Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A technician is troubleshooting an issue where users are unable to access internal web servers after a new Security policy rule was implemented. The rule is intended to allow HTTP and HTTPS traffic from the 'Internal-Zone' to the 'DMZ-Zone'. After checking the traffic logs, the technician sees entries with (action: drop) and (rule: default-deny). What is the MOST likely cause?

  1. AThere is a NAT policy issue preventing the traffic from matching the rule.
  2. BThe application filter in the Security policy rule is configured incorrectly.
  3. CThe source or destination zones in the Security policy rule are incorrect.
  4. DThe Security policy rule is placed too high in the rule order.
Show answer & explanation

Correct answer: C. The source or destination zones in the Security policy rule are incorrect.

If traffic is hitting the 'default-deny' rule, it means no explicit allow rule above it matched the traffic. Incorrect source or destination zones would cause the intended allow rule to be bypassed entirely, leading to the default-deny action.

Why the other options are wrong

  • A. NAT policy issues typically manifest as connection failures or incorrect address translation, but if the Security policy isn't matching, it's a policy evaluation issue before NAT is fully processed in the security rule lookup.
  • B. An incorrect application filter might prevent the rule from matching specific applications, but it wouldn't necessarily cause the traffic to hit 'default-deny' if other parameters like zones and addresses were correct.
  • D. If the rule were placed too high, it would likely match and allow traffic, or potentially block it if it was a deny rule placed before an allow rule. Hitting 'default-deny' implies it didn't match any explicit rule.

Security Policy Troubleshooting

Troubleshooting Security policy involves verifying that traffic matches the intended rule by checking parameters like zones, addresses, applications, and service, and ensuring correct rule order.

  • Rules are evaluated top-down.
  • Default-deny catches unmatched traffic.
  • Zones are critical for initial rule matching.

Memory trick: The firewall checks its checklist from top to bottom; miss one detail, and it's a no-go.

More Troubleshoot questions