Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium
A network administrator is troubleshooting an issue where users are intermittently unable to access a critical internal application hosted on a server in the 'Server-Zone'. The application uses a non-standard port. Security policy rules are in place to allow the traffic. After reviewing traffic logs, the administrator sometimes sees 'application: unknown-tcp' and other times 'application: incomplete'. What is the MOST likely cause?
- AThere is an asymmetric routing issue causing the firewall to only see one side of the connection.
- BThe firewall is unable to identify the application due to insufficient traffic or an unsupported application.
- CThe Security policy rule is using 'any' as the application, preventing correct App-ID.
- DThe application's port is not included in the service object of the Security policy rule.
Show answer & explanationAnswer & explanation
Correct answer: A. There is an asymmetric routing issue causing the firewall to only see one side of the connection.
Both 'unknown-tcp' and 'incomplete' can be symptoms of asymmetric routing. 'Incomplete' often means the firewall saw the SYN but not the SYN-ACK or ACK. 'Unknown-tcp' can occur if the firewall only sees part of the session, making application identification difficult or impossible.
Why the other options are wrong
- B. While true that insufficient traffic can lead to 'incomplete' or 'unknown-tcp', the intermittent nature and the combination of both often point to a more fundamental network issue like asymmetric routing, which causes the firewall to miss parts of the session.
- C. Using 'any' as the application still allows App-ID to identify the application. It wouldn't cause 'unknown-tcp' or 'incomplete' errors related to App-ID failure.
- D. If the port was not included in the service object, the traffic would be dropped by the firewall, not classified as 'unknown-tcp' or 'incomplete' (unless it hit a default-deny after App-ID failed to identify).
App-ID Incomplete/Unknown
The 'incomplete' and 'unknown-tcp' application identifications often indicate underlying network issues (like asymmetric routing) or the firewall not seeing the full session, hindering App-ID.
- 'incomplete' = firewall didn't see full handshake.
- 'unknown-tcp' = firewall can't identify app on known port.
- Asymmetric routing is a common cause.
Memory trick: App-ID is a detective; if it only gets half the clues, it can't solve the mystery.