Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium
A network administrator is troubleshooting an issue where a specific application, 'ExampleApp', is not being correctly identified by App-ID, leading to incorrect policy enforcement. The application uses non-standard ports, and the administrator suspects App-ID isn't recognizing it. What is the most effective way to teach the Palo Alto Networks firewall to correctly identify 'ExampleApp' when it uses non-standard ports?
- ACreate a custom application signature for 'ExampleApp' using the App-ID custom application editor.
- BImplement a port-based Security policy rule for 'ExampleApp' instead of an App-ID based rule.
- CChange the App-ID Security policy rule to 'any' for the service.
- DCreate a custom service object for the non-standard ports and use it in the Security policy.
Show answer & explanationAnswer & explanation
Correct answer: A. Create a custom application signature for 'ExampleApp' using the App-ID custom application editor.
When an application uses non-standard ports and isn't recognized by App-ID, creating a custom application signature is the most effective way to 'teach' the firewall to identify it accurately. This allows App-ID to recognize the application regardless of the port it uses, maintaining deep packet inspection benefits.
Why the other options are wrong
- B. Implementing a port-based rule bypasses App-ID and offers less granular control and visibility compared to a custom application.
- C. Changing the service to 'any' would allow all traffic on all ports, completely bypassing App-ID for this rule and significantly reducing security.
- D. Creating a custom service object would allow traffic on specific ports but would not leverage App-ID's deep packet inspection for 'ExampleApp', effectively bypassing it.
Custom App-ID
Custom App-ID allows administrators to create signatures for internally developed or niche applications that are not recognized by Palo Alto Networks' standard App-ID database.
- Identifies applications based on payload/behavior, not just port.
- Maintains deep packet inspection capabilities.
- Requires knowledge of application traffic characteristics.
Memory trick: Custom signatures teach the firewall new tricks.