PCNSE · Question #225
Which three authentication services can an administrator use to authenticate admins into the Palo Alto Networks NGFW without defining a corresponding admin account on the local firewall? (Choose…
The correct answer is C. SAML D. TACACS+ E. RADIUS. The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor- Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML…
Question
Which three authentication services can an administrator use to authenticate admins into the Palo Alto Networks NGFW without defining a corresponding admin account on the local firewall? (Choose three.)
Options
- AKerberos
- BPAP
- CSAML
- DTACACS+
- ERADIUS
- FLDAP
How the community answered
(55 responses)- A2% (1)
- B4% (2)
- C89% (49)
- F5% (3)
Explanation
The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor- Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML server. PAN-OS maps the attributes to administrator roles, access domains, user groups, and virtual systems that you define on the firewall. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/firewall-administration/manage- firewall-administrators/administrative-authentication
Topics
Community Discussion
No community discussion yet for this question.