Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium
A security engineer is configuring a new GlobalProtect VPN portal and gateway. The company policy requires that all users connecting to GlobalProtect must use two-factor authentication (2FA) provided by a RADIUS server. Which two components are essential to configure on the Palo Alto Networks firewall to meet this requirement?
- AA Group Mapping configuration for RADIUS and a GlobalProtect Gateway Security Policy.
- BA Local User Database and an Authentication Sequence that includes RADIUS.
- CA RADIUS Server Profile and an Authentication Profile that uses the RADIUS Server Profile.
- DAn Authentication Profile that uses LDAP and an Authentication Policy for GlobalProtect.
Show answer & explanationAnswer & explanation
Correct answer: C. A RADIUS Server Profile and an Authentication Profile that uses the RADIUS Server Profile.
To use RADIUS for 2FA, the firewall needs a RADIUS Server Profile to define how to connect to the RADIUS server. Then, an Authentication Profile must be created that references this RADIUS Server Profile and is configured for GlobalProtect authentication. This Authentication Profile is then applied to the GlobalProtect Portal and/or Gateway.
Why the other options are wrong
- A. Group Mapping is for retrieving user group information, not for authenticating users. A GlobalProtect Gateway Security Policy is a security rule, not an authentication mechanism.
- B. A Local User Database stores users locally on the firewall, which is not suitable for 2FA via an external RADIUS server. An Authentication Sequence could include RADIUS, but the fundamental components are the RADIUS Server Profile and the Authentication Profile.
- D. LDAP is for directory services, not typically for 2FA via RADIUS. An Authentication Policy is used to enforce authentication, but the core components for RADIUS 2FA are the server and authentication profiles.
GlobalProtect RADIUS 2FA
Configuring GlobalProtect to authenticate users using a RADIUS server, commonly for two-factor authentication, by defining the RADIUS server and an authentication profile.
- RADIUS Server Profile defines connectivity to the RADIUS server.
- Authentication Profile references the RADIUS Server Profile.
- Authentication Profile is applied to the GlobalProtect Portal and/or Gateway.
Memory trick: RADIUS is the server, Profile is the method.