Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium
A network administrator is troubleshooting an issue where users on the internal network cannot access a newly deployed server in the DMZ. The server has a NAT policy configured to translate its internal IP to a public IP. Traffic logs show sessions being dropped with 'action: drop', 'rule: default-deny', and 'destination: translated IP'. What is the MOST likely cause?
- AThe Security policy rule allowing traffic to the server is missing or misconfigured.
- BThe application service in the Security policy rule does not match the traffic.
- CThe NAT policy is configured with an incorrect source zone.
- DThe server's default gateway is incorrectly configured, leading to asymmetric routing.
Show answer & explanationAnswer & explanation
Correct answer: A. The Security policy rule allowing traffic to the server is missing or misconfigured.
If traffic is hitting 'default-deny' after NAT has occurred (destination is the translated IP), it means the Security policy rule intended to allow this traffic is not matching. This indicates a misconfiguration or absence of the allow rule itself.
Why the other options are wrong
- B. If the application service was incorrect, the rule might still match on zones/addresses but then drop due to the service, or App-ID could fail. However, hitting 'default-deny' implies the intended rule wasn't matched *at all*.
- C. An incorrect source zone in the NAT policy would prevent the NAT from occurring, so the destination wouldn't show as the translated IP in the logs.
- D. Asymmetric routing would typically manifest as 'incomplete' or 'unknown' applications, or intermittent connectivity, not a consistent 'default-deny' after NAT.
NAT & Security Policy
When troubleshooting NAT and Security policy, remember that Security policy evaluation occurs *after* NAT. Ensure your Security policy rules match the post-NAT addresses and zones.
- Security policy evaluates post-NAT addresses.
- 'Default-deny' after NAT implies missing allow rule.
- NAT order is critical for correct translation.
Memory trick: Change the address, then check the guest list for the new address.