PCNSE · Question #148
Which Captive Portal mode must be configured to support MFA authentication?
The correct answer is B. Redirect. To support multi-factor authentication (MFA) with Captive Portal, the Redirect mode must be configured. This mode redirects users to a web page for authentication, where MFA can be integrated.
Question
Which Captive Portal mode must be configured to support MFA authentication?
Options
- ANTLM
- BRedirect
- CSingle Sign-On
- DTransparent
How the community answered
(28 responses)- B89% (25)
- C7% (2)
- D4% (1)
Why each option
To support multi-factor authentication (MFA) with Captive Portal, the Redirect mode must be configured. This mode redirects users to a web page for authentication, where MFA can be integrated.
NTLM is an authentication protocol primarily used for Windows network authentication and does not inherently support or enable MFA for Captive Portal in the way a redirect page does.
Redirect mode in Captive Portal explicitly redirects unauthenticated users' web browser traffic to a configurable authentication portal, allowing for integration with external authentication services that support MFA challenges before granting network access.
Single Sign-On (SSO) is an authentication method, but it's a feature that would be *used* with Captive Portal, not a Captive Portal *mode* itself for MFA enablement.
Transparent mode for Captive Portal intercepts traffic without explicit redirection, which typically prevents the necessary user interaction and external page redirection required for MFA.
Concept tested: Captive Portal modes for MFA
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/authentication/configure-captive-portal
Topics
Community Discussion
No community discussion yet for this question.