Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementMedium

A security auditor recommends restricting administrative access to the Palo Alto Networks firewall to specific trusted IP addresses only. Which feature should the network administrator configure to implement this recommendation for both web interface (HTTPS) and CLI (SSH) access?

  1. AService Routes
  2. BManagement Interface Profile
  3. CSecurity Policies
  4. DAuthentication Profiles
Show answer & explanation

Correct answer: B. Management Interface Profile

The Management Interface Profile is specifically designed to control which services (like HTTPS, SSH, Ping, SNMP) are allowed on the management interface and from which source IP addresses or networks, providing granular control over administrative access.

Why the other options are wrong

  • A. Service Routes define which interface outgoing services use, not who can access the firewall's management services.
  • C. Security Policies control traffic THROUGH the firewall, not traffic TO the firewall's management plane.
  • D. Authentication Profiles define how users are authenticated, not which IP addresses are allowed to attempt authentication.

Management Interface Profile

A Management Interface Profile on a Palo Alto Networks firewall defines which administrative services (HTTPS, SSH, Ping, SNMP, etc.) are permitted on a specific interface, and from which source IP addresses.

  • Controls access to the firewall's management plane.
  • Applied per interface (management, data plane interfaces).
  • Includes allowed services and IP addresses/ranges.

Memory trick: Management Profile Protects Privileged Ports.

More Initial Configuration and Management questions