Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A network administrator needs to create a security policy rule to allow ping (ICMP echo request/reply) from the internal network to a specific server in the DMZ. However, the administrator wants to prevent any other ICMP types, such as timestamp requests or unreachable messages, from being permitted by this rule. Which application and service configuration should be used in the security policy rule?

  1. AApplication: 'ping', Service: 'icmp-echo'
  2. BApplication: 'any', Service: 'icmp-echo'
  3. CApplication: 'icmp', Service: 'any'
  4. DApplication: 'ping', Service: 'application-default'
Show answer & explanation

Correct answer: D. Application: 'ping', Service: 'application-default'

Palo Alto Networks firewalls leverage App-ID for application identification, even for protocols like ICMP. The 'ping' App-ID specifically identifies ICMP echo requests and replies. When 'application-default' is used as the service, the firewall dynamically uses the standard port/protocol for the identified application, which for 'ping' is ICMP type 8 (echo request) and type 0 (echo reply). This combination ensures only ping is allowed, excluding other ICMP types.

Why the other options are wrong

  • A. While 'ping' is the correct application, 'icmp-echo' is not a standard, pre-defined service object in Palo Alto Networks for ICMP echo. 'application-default' is the standard way to handle this with App-ID.
  • B. Using 'any' as the application would bypass App-ID for this rule and potentially allow other applications on ICMP, which is not desired. 'icmp-echo' as a service is also not standard.
  • C. Using 'icmp' as the application and 'any' as the service would permit all ICMP types, which is too broad.

App-ID for ICMP

Palo Alto Networks App-ID can identify specific types of ICMP traffic, such as 'ping', allowing granular control over ICMP in security policies beyond just allowing the entire protocol.

  • App-ID can differentiate between ICMP types (e.g., ping, traceroute, unreachable).
  • Using 'ping' App-ID allows only echo request/reply.
  • 'application-default' service works with App-ID to enforce standard ports/protocols.
  • More precise than port/protocol-only rules for ICMP.

Memory trick: Controlling ICMP with App-ID is like having a smart filter for radio signals: you only pick up 'ping' messages, ignoring all the other static.

More Security Policy Configuration questions