Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A security engineer is investigating why certain web applications are not being blocked by a security policy configured with an 'application-default' service. The application logs show traffic hitting the firewall, but the policy is not enforcing the block. The security policy is configured to block 'web-browsing' and 'ssl' applications. Which command would be most useful to determine if the firewall is correctly identifying the applications for this traffic?

  1. Atest security-policy-match source <IP> destination <IP> application web-browsing
  2. Bdebug application application-id statistics
  3. Cshow system resources
  4. Dshow session all filter application web-browsing
Show answer & explanation

Correct answer: D. show session all filter application web-browsing

The 'show session all filter application <app-name>' command allows you to view all active sessions that the firewall has identified with a specific application. This is crucial for verifying if the firewall's App-ID engine is correctly identifying the applications (web-browsing, ssl) that the policy intends to block.

Why the other options are wrong

  • A. While 'test security-policy-match' is useful, it simulates policy matching based on *assumed* application. It doesn't tell you what the firewall is *actually* identifying in live traffic. The problem states traffic is hitting the firewall, so actual identification is key.
  • B. This command provides statistics about App-ID, but not specific session identification which is needed to troubleshoot a policy not matching due to application misidentification.
  • C. This command shows system resource utilization, which is not directly relevant to troubleshooting application identification for policy matching.

App-ID Verification

Verifying how the Palo Alto Networks firewall identifies specific applications in live traffic is crucial for troubleshooting security policy enforcement.

  • App-ID identifies applications regardless of port.
  • Policies rely on accurate App-ID.
  • Misidentification can lead to policy bypass or incorrect blocking.

Memory trick: Identify the App, then Apply the Policy.

More Troubleshoot questions