nerdexam
Palo_Alto_Networks

PCNSE · Question #571

After some firewall configuration changes, an administrator discovers that application identification has started failing. The administrator investigates further and notices that a high number of…

The correct answer is A. enabling Forward segments that exceed the TCP App-ID inspection queue in Device > Setup >. Disable this option to prevent the firewall from forwarding TCP segments and skipping App-ID inspection when the App-ID inspection queue is full. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/device/device-setup-

Submitted by brentm· Apr 18, 2026Configuration Troubleshooting

Question

After some firewall configuration changes, an administrator discovers that application identification has started failing. The administrator investigates further and notices that a high number of sessions were going to a discard state with the application showing as unknown-tcp. Which possible firewall change could have caused this issue?

Options

  • Aenabling Forward segments that exceed the TCP App-ID inspection queue in Device > Setup >
  • Benabling Forward segments that exceed the TCP content inspection queue in Device > Setup >
  • CJumbo frames were enabled on the firewall, which reduced the App-ID queue size and the
  • DJumbo frames were disabled on the firewall, which reduced the queue sizes dedicated for out-of-

How the community answered

(25 responses)
  • A
    72% (18)
  • B
    16% (4)
  • C
    4% (1)
  • D
    8% (2)

Explanation

Disable this option to prevent the firewall from forwarding TCP segments and skipping App-ID inspection when the App-ID inspection queue is full. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/device/device-setup-

Topics

#App-ID#Troubleshooting#TCP Queues#Performance

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice