Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium

A network administrator is troubleshooting an issue where users are intermittently experiencing slow access to an external web application. The firewall logs show a high number of 'deny' actions for the application due to 'Application-not-detected'. However, the application uses standard HTTPS on port 443. Which configuration change is most likely to resolve this issue?

  1. ADisable application identification on the security policy rule for this traffic.
  2. BConfigure an Application Override policy for the web application's traffic.
  3. CCreate a custom application for the web application and use it in the security policy.
  4. DChange the service in the security policy from 'application-default' to 'web-browsing'.
Show answer & explanation

Correct answer: B. Configure an Application Override policy for the web application's traffic.

If the firewall is intermittently failing to identify a known application, especially one using standard ports, an Application Override policy can force the firewall to classify the traffic as the intended application, preventing 'application-not-detected' denials and ensuring consistent policy enforcement.

Why the other options are wrong

  • A. Disabling application identification would defeat the purpose of a next-generation firewall and would significantly reduce security posture, as all traffic on that port would be allowed without inspection.
  • C. Creating a custom application is typically for proprietary or unique applications that the firewall cannot identify. For a standard web application showing intermittent identification issues, Application Override is more appropriate.
  • D. Changing the service to 'web-browsing' might allow the traffic, but it bypasses granular application identification, potentially allowing other unwanted web traffic and not addressing the root cause of 'Application-not-detected' for the specific app.

Application Override

A policy used to force the Palo Alto Networks firewall to classify specific traffic as a designated application, bypassing the standard application identification process.

  • Useful for custom applications, non-standard ports, or intermittent app-ID failures.
  • Evaluated before security policy rules.
  • Can be based on source/destination IP, port, and protocol.

Memory trick: When the app-ID search fails, override it!

More Manage and Operate questions