PCNSE · Question #748
A consultant advises a client on designing an explicit Web Proxy deployment on PAN-OS 11.0. The client currently uses RADIUS authentication in their environment. Which two pieces of information should
The correct answer is A. Kerberos or SAML authentication need to be configured. C. RADIUS is not supported for explicit or transparent Web Proxy.. For the explicit proxy method, the request contains the destination IP address of the configured proxy and the client browser sends requests to the proxy directly. You can use one of following methods to authenticate users with the explicit proxy: Kerberos, which requires a web p
Question
A consultant advises a client on designing an explicit Web Proxy deployment on PAN-OS 11.0. The client currently uses RADIUS authentication in their environment. Which two pieces of information should the consultant provide regarding Web Proxy authentication? (Choose two.)
Options
- AKerberos or SAML authentication need to be configured.
- BRADIUS is only supported for a transparent Web Proxy.
- CRADIUS is not supported for explicit or transparent Web Proxy.
- DLDAP or TACACS+ authentication need to be configured.
How the community answered
(42 responses)- A74% (31)
- B10% (4)
- D17% (7)
Explanation
For the explicit proxy method, the request contains the destination IP address of the configured proxy and the client browser sends requests to the proxy directly. You can use one of following methods to authenticate users with the explicit proxy: Kerberos, which requires a web proxy license. SAML 2.0, which requires Panorama, a Prisma Access license, the Cloud Services 3.2.1 plugin (and later versions), and the add-on web proxy license. Cloud Identity Engine, which requires Panorama, a Prisma Access license, the Cloud Services 3.2.1 plugin (and later versions), and the add-on web proxy license. https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/web- proxy#id3d1ea0dd-360f-44ee-8c48-30678c80d509_id2b5c6385-2ec6-4ba8-b1f1-2bea8b5139f5
Topics
Community Discussion
No community discussion yet for this question.