Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium

A company is integrating their Palo Alto Networks firewall with an existing Active Directory infrastructure to provide user-based security policies for internal users. They need to ensure that the firewall can query Active Directory for user and group information. Which authentication profile type is primarily used for this integration to retrieve user identity information?

  1. ASAML
  2. BLDAP
  3. CRADIUS
  4. DTACACS+
Show answer & explanation

Correct answer: B. LDAP

LDAP (Lightweight Directory Access Protocol) is the standard protocol used by Palo Alto Networks firewalls to query Active Directory for user and group information, enabling user-based security policies.

Why the other options are wrong

  • A. SAML is an XML-based standard for exchanging authentication and authorization data between security domains, often used for SSO, not direct AD querying for User-ID.
  • C. RADIUS is primarily for authentication and authorization (e.g., VPN access), not for querying user/group identity for security policies.
  • D. TACACS+ is a Cisco proprietary protocol primarily used for device administration authentication, authorization, and accounting.

LDAP Authentication Profile

An authentication profile in Palo Alto Networks firewalls that uses the Lightweight Directory Access Protocol (LDAP) to query directory services like Active Directory for user and group information, enabling user-based security policies.

  • Used for retrieving user and group memberships from Active Directory.
  • Enables User-ID for policy enforcement.
  • Can also be used for authentication (e.g., GlobalProtect, admin login).
  • Requires specifying LDAP server IP, base DN, bind DN, and password.

Memory trick: LDAP links users to the firewall.

More Deploy and Configure questions