Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootHard

A network administrator is troubleshooting an issue where users are experiencing intermittent access to a critical web application hosted behind a Palo Alto Networks firewall. The application uses a custom port. The administrator has verified that the Security policy allows the custom port, and the App-ID shows 'web-browsing'. However, sometimes the application still fails. What is a common troubleshooting step to ensure App-ID is not interfering with custom applications?

  1. ACreate a custom application for the application and add it to the Security policy.
  2. BDisable App-ID for the specific security zone.
  3. CChange the application in the Security policy rule to 'application-default'.
  4. DSet the service to 'any' in the Security policy rule.
Show answer & explanation

Correct answer: A. Create a custom application for the application and add it to the Security policy.

If a custom application is misidentified, or if 'web-browsing' is too broad, creating a specific custom application allows for precise identification and policy enforcement. This ensures App-ID correctly recognizes the application and doesn't interfere with its traffic, especially on non-standard ports.

Why the other options are wrong

  • B. Disabling App-ID for a zone is not possible directly and would defeat the purpose of the firewall. App-ID is fundamental to Palo Alto Networks' security posture.
  • C. Using 'application-default' would rely on the default ports for 'web-browsing' (80, 443), which would not work for a custom application on a non-standard port.
  • D. Setting the service to 'any' would allow all ports, which is a security risk and doesn't solve the App-ID identification issue for a custom application.

Custom App-ID

For applications using non-standard ports or unique protocols, creating a custom App-ID ensures correct identification and policy enforcement, preventing misclassification by the firewall.

  • Used for unique or non-standard applications.
  • Allows precise policy control.
  • Prevents 'unknown' or 'misidentified' apps.

Memory trick: If the shoe doesn't fit, you need to make a custom one.

More Troubleshoot questions