QuestionQ9

PAN-OS Device Setting Configuration

Which statement describes the relationship between Panorama-pushed Security policy and local firewall Security policy?

  • A When a policy match is found in a local firewall policy, if any Panorama shared post-rule is configured, it will still be evaluated.
  • B Local firewall rules are evaluated after Panorama pre-rules and before Panorama post-rules.
  • C Panorama post-rules can be configured to be evaluated before local firewall policy for the purpose of troubleshooting.
  • D The order of policy evaluation can be configured differently in different device groups.
Explanation

Security policy evaluation places Panorama pre-rules ahead of local firewall rules and Panorama post-rules after them. The firewall applies the first matching rule, so local Security rules are evaluated after pre-rules and before post-rules.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!