ExamGecko
Question list
Search
Search

Related questions











Question 365 - PCNSE discussion

Report
Export

Which two items must be configured when implementing application override and allowing traffic through the firewall? (Choose two.)

A.
Application filter
Answers
A.
Application filter
B.
Application override policy rule
Answers
B.
Application override policy rule
C.
Security policy rule
Answers
C.
Security policy rule
D.
Custom app
Answers
D.
Custom app
Suggested answer: B, C

Explanation:

When implementing an application override in a Palo Alto Networks firewall, the primary goal is to explicitly define how specific traffic is identified and processed by the firewall, bypassing the regular App-ID process. This is particularly useful for traffic that might be misidentified by App-ID or for applications that require special handling for performance reasons.

To successfully implement application override, the following items must be configured:

B. Application override policy rule: This is a specialized policy rule that you create to specify the criteria for the traffic you want to override. In this rule, you define the source and destination zones, addresses, and ports. Instead of relying on the App-ID engine to identify the application, the firewall uses the criteria defined in the application override policy to classify the traffic.

C. Security policy rule: After defining an application override policy, you must also configure a security policy rule to allow the overridden traffic through the firewall. This rule specifies the action (allow, deny, drop, etc.) for the traffic that matches the application override policy. It's essential to ensure that the security policy rule matches the traffic defined in the application override policy to ensure that the intended traffic is allowed through the firewall.

For detailed guidance on configuring application override and the necessary security policies, refer to the official Palo Alto Networks documentation. This resource provides step-by-step instructions and best practices for effectively managing traffic using application overrides.

asked 23/09/2024
John Hammonds
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first