PCNSE · Question #254
Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)
The correct answer is A. TACACS+ E. SAML F. RADIUS. External service The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor- Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes
Question
Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)
Options
- ATACACS+
- BKerberos
- CPAP
- DLDAP
- ESAML
- FRADIUS
How the community answered
(33 responses)- A88% (29)
- B6% (2)
- C3% (1)
- D3% (1)
Explanation
External service The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor- Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML server. PAN-OS maps the attributes to administrator roles, access domains, user groups, and virtual systems that you define on the firewall. For details, see: Configure SAML Authentication Configure TACACS+ Authentication Configure RADIUS Authentication https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/firewall-administration/manage- firewall-administrators/administrative-authentication.html
Topics
Community Discussion
No community discussion yet for this question.