Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium
A technician is configuring a security policy rule to allow access to a new internal web application. The application uses a non-standard TCP port 8080. When configuring the security policy, the technician sets the 'Application' to 'web-browsing' and the 'Service' to 'application-default'. After committing the configuration, users report they cannot access the application. What is the most likely reason for this failure?
- AA NAT policy is misconfigured, preventing the traffic from reaching the application server.
- BThe firewall's App-ID engine has not yet downloaded the signature for 'web-browsing' on port 8080.
- CThe 'web-browsing' application only uses TCP port 80 and TCP port 443, not 8080 by default.
- DThe 'application-default' service is implicitly denying the connection because App-ID cannot identify 'web-browsing' on port 8080.
Show answer & explanationAnswer & explanation
Correct answer: C. The 'web-browsing' application only uses TCP port 80 and TCP port 443, not 8080 by default.
When 'application-default' is selected for the service, the firewall will only allow the specified application (web-browsing) on its *standard* ports (TCP 80 for HTTP and TCP 443 for HTTPS). Since the application uses a non-standard port 8080, 'application-default' will not match, causing the traffic to be blocked.
Why the other options are wrong
- A. A NAT misconfiguration would prevent routing, but the question implies the policy itself is the issue due to the 'Service' setting, not upstream routing.
- B. App-ID signatures are generally for identifying applications, not for defining what ports they *should* use. 'web-browsing' is a well-known application.
- D. App-ID can identify applications on non-standard ports, but the 'application-default' service setting explicitly restricts it to standard ports. The identification itself isn't the issue, but the service constraint.
Application-Default Service
The 'application-default' service setting in a Palo Alto Networks security policy restricts traffic for the specified App-ID to its standard, well-known ports.
- Ensures applications only run on their expected ports.
- Provides a more secure configuration by preventing protocol evasion.
- If an application uses a non-standard port, 'application-default' will block it.
- To allow non-standard ports, a custom service object or 'any' service must be used (less recommended).
Memory trick: App-ID is the lock, service is the key, 'application-default' is the factory setting.