PCNSE · Question #45
A network administrator uses Panorama to push security polices to managed firewalls at branch offices. Which policy type should be configured on Panorama if the administrators at the branch office…
The correct answer is B. Post Rules. To allow branch office administrators to override Panorama policies, the centralized policies should be configured as Post Rules.
Question
A network administrator uses Panorama to push security polices to managed firewalls at branch offices. Which policy type should be configured on Panorama if the administrators at the branch office sites to override these products?
Options
- APre Rules
- BPost Rules
- CExplicit Rules
- DImplicit Rules
How the community answered
(22 responses)- A14% (3)
- B77% (17)
- C5% (1)
- D5% (1)
Why each option
To allow branch office administrators to override Panorama policies, the centralized policies should be configured as Post Rules.
Pre Rules, pushed by Panorama, are evaluated before any local firewall rules, meaning local administrators cannot override them with their own device-level rules.
Panorama Post Rules are evaluated after any local firewall rules. Configuring Panorama's general security policies as Post Rules allows branch office administrators to insert their own more specific local rules that will take precedence, effectively enabling them to override or refine centralized policies for their specific needs.
Explicit rules are simply rules that are manually configured, not a specific type within Panorama's policy hierarchy that enables local overrides.
Implicit rules are default deny rules at the bottom of the policy stack and are not configurable in a way that allows local administrators to override Panorama's directives.
Concept tested: Panorama policy hierarchy and rule precedence
Source: https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/manage-firewalls/manage-device-groups/security-policy-rules-overview
Topics
Community Discussion
No community discussion yet for this question.