Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium

A company uses Panorama to manage multiple Palo Alto Networks firewalls. The security team needs to deploy a new security policy rule that allows specific applications for a new development environment. This rule should be located at the top of the rulebase for evaluation priority and apply only to firewalls associated with the 'Development' device group. How should the administrator configure this on Panorama?

  1. ACreate the rule in a shared policy at the bottom and then move it to the top of the 'Development' device group policy.
  2. BCreate the rule in a post-rule on a template stack and apply it to the 'Development' device group.
  3. CCreate the rule directly within the 'Development' device group policy at the top of its rulebase.
  4. DCreate the rule in a pre-rule on a template stack and apply it to the 'Development' device group.
Show answer & explanation

Correct answer: C. Create the rule directly within the 'Development' device group policy at the top of its rulebase.

To ensure a rule is at the top of the rulebase for a specific device group and applies only to firewalls in that group, it must be created directly within the device group's policy rules. Shared policies apply globally, and template stacks manage network/device settings, not security policy rule order within device groups.

Why the other options are wrong

  • A. Shared policies apply globally to all device groups. While it can be moved to the top of a shared policy, it would still apply to all firewalls, not just 'Development'.
  • B. Similar to option C, template stacks are for device configuration. Post-rules are part of shared policies and would apply globally, not just to the 'Development' device group.
  • D. Template stacks primarily manage network and device configuration, not the order or content of security policy rules within a device group's rulebase. Pre-rules/post-rules are part of shared policies, not device group policies.

Panorama Policy Rule Hierarchy

Panorama manages policy rules in a hierarchical structure, including Shared Policies, Device Group Policies (pre-rules, rules, post-rules), and Local Device Rules, with evaluation order from top to bottom.

  • Shared policies apply globally to all managed firewalls.
  • Device group policies apply only to firewalls within that specific device group.
  • Rules are evaluated from Shared Pre-Rules, then Device Group Pre-Rules, Device Group Rules, Device Group Post-Rules, Shared Post-Rules, and finally Local Rules.

Memory trick: Global rules first, then specific group rules, then local device rules.

More Manage and Operate questions