Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A network administrator is troubleshooting an issue where a specific application, 'ExampleApp', is not being correctly identified by App-ID, leading to incorrect policy enforcement. The application uses non-standard ports, and the administrator suspects App-ID isn't recognizing it. What is the most effective way to teach the Palo Alto Networks firewall to correctly identify 'ExampleApp' when it uses non-standard ports?

  1. ACreate a custom application signature for 'ExampleApp' using the App-ID custom application editor.
  2. BImplement a port-based Security policy rule for 'ExampleApp' instead of an App-ID based rule.
  3. CChange the App-ID Security policy rule to 'any' for the service.
  4. DCreate a custom service object for the non-standard ports and use it in the Security policy.
Show answer & explanation

Correct answer: A. Create a custom application signature for 'ExampleApp' using the App-ID custom application editor.

When an application uses non-standard ports and isn't recognized by App-ID, creating a custom application signature is the most effective way to 'teach' the firewall to identify it accurately. This allows App-ID to recognize the application regardless of the port it uses, maintaining deep packet inspection benefits.

Why the other options are wrong

  • B. Implementing a port-based rule bypasses App-ID and offers less granular control and visibility compared to a custom application.
  • C. Changing the service to 'any' would allow all traffic on all ports, completely bypassing App-ID for this rule and significantly reducing security.
  • D. Creating a custom service object would allow traffic on specific ports but would not leverage App-ID's deep packet inspection for 'ExampleApp', effectively bypassing it.

Custom App-ID

Custom App-ID allows administrators to create signatures for internally developed or niche applications that are not recognized by Palo Alto Networks' standard App-ID database.

  • Identifies applications based on payload/behavior, not just port.
  • Maintains deep packet inspection capabilities.
  • Requires knowledge of application traffic characteristics.

Memory trick: Custom signatures teach the firewall new tricks.

More Troubleshoot questions