PCNSE · Question #718
Which three external authentication services can the firewall use to authenticate admins into the Palo Alto Networks NGFW without creating administrator account on the local firewall? (Choose three.)
The correct answer is A. TACACS+ C. SAML D. RADIUS. TACACS+ (A), SAML (C), and RADIUS (D) are the three external authentication services that can authenticate firewall administrators without requiring a pre-created local administrator account on the firewall. These protocols support returning role/privilege information in the…
Question
Which three external authentication services can the firewall use to authenticate admins into the Palo Alto Networks NGFW without creating administrator account on the local firewall? (Choose three.)
Options
- ATACACS+
- BKerberos
- CSAML
- DRADIUS
- ELDAP
How the community answered
(53 responses)- A92% (49)
- B2% (1)
- E6% (3)
Explanation
TACACS+ (A), SAML (C), and RADIUS (D) are the three external authentication services that can authenticate firewall administrators without requiring a pre-created local administrator account on the firewall. These protocols support returning role/privilege information in the authentication response itself: RADIUS uses Vendor-Specific Attributes (VSAs) from Palo Alto Networks, TACACS+ returns admin role details from the server, and SAML carries attributes from the IdP that map to admin roles. Kerberos (B) and LDAP (E) can verify a user's identity, but PAN-OS still requires a matching local admin account on the firewall to determine the admin's role and access level - they authenticate credentials but do not carry authorization/role data back to the firewall.
Topics
Community Discussion
No community discussion yet for this question.