PCNSE · Question #780
A firewall engineer has determined that, in an application developed by the company's internal team, sessions often remain idle for hours before the client and server exchange any data. The…
The correct answer is C. Create a custom application with specific timeouts, then create an application override rule and. Creating a custom application with specific session timeouts (to accommodate long idle periods) and then creating an application override rule is the fastest solution. The application override rule tells the firewall to immediately classify matching traffic as the custom…
Question
A firewall engineer has determined that, in an application developed by the company's internal team, sessions often remain idle for hours before the client and server exchange any data. The application is also currently identified as unknown-tcp by the firewalls. It is determined that because of a high level of trust, the application does not require to be scanned for threats, but it needs to be properly identified in Traffic logs for reporting purposes. Which solution will take the least time to implement and will ensure the App-ID engine is used to identify the application?
Options
- ACreate a custom application with specific timeouts and signatures based on patterns discovered
- BAccess the Palo Alto Networks website and complete the online form to request that a new
- CCreate a custom application with specific timeouts, then create an application override rule and
- DAccess the Palo Alto Networks website and raise a support request through the Customer
How the community answered
(39 responses)- A5% (2)
- B13% (5)
- C74% (29)
- D8% (3)
Explanation
Creating a custom application with specific session timeouts (to accommodate long idle periods) and then creating an application override rule is the fastest solution. The application override rule tells the firewall to immediately classify matching traffic as the custom application without going through the full App-ID inspection engine - this means no threat scanning occurs, satisfying the security requirement. The traffic is correctly labeled in Traffic logs under the custom application name. Option A (creating signature patterns) takes more time and adds unnecessary complexity. Options B and D involve submitting requests to Palo Alto Networks, which can take weeks - not the least time to implement.
Topics
Community Discussion
No community discussion yet for this question.