Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementMedium
A company is deploying a Palo Alto Networks firewall and needs to ensure that only authorized administrators can access the device's management interface. They want to restrict access based on the source IP address of the administrative workstation. Where would this restriction be configured?
- ANetwork > Interfaces > Management Interface Settings
- BDevice > Setup > Management > Permitted IP Addresses
- CPolicies > Security > Management Access Rule
- DNetwork > Zones > Management Zone Settings
Show answer & explanationAnswer & explanation
Correct answer: B. Device > Setup > Management > Permitted IP Addresses
To restrict administrative access to the firewall's management interface based on source IP address, you configure 'Permitted IP Addresses' under Device > Setup > Management. This explicitly defines which IP addresses are allowed to connect to the MGT interface.
Why the other options are wrong
- A. While the management interface settings define its IP and general access, the specific IP-based restriction list is found under Device > Setup > Management.
- C. Security policies apply to traffic passing through data plane interfaces, not directly to the management interface itself.
- D. Management zones are not a standard feature for IP-based management access restrictions.
Management Access Restriction
The ability to limit which source IP addresses are permitted to access a Palo Alto Networks firewall's management interface (web UI, SSH, SNMP).
- Enhances security by reducing attack surface.
- Configured under Device > Setup > Management.
- Allows specific IP addresses or subnets.
Memory trick: Lock down the admin's door by checking their IP at the Device's setup for Management.