In RFC-2026-PCNSE-1519, a hospital using PA-3420 HA pairs, GlobalProtect, and a separate guest wireless zone is validating BGP import policy on PAN-OS 11.2 after a cloud cutover freeze. The change record notes that the traffic log shows the rule name, NAT rule, ingress zone, egress zone, and an App-ID shift after the first packets. The application owner changed certificates but says the TCP port is unchanged. A rollback would affect unrelated rulebases, so the team must preserve inspection and avoid widening policy. Which design decision best satisfies the requirement?