Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureEasy
A network security engineer is deploying a new Palo Alto Networks firewall and needs to ensure that all management traffic (SSH, HTTPS, SNMP) to the firewall itself is restricted to a specific management network. Which configuration element should be applied to the interface designated for management access?
- AZone Protection Profile
- BManagement Profile
- CVirtual Router
- DSecurity Policy Rule
Show answer & explanationAnswer & explanation
Correct answer: B. Management Profile
Management Profiles are used to control access to the firewall's management interfaces, specifying allowed services and source IP addresses. This ensures only authorized traffic can reach the firewall's control plane.
Why the other options are wrong
- A. Zone Protection Profiles defend against flood attacks and reconnaissance within or between zones, not direct management access.
- C. Virtual Routers handle routing decisions for data plane traffic, not management plane access control.
- D. Security Policy Rules control traffic passing THROUGH the firewall, not TO the firewall's management interface.
Management Profile
A configuration object in Palo Alto Networks firewalls that defines which administrative services (like SSH, HTTPS, SNMP) are allowed on a specific interface and from which source IP addresses.
- Controls access TO the firewall's management plane.
- Applied to specific interfaces (e.g., Management, Ethernet interfaces).
- Includes services like SSH, HTTPS, Ping, SNMP, User-ID agent.
Memory trick: Manage Your Access Points with a Profile.