PCNSE · Question #571
After some firewall configuration changes, an administrator discovers that application identification has started failing. The administrator investigates further and notices that a high number of…
The correct answer is A. enabling Forward segments that exceed the TCP App-ID inspection queue in Device > Setup >. Disable this option to prevent the firewall from forwarding TCP segments and skipping App-ID inspection when the App-ID inspection queue is full. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/device/device-setup-
Question
After some firewall configuration changes, an administrator discovers that application identification has started failing. The administrator investigates further and notices that a high number of sessions were going to a discard state with the application showing as unknown-tcp. Which possible firewall change could have caused this issue?
Options
- Aenabling Forward segments that exceed the TCP App-ID inspection queue in Device > Setup >
- Benabling Forward segments that exceed the TCP content inspection queue in Device > Setup >
- CJumbo frames were enabled on the firewall, which reduced the App-ID queue size and the
- DJumbo frames were disabled on the firewall, which reduced the queue sizes dedicated for out-of-
How the community answered
(25 responses)- A72% (18)
- B16% (4)
- C4% (1)
- D8% (2)
Explanation
Disable this option to prevent the firewall from forwarding TCP segments and skipping App-ID inspection when the App-ID inspection queue is full. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/device/device-setup-
Topics
Community Discussion
No community discussion yet for this question.