Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A network administrator is troubleshooting an issue where users are unable to access a newly deployed web server that resides in a DMZ zone behind a Palo Alto Networks firewall. The security policy allowing access has been created, and a NAT policy exists for the public IP. Packet captures on the firewall show traffic arriving on the external interface but no return traffic. What is the most likely misconfiguration?

  1. AThe default route on the firewall is incorrect for the DMZ zone.
  2. BThe NAT policy is configured for Source NAT instead of Destination NAT.
  3. CThe security policy is missing the correct application.
  4. DThe security policy from DMZ to Trust is missing or misconfigured.
Show answer & explanation

Correct answer: D. The security policy from DMZ to Trust is missing or misconfigured.

Packet captures show traffic arriving on the external interface, indicating the Destination NAT (DNAT) is working and the initial security policy is allowing the inbound connection. The absence of return traffic suggests that the firewall is not allowing the traffic from the DMZ back out to the client. This points to a missing or misconfigured security policy allowing traffic from the DMZ zone (where the web server is) to the untrust zone (where the client is).

Why the other options are wrong

  • A. An incorrect default route on the firewall would affect all outbound traffic, but the specific problem points to traffic from the DMZ not exiting, implying a policy block first.
  • B. If the NAT policy was Source NAT, the initial inbound traffic wouldn't reach the server, or the server would see the wrong source IP, but the problem is about lack of *return* traffic after initial arrival.
  • C. If the security policy was missing the correct application, the initial inbound traffic wouldn't be allowed, contradicting the packet capture evidence.

Return Traffic Policy

For successful communication through a firewall, both inbound and outbound (return) traffic must be explicitly allowed by security policies, especially when crossing zone boundaries.

  • Palo Alto firewalls are stateful, but policies still apply to new sessions.
  • Return traffic for initiated sessions is typically allowed by the stateful inspection.
  • However, if the server initiates a *new* connection or a policy explicitly blocks the return path, issues arise.

Memory trick: DMZ traffic needs a 'Return Ticket' policy.

More Troubleshoot questions