Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium

A company is implementing GlobalProtect for remote users and requires that all users authenticate against their existing Active Directory infrastructure. Which configuration element is essential for this requirement?

  1. ARADIUS Server Profile
  2. BKerberos Authentication Profile
  3. CLDAP Authentication Profile
  4. DSAML Identity Provider
Show answer & explanation

Correct answer: C. LDAP Authentication Profile

Active Directory primarily uses LDAP (Lightweight Directory Access Protocol) for directory services and authentication. Therefore, an LDAP Authentication Profile is required to integrate GlobalProtect with Active Directory.

Why the other options are wrong

  • A. RADIUS is a common authentication protocol, but Active Directory natively uses LDAP for directory services.
  • B. Kerberos is an authentication protocol but is typically integrated via LDAP for directory lookups in Active Directory.
  • D. SAML is an XML-based standard for exchanging authentication and authorization data, often used with identity providers, but not the direct protocol for Active Directory.

LDAP Authentication Profile

An LDAP Authentication Profile on a Palo Alto Networks firewall defines how the firewall connects to and authenticates users against an LDAP directory service, such as Active Directory.

  • Used for user authentication against directories.
  • Requires server address, base DN, bind DN, and password.
  • Essential for integrating with Active Directory for GlobalProtect.

Memory trick: GlobalProtect needs a 'Look-Up Directory Access Profile' for its remote users.

More Deploy and Configure questions