Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsMedium
A security auditor is reviewing the logging configuration of a Palo Alto Networks firewall and notes that sessions are being dropped due to application-default not being allowed. Which action should the administrator take to allow traffic for applications that rely on standard ports while enforcing Application-ID?
- ADisable Application-ID on the security policy.
- BConfigure an Application Override policy.
- CChange the service to 'application-default' in the security policy.
- DSet the service to 'any' in the security policy.
Show answer & explanationAnswer & explanation
Correct answer: C. Change the service to 'application-default' in the security policy.
To allow traffic for applications that use standard ports (like HTTP on 80, HTTPS on 443) while still leveraging Application-ID, the 'service' in the security policy should be set to 'application-default'. This permits the firewall to identify the application and allow it on its standard port(s).
Why the other options are wrong
- A. Disabling Application-ID would prevent the firewall from identifying applications, undermining the core security features.
- B. An Application Override policy forces the firewall to identify traffic as a specific application, which is not the goal here; the goal is to allow *any* application on its *default* port.
- D. Setting the service to 'any' would allow all ports, bypassing the intent of Application-ID and potentially creating security gaps.
Application-Default Service
A service setting in Palo Alto Networks security policies that allows applications to be identified and permitted on their standard, default ports, while still enforcing Application-ID.
- Crucial for Application-ID to function correctly.
- Permits traffic on standard ports (e.g., HTTP on 80).
- Ensures accurate application identification and control.
Memory trick: Application-Default is the 'smart' traffic cop for apps.