PSE-PLATFORM · Question #313
A web server is hosted in the DMZ and the server is configured to listen for incoming connections on TCP port 443. A Security policies rules allowing access from the Trust zone to the DMZ zone needs t
The correct answer is B. Rule #1: application: web-browsing; service: service-https; action: allowRule #2:. Explanation/Reference: If decrypted traffic matches the web-browsing application. Then the firewall will log it as web-browsing over ssl (443) and will never match if it is set to "application- https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEyCAK
Question
A web server is hosted in the DMZ and the server is configured to listen for incoming connections on TCP port 443. A Security policies rules allowing access from the Trust zone to the DMZ zone needs to be configured to allow web-browsing access. The web server hosts its contents over HTTP(S). Traffic from Trust to DMZ is being decrypted with a Forward Proxy rule. Which combination of service and application, and order of Security policy rules, needs to be configured to allow cleartext web-browsing traffic to this server on tcp/443.
Options
- ARule #1: application: web-browsing; service: application-default; action: allowRule #2:
- BRule #1: application: web-browsing; service: service-https; action: allowRule #2:
- CRule # 1: application: ssl; service: application-default; action: allowRule #2: application:
- DRule #1: application: web-browsing; service: service-http; action: allowRule #2:
How the community answered
(18 responses)- A22% (4)
- B61% (11)
- C11% (2)
- D6% (1)
Explanation
Explanation/Reference: If decrypted traffic matches the web-browsing application. Then the firewall will log it as web-browsing over ssl (443) and will never match if it is set to "application- https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEyCAK
Topics
Community Discussion
No community discussion yet for this question.