Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsMedium

A security auditor is reviewing the logging configuration of a Palo Alto Networks firewall and notes that sessions are being dropped due to application-default not being allowed. Which action should the administrator take to allow traffic for applications that rely on standard ports while enforcing Application-ID?

  1. ADisable Application-ID on the security policy.
  2. BConfigure an Application Override policy.
  3. CChange the service to 'application-default' in the security policy.
  4. DSet the service to 'any' in the security policy.
Show answer & explanation

Correct answer: C. Change the service to 'application-default' in the security policy.

To allow traffic for applications that use standard ports (like HTTP on 80, HTTPS on 443) while still leveraging Application-ID, the 'service' in the security policy should be set to 'application-default'. This permits the firewall to identify the application and allow it on its standard port(s).

Why the other options are wrong

  • A. Disabling Application-ID would prevent the firewall from identifying applications, undermining the core security features.
  • B. An Application Override policy forces the firewall to identify traffic as a specific application, which is not the goal here; the goal is to allow *any* application on its *default* port.
  • D. Setting the service to 'any' would allow all ports, bypassing the intent of Application-ID and potentially creating security gaps.

Application-Default Service

A service setting in Palo Alto Networks security policies that allows applications to be identified and permitted on their standard, default ports, while still enforcing Application-ID.

  • Crucial for Application-ID to function correctly.
  • Permits traffic on standard ports (e.g., HTTP on 80).
  • Ensures accurate application identification and control.

Memory trick: Application-Default is the 'smart' traffic cop for apps.

More Core Concepts questions