Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationEasy
A security administrator needs to configure a security policy rule that allows internal users to access web servers, but only if they belong to the 'IT-Admins' Active Directory group. The firewall is integrated with Active Directory using User-ID. Which security policy configuration parameter is essential for enforcing this group-based access control?
- ASource Zone: Trust, Destination Zone: Untrust, Source User: IT-Admins, Application: web-browsing, ssl, Service: application-default, Action: allow
- BSource Zone: Trust, Destination Zone: Untrust, Source Address: any, Application: web-browsing, ssl, Service: application-default, Action: allow
- CSource Zone: Trust, Destination Zone: Untrust, Source IP: IT-Admins_IP_Range, Application: web-browsing, ssl, Service: application-default, Action: allow
- DSource Zone: Trust, Destination Zone: Untrust, Source User: any, Application: web-browsing, ssl, Service: application-default, Action: allow
Show answer & explanationAnswer & explanation
Correct answer: A. Source Zone: Trust, Destination Zone: Untrust, Source User: IT-Admins, Application: web-browsing, ssl, Service: application-default, Action: allow
To enforce access based on Active Directory groups, the 'Source User' field in the security policy rule must be configured with the specific user group (e.g., 'IT-Admins'). This leverages User-ID's ability to map IP addresses to users and their group memberships, allowing policies to be applied based on identity.
Why the other options are wrong
- B. Using 'Source Address: any' allows anyone from the internal network, not just 'IT-Admins'.
- C. Relying on 'Source IP' for group-based access is not effective as user IPs can change, and it doesn't leverage the dynamic nature of User-ID's group mapping.
- D. Using 'Source User: any' allows any identified user, not just those in the 'IT-Admins' group.
User-ID in Security Policies
User-ID allows Palo Alto Networks firewalls to integrate with directory services (e.g., Active Directory) to identify users and their group memberships, enabling user-based security policies.
- Policies can be written based on users or user groups instead of just IP addresses.
- Requires integration with a directory service (e.g., LDAP, Active Directory).
- User-ID agents or WMI probing collect user-to-IP mappings.
- The 'Source User' field in security rules is used to specify users/groups.
Memory trick: User-ID: Know the user, know the group, then policy will swoop.