Exam PCNSE All QuestionsBrowse all questions from this exam
Question 336

A Firewall Engineer is migrating a legacy firewall to a Palo Alto Networks firewall in order to use features like App-ID and SSL decryption.

Which order of steps is best to complete this migration?

    Correct Answer: D

    To successfully migrate a legacy firewall to a Palo Alto Networks firewall while utilizing advanced features like App-ID and SSL decryption, the most logical order of operations involves first migrating port-based rules to App-ID rules. This ensures that the firewall can correctly identify and control applications, which is crucial for the accurate setup and functioning of security policies. After this, implementing SSL decryption can be done effectively, as the App-ID rules will provide a robust foundation to handle encrypted traffic. This sequence helps in avoiding misconfigurations and ensures smoother deployment of decryption policies.

Discussion
secdaddyOption: C

Why not C ? Don't we need visibility (via decryption) before app-ID can function?

Jared28

Definitely D. The link provided by some, pay close attention to this specific line (and the non-standard port part): "...Security policy rules are likely to use application default ports to prevent traffic from using non-standard ports." Granted you could account for non-default ports just fine beforehand too but test is on PAN BPs so D

Roger123444Option: D

Migrate from port-based to application-based Security policy rules before you create and deploy Decryption policy rules. https://docs.paloaltonetworks.com/best-practices/9-1/decryption-best-practices/decryption-best-practices/plan-ssl-decryption-best-practice-deployment

GBD35055Option: D

D is correct. Migrate from port-based to applicaon-based Security policy rules before you create and deploy Decrypon policy rules. If you create Decrypon rules based on port-based Security policy and then migrate to applicaon-based Security policy, the change could cause the Decrypon rules to block traffic that you intend to allow because Security policy rules are likely to use applicaon default ports to prevent traffic from using non-standard ports. Migrang to App-ID based rules before deploying decrypon ensures that when you test your decrypon deployment, you’ll discover Security policy misconfiguraons and fix them before rolling decrypon out to the general user populaon.

Gabuu

Can you post the link where you got your information ?

gully300Option: D

https://docs.paloaltonetworks.com/best-practices/10-2/decryption-best-practices/decryption-best-practices/plan-ssl-decryption-best-practice-deployment "Migrating to App-ID based rules before deploying decryption ensures that when you test your decryption deployment"

confusionOption: D

D move to App-ID befohttps://www.examtopics.com/exams/palo-alto-networks/pcnse/view/#re you implement Decryption

TAKUM1yOption: D

https://docs.paloaltonetworks.com/best-practices/10-2/decryption-best-practices/decryption-best-practices/plan-ssl-decryption-best-practice-deployment