NGFW-ENGINEER · Question #52
A large enterprise wants to implement certificate-based authentication for both users and devices, using an on-premises Microsoft Active Directory Certificate Services (AD CS) hierarchy as the…
The correct answer is B. Distribute the root and intermediate CA certificates via Panorama as shared objects to ensure all. This approach best addresses the enterprise's requirements for certificate-based authentication, OCSP checks, and consistent policy enforcement: Distributing the root and intermediate CA certificates via Panorama ensures that all firewalls in the enterprise are consistent in…
Question
A large enterprise wants to implement certificate-based authentication for both users and devices, using an on-premises Microsoft Active Directory Certificate Services (AD CS) hierarchy as the primary certificate authority (CA). The enterprise also requires Online Certificate Status Protocol (OCSP) checks to ensure efficient revocation status updates and reduce the overhead on its NGFWs. The environment includes multiple Active Directory forests, Panorama management for several geographically dispersed firewalls, GlobalProtect portals and gateways needing distinct certificate profiles for users and devices, and strict Security policies demanding frequent revocation checks with minimal latency. Which approach best addresses these requirements while maintaining consistent policy enforcement?
Options
- ADeploy self-signed certificates at each site to simplify local certificate validation and reduce
- BDistribute the root and intermediate CA certificates via Panorama as shared objects to ensure all
- CConfigure each firewall independently to trust the root and intermediate CA certificates. Rely only
- DObtain wildcard certificates from a public CA for both user and device authentication, and
How the community answered
(36 responses)- A8% (3)
- B67% (24)
- C19% (7)
- D6% (2)
Explanation
This approach best addresses the enterprise's requirements for certificate-based authentication, OCSP checks, and consistent policy enforcement: Distributing the root and intermediate CA certificates via Panorama ensures that all firewalls in the enterprise are consistent in their trust chain and can validate certificates properly. Configuring OCSP responder profiles on each firewall offloads the revocation checks to an internal OCSP server, which reduces the overhead on the firewalls and ensures fast, real-time certificate status Using CRL checks as a fallback ensures reliability in case the OCSP responder is unavailable. Separate certificate profiles for users and devices ensure that the firewall can enforce different security policies based on the type of certificate (user vs. device). Automated certificate enrollment methods such as Group Policy or SCEP streamline certificate distribution to endpoints, ensuring efficient management of certificates across geographically dispersed
Topics
Community Discussion
No community discussion yet for this question.