An organization has a data center with servers in the 10.10.0.0/16 subnet and remote users who connect via GlobalProtect. The security team wants to ensure that only approved applications (web-browsing, ssl, dns) are allowed from the remote user subnet (172.16.0.0/24) to the data center. They create a security rule with source zone 'GP' (GlobalProtect), destination zone 'DC', source address '172.16.0.0/24', destination address '10.10.0.0/16', application 'web-browsing', 'ssl', 'dns', action 'allow'. After deployment, users complain that they cannot access a custom web application on port 8080, which uses HTTP but the application is identified as 'web-browsing'. The administrator checks the traffic logs and sees that the traffic is being denied by an implicit deny rule. What is the most likely cause?
Trap 1: The rule order is incorrect; a previous rule is denying the traffic.
The logs show implicit deny, which is the default rule at the end, indicating no matching allow rule.
Trap 2: The destination address object 10.10.0.0/16 is incorrect.
The subnet appears correct for the data center.
Trap 3: The source zone 'GP' should be 'untrust'.
GlobalProtect typically uses a dedicated zone 'GP'.
- A
The application 'web-browsing' does not cover port 8080 traffic.
App-ID identifies traffic based on signatures, not just port. Custom HTTP on 8080 may not match 'web-browsing' signature, so it is not allowed.
- B
The rule order is incorrect; a previous rule is denying the traffic.
Why it fails: The logs show implicit deny, which is the default rule at the end, indicating no matching allow rule.
- C
The destination address object 10.10.0.0/16 is incorrect.
Why it fails: The subnet appears correct for the data center.
- D
The source zone 'GP' should be 'untrust'.
Why it fails: GlobalProtect typically uses a dedicated zone 'GP'.