Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium

A network security engineer observes that after a recent content update, a critical internal application using a proprietary protocol on a non-standard port is being incorrectly identified by the firewall as 'unknown-tcp' and subsequently blocked. How should the engineer ensure this application is correctly identified and allowed without compromising security for other traffic?

  1. ACreate a security policy rule to allow 'any' application on the specific port for the internal application.
  2. BDisable App-ID on the security policy rule for the internal application's zone.
  3. CConfigure an Application Override rule for the proprietary application to force its identification.
  4. DChange the service in the existing security policy rule from 'application-default' to 'any' for the application's port.
Show answer & explanation

Correct answer: C. Configure an Application Override rule for the proprietary application to force its identification.

When a proprietary application on a non-standard port is incorrectly identified as 'unknown-tcp', an Application Override rule is the most suitable solution. It forces the firewall to classify the specific traffic as the intended application, allowing granular control without opening up the port to 'any' application.

Why the other options are wrong

  • A. Allowing 'any' application on a specific port would open a security hole, potentially allowing unwanted or malicious applications to use that port.
  • B. Disabling App-ID would prevent the firewall from identifying any application on that traffic flow, significantly reducing the security posture and violating the 'without compromising security' requirement.
  • D. Changing the service to 'any' is similar to option A; it allows all applications on that port, which is not granular and compromises security.

Application Override for Proprietary Apps

Using an Application Override policy to ensure custom or proprietary applications, especially those on non-standard ports or misidentified by App-ID, are correctly classified by the firewall.

  • Provides granular control for specific traffic flows.
  • Forces App-ID classification, overriding default signatures.
  • Essential for maintaining security while supporting unique applications.

Memory trick: When the custom gear is unknown, give it a specific override label.

More Manage and Operate questions