Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium
A network administrator is troubleshooting an issue where users are intermittently experiencing slow access to an external web application. The firewall logs show a high number of 'deny' actions for the application due to 'Application-not-detected'. However, the application uses standard HTTPS on port 443. Which configuration change is most likely to resolve this issue?
- ADisable application identification on the security policy rule for this traffic.
- BConfigure an Application Override policy for the web application's traffic.
- CCreate a custom application for the web application and use it in the security policy.
- DChange the service in the security policy from 'application-default' to 'web-browsing'.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure an Application Override policy for the web application's traffic.
If the firewall is intermittently failing to identify a known application, especially one using standard ports, an Application Override policy can force the firewall to classify the traffic as the intended application, preventing 'application-not-detected' denials and ensuring consistent policy enforcement.
Why the other options are wrong
- A. Disabling application identification would defeat the purpose of a next-generation firewall and would significantly reduce security posture, as all traffic on that port would be allowed without inspection.
- C. Creating a custom application is typically for proprietary or unique applications that the firewall cannot identify. For a standard web application showing intermittent identification issues, Application Override is more appropriate.
- D. Changing the service to 'web-browsing' might allow the traffic, but it bypasses granular application identification, potentially allowing other unwanted web traffic and not addressing the root cause of 'Application-not-detected' for the specific app.
Application Override
A policy used to force the Palo Alto Networks firewall to classify specific traffic as a designated application, bypassing the standard application identification process.
- Useful for custom applications, non-standard ports, or intermittent app-ID failures.
- Evaluated before security policy rules.
- Can be based on source/destination IP, port, and protocol.
Memory trick: When the app-ID search fails, override it!