Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementEasy
A network administrator is setting up a new Palo Alto Networks firewall and needs to configure the management interface to allow only specific administrative services from a defined management subnet. Which feature should be used to restrict access to the management interface?
- AManagement Profile
- BSecurity Policy Rule
- CZone Protection Profile
- DVirtual Router
Show answer & explanationAnswer & explanation
Correct answer: A. Management Profile
A Management Profile is specifically designed to control which services (e.g., HTTPS, SSH, Ping) are allowed on an interface and from which source IP addresses. This is applied directly to the management interface to secure administrative access.
Why the other options are wrong
- B. Security Policy rules control data plane traffic passing through the firewall, not access to the firewall's own management interface.
- C. Zone Protection Profiles protect zones from flood attacks and reconnaissance, but do not control administrative access to the management interface.
- D. Virtual Routers handle routing for data plane traffic within and between zones, not management interface access.
Management Profile
A configuration object in Palo Alto Networks firewalls that controls access to the firewall's interfaces, specifying allowed services and source IP addresses.
- Applied to physical or virtual interfaces (including management).
- Restricts administrative services (HTTPS, SSH, Ping, SNMP).
- Enhances security by limiting management access.
Memory trick: The Management Profile is the bouncer for the firewall's admin door.