: Untrust, Application: web-browsing, ssl, Service: application-default, Action: allow
- BSource Zone: Trust, Destination Zone: Untrust, Application: ssl, web-browsing, Service: any, Action: allow
- CSource Zone: Trust, Destination Zone: Untrust, Application: any, Service: tcp/80, tcp/443, Action: allow
- DSource Zone: Trust, Destination Zone: Untrust, Application: any, Service: application-default, Action: allow
Show answer & explanationAnswer & explanation
Correct answer: A. Source Zone: Trust, Destination Zone: Untrust, Application: web-browsing, ssl, Service: application-default, Action: allow
To adhere to the principle of least privilege and allow only standard web browsing, the policy should specifically permit the 'web-browsing' and 'ssl' applications. Using 'application-default' for services ensures that the correct ports are used for those applications, preventing other applications from using those ports.
Why the other options are wrong
- B. Using 'Service: any' is too broad and allows any service to pass if the application matches, which is not aligned with least privilege for standard web traffic.
- C. This rule specifies services by port, which is less granular than using App-ID and can allow non-web traffic if it uses those ports.
- D. Using 'Application: any' is too broad and violates the principle of least privilege.
App-ID and Security Policy
Palo Alto Networks App-ID technology identifies applications traversing the network, regardless of port, protocol, or evasive tactics. Security policies should leverage App-ID for granular control.
- App-ID identifies applications based on multiple techniques (signatures, decryption, heuristics).
- Using App-ID in security policies provides more granular control than port-based policies.
- The 'application-default' service setting ensures that the policy only allows the identified application on its standard ports.
Memory trick: App-ID is your first line, then service, then action, keeping traffic aligned.