Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootHard
A network administrator is troubleshooting an issue where users are experiencing intermittent access to a critical web application hosted behind a Palo Alto Networks firewall. The application uses a custom port. The administrator has verified that the Security policy allows the custom port, and the App-ID shows 'web-browsing'. However, sometimes the application still fails. What is a common troubleshooting step to ensure App-ID is not interfering with custom applications?
- ACreate a custom application for the application and add it to the Security policy.
- BDisable App-ID for the specific security zone.
- CChange the application in the Security policy rule to 'application-default'.
- DSet the service to 'any' in the Security policy rule.
Show answer & explanationAnswer & explanation
Correct answer: A. Create a custom application for the application and add it to the Security policy.
If a custom application is misidentified, or if 'web-browsing' is too broad, creating a specific custom application allows for precise identification and policy enforcement. This ensures App-ID correctly recognizes the application and doesn't interfere with its traffic, especially on non-standard ports.
Why the other options are wrong
- B. Disabling App-ID for a zone is not possible directly and would defeat the purpose of the firewall. App-ID is fundamental to Palo Alto Networks' security posture.
- C. Using 'application-default' would rely on the default ports for 'web-browsing' (80, 443), which would not work for a custom application on a non-standard port.
- D. Setting the service to 'any' would allow all ports, which is a security risk and doesn't solve the App-ID identification issue for a custom application.
Custom App-ID
For applications using non-standard ports or unique protocols, creating a custom App-ID ensures correct identification and policy enforcement, preventing misclassification by the firewall.
- Used for unique or non-standard applications.
- Allows precise policy control.
- Prevents 'unknown' or 'misidentified' apps.
Memory trick: If the shoe doesn't fit, you need to make a custom one.