Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium
A security engineer is configuring a site-to-site VPN between two Palo Alto Networks firewalls. The goal is to ensure that only authenticated and authorized devices can establish the VPN tunnel. Which authentication method is commonly used and recommended for establishing secure IPsec VPN tunnels between firewalls?
- AKerberos authentication
- BPre-shared Key (PSK)
- CCertificate-based authentication
- DUser-based authentication
Show answer & explanationAnswer & explanation
Correct answer: C. Certificate-based authentication
Certificate-based authentication is the recommended and most secure method for site-to-site VPNs, providing mutual authentication, improved scalability, and protection against brute-force attacks compared to PSKs.
Why the other options are wrong
- A. Kerberos is an authentication protocol primarily used within a domain for user and service authentication, not for IPsec tunnel establishment between firewalls.
- B. Pre-shared Keys are simpler but less secure and harder to manage at scale, making them less recommended for high-security environments.
- D. User-based authentication is typically used for remote access VPNs, not site-to-site connections between devices.
Certificate-based Authentication for VPN
Using X.509 digital certificates to mutually authenticate VPN peers, providing strong identity verification and key exchange.
- Provides stronger security than Pre-shared Keys.
- Enables mutual authentication (both sides verify each other).
- Scales better for multiple VPN connections.
- Requires a Public Key Infrastructure (PKI) for certificate management.
Memory trick: Certificates are the key, for a VPN that's truly free!