Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A technician is configuring a security policy rule to allow access to a new internal web application. The application uses a non-standard TCP port 8080. When configuring the security policy, the technician sets the 'Application' to 'web-browsing' and the 'Service' to 'application-default'. After committing the configuration, users report they cannot access the application. What is the most likely reason for this failure?

  1. AA NAT policy is misconfigured, preventing the traffic from reaching the application server.
  2. BThe firewall's App-ID engine has not yet downloaded the signature for 'web-browsing' on port 8080.
  3. CThe 'web-browsing' application only uses TCP port 80 and TCP port 443, not 8080 by default.
  4. DThe 'application-default' service is implicitly denying the connection because App-ID cannot identify 'web-browsing' on port 8080.
Show answer & explanation

Correct answer: C. The 'web-browsing' application only uses TCP port 80 and TCP port 443, not 8080 by default.

When 'application-default' is selected for the service, the firewall will only allow the specified application (web-browsing) on its *standard* ports (TCP 80 for HTTP and TCP 443 for HTTPS). Since the application uses a non-standard port 8080, 'application-default' will not match, causing the traffic to be blocked.

Why the other options are wrong

  • A. A NAT misconfiguration would prevent routing, but the question implies the policy itself is the issue due to the 'Service' setting, not upstream routing.
  • B. App-ID signatures are generally for identifying applications, not for defining what ports they *should* use. 'web-browsing' is a well-known application.
  • D. App-ID can identify applications on non-standard ports, but the 'application-default' service setting explicitly restricts it to standard ports. The identification itself isn't the issue, but the service constraint.

Application-Default Service

The 'application-default' service setting in a Palo Alto Networks security policy restricts traffic for the specified App-ID to its standard, well-known ports.

  • Ensures applications only run on their expected ports.
  • Provides a more secure configuration by preventing protocol evasion.
  • If an application uses a non-standard port, 'application-default' will block it.
  • To allow non-standard ports, a custom service object or 'any' service must be used (less recommended).

Memory trick: App-ID is the lock, service is the key, 'application-default' is the factory setting.

More Security Policy Configuration questions