Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A network administrator is troubleshooting an issue where users on the internal network cannot access a newly deployed server in the DMZ. The server has a NAT policy configured to translate its internal IP to a public IP. Traffic logs show sessions being dropped with 'action: drop', 'rule: default-deny', and 'destination: translated IP'. What is the MOST likely cause?

  1. AThe Security policy rule allowing traffic to the server is missing or misconfigured.
  2. BThe application service in the Security policy rule does not match the traffic.
  3. CThe NAT policy is configured with an incorrect source zone.
  4. DThe server's default gateway is incorrectly configured, leading to asymmetric routing.
Show answer & explanation

Correct answer: A. The Security policy rule allowing traffic to the server is missing or misconfigured.

If traffic is hitting 'default-deny' after NAT has occurred (destination is the translated IP), it means the Security policy rule intended to allow this traffic is not matching. This indicates a misconfiguration or absence of the allow rule itself.

Why the other options are wrong

  • B. If the application service was incorrect, the rule might still match on zones/addresses but then drop due to the service, or App-ID could fail. However, hitting 'default-deny' implies the intended rule wasn't matched *at all*.
  • C. An incorrect source zone in the NAT policy would prevent the NAT from occurring, so the destination wouldn't show as the translated IP in the logs.
  • D. Asymmetric routing would typically manifest as 'incomplete' or 'unknown' applications, or intermittent connectivity, not a consistent 'default-deny' after NAT.

NAT & Security Policy

When troubleshooting NAT and Security policy, remember that Security policy evaluation occurs *after* NAT. Ensure your Security policy rules match the post-NAT addresses and zones.

  • Security policy evaluates post-NAT addresses.
  • 'Default-deny' after NAT implies missing allow rule.
  • NAT order is critical for correct translation.

Memory trick: Change the address, then check the guest list for the new address.

More Troubleshoot questions