Module 4 Managing Accounts Flashcards
What type of user accounts does PAN-OS software support?
LDAP, AD, Kerberos, RADIUS, TACACS+ and SAML
What three types of authentication services are supported?
Local, external and multi-factor authentication
How many local authentication services are there?
2: Local auth without a database and local authentication with a database.
What is local authentication w/o a database?
Username and password stored on the firewall in the XML configuration file of the firewall.
What is local authentication w a database?
Username and password stored on the firewall in a local user database. The firewall can use this service to authenticate logins to the firewall, and user traffic flowing through the firewall, like to webmail, where authentication is required. (Users connecting to local sources)
Authentication Profile and Authentication Services - what is the difference?
You can configure each user individually on the firewall, with their own authentication profile…or you can configure all users to use the same authentication profile and authentication service (LDAP, RADIUS, TACACS+)
Configure Authentication “Through the Firewall”
You can also configure the firewall to authenticate user credentials when uses attempt to access network resources THROUGH the firewall - like webmail.
How many types of admin role profiles are there?
Two - dynamic admin role profiles are built in and have a predefined set of permissions
How many dynamic admin roles
6: Superuser, Superuser (read-only), Device administrator, device administrator (read-only), Virtual Systems administrator and Virtual Systems administrator (read-only)
What is the difference between all three admin roles?
Device administrator cannot create new accounts, or virtual systems. Virtual admins can only manage those virtual systems assigned to them. (Also virtual admins do not have access to firewalls network-level functions such as network interfaces, etc)
How to create a Local (Non Database Admin Account
Device - admin
How to create a local Database Authentication Profile
An authentication profile links in a username to the authentication service that the firewall must use to authenticate the users login credentials.