Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementMedium

A security engineer is configuring administrative access to a new Palo Alto Networks firewall. The company policy dictates that all administrative logins must use a centralized authentication system and secure protocols. Which combination of settings should the engineer configure on the firewall to meet these requirements?

  1. ARADIUS server profile and SSH/HTTPS for management access.
  2. BLocal user database and HTTP/Telnet for management access.
  3. CLDAP server profile and SNMPv2c for management access.
  4. DTACACS+ server profile and FTP/HTTP for management access.
Show answer & explanation

Correct answer: A. RADIUS server profile and SSH/HTTPS for management access.

To use a centralized authentication system, an external authentication server profile (like RADIUS, LDAP, or TACACS+) must be configured. For secure protocols, SSH (for CLI) and HTTPS (for WebUI) are the standard choices for Palo Alto Networks firewalls.

Why the other options are wrong

  • B. Local user database is not centralized. HTTP/Telnet are insecure protocols.
  • C. LDAP is centralized, but SNMPv2c is for monitoring, not administrative login, and is less secure than SNMPv3.
  • D. TACACS+ is centralized, but FTP/HTTP are insecure and not used for administrative login to the WebUI/CLI.

Secure Administrative Access

Configuring a Palo Alto Networks firewall to allow administrative logins using centralized authentication and encrypted protocols.

  • Centralized auth: RADIUS, LDAP, TACACS+.
  • Secure protocols: HTTPS (WebUI), SSH (CLI).
  • Management profiles restrict access by IP/interface.

Memory trick: Centralized keys, encrypted doors: That's how admins get in.

More Initial Configuration and Management questions