Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A network administrator is troubleshooting an issue where users are intermittently experiencing slow access to a web application hosted in a data center protected by a Palo Alto Networks firewall. The firewall logs show occasional 'deny' actions for the web application's traffic, indicating that not all traffic is being allowed consistently. The Security policy rule allowing the traffic has a 'service' configured as 'application-default'. Which action should the administrator take FIRST to diagnose the intermittent denials?

  1. AChange the service to 'any' in the Security policy rule.
  2. BCheck the application's default ports using 'show application <app-name>' CLI command.
  3. CCreate a new Security policy rule specifically for the web application.
  4. DExamine the traffic logs for the denied sessions to identify the specific service/port being denied.
Show answer & explanation

Correct answer: D. Examine the traffic logs for the denied sessions to identify the specific service/port being denied.

The 'application-default' service means the rule only matches traffic on the standard ports for the identified application. Intermittent denials suggest some traffic might be using non-standard ports or the application is being misidentified. Examining the denied traffic logs will reveal the exact port/protocol being denied, which is critical for understanding why 'application-default' is failing.

Why the other options are wrong

  • A. Changing to 'any' would likely fix the issue but bypasses the security benefit of App-ID and doesn't diagnose the root cause of the intermittent denials.
  • B. Checking default ports is useful, but the problem is likely non-default ports or misidentification, so examining denied traffic is more direct.
  • C. Creating a new rule without understanding the denied traffic might just duplicate the problem or introduce unnecessary complexity.

Application-Default Service

The 'application-default' service in a Palo Alto Networks Security policy rule restricts matching traffic to the standard ports and protocols associated with the identified application.

  • Requires accurate App-ID identification.
  • Traffic on non-standard ports for an application will be denied.
  • Troubleshooting often involves checking actual ports used in denied logs.

Memory trick: Logs tell the tale of the traffic's denial.

More Troubleshoot questions