Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium
A company is implementing GlobalProtect for remote users to securely access internal resources. The security team wants to ensure that users are authenticated against their existing Microsoft Active Directory infrastructure. Which external authentication method should be configured on the Palo Alto Networks firewall for GlobalProtect portals and gateways?
- AKerberos
- BLDAP
- CRADIUS
- DSAML
Show answer & explanationAnswer & explanation
Correct answer: B. LDAP
LDAP (Lightweight Directory Access Protocol) is the standard protocol for querying and modifying directory services like Microsoft Active Directory. Configuring an LDAP authentication profile on the Palo Alto Networks firewall allows it to authenticate GlobalProtect users directly against the Active Directory server.
Why the other options are wrong
- A. Kerberos is a network authentication protocol that works on the basis of 'tickets' to allow nodes communicating over a non-secure network to prove their identity to one another securely. While used by Active Directory, LDAP is the protocol the firewall uses to query it.
- C. RADIUS (Remote Authentication Dial-In User Service) is a networking protocol providing centralized Authentication, Authorization, and Accounting (AAA) management for users, often used with VPNs but not the primary for Active Directory integration.
- D. SAML (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between identity providers and service providers, often used for SSO.
External Authentication Profiles
Palo Alto Networks firewalls can integrate with external directory services or authentication servers to authenticate users for various services like GlobalProtect, VPNs, or administrator access.
- Supports LDAP, RADIUS, TACACS+, SAML, Kerberos.
- Configured under Device > Authentication Profile.
- Used to centralize user management and authentication.
Memory trick: GlobalProtect Connects with LDAP for AD Users.