Exam PCNSE All QuestionsBrowse all questions from this exam
Question 572

A consultant advises a client on designing an explicit Web Proxy deployment on PAN-OS 11.0. The client currently uses RADIUS authentication in their environment.

Which two pieces of information should the consultant provide regarding Web Proxy authentication? (Choose two.)

    Correct Answer: A, C

    For an explicit Web Proxy deployment on PAN-OS 11.0, RADIUS is not supported for authentication. Instead, Kerberos and SAML are the supported authentication methods for explicit Web Proxy. This means the client cannot use their existing RADIUS setup and will need to configure either Kerberos or SAML for authenticating users with the explicit Web Proxy.

Discussion
ajain6646Options: AC

Only SAML and Kerberos are supported for auth in Web Proxy

betko

This question was on exam in June 24.

tonjaOptions: AC

A and C

tonjaOptions: AC

A and C

MarshpillowzOptions: AC

A and C correct

PnosukeOptions: AC

A and C: For the explicit proxy method, the request contains the destination IP address of the configured proxy and the client browser sends requests to the proxy directly. You can use one of following methods to authenticate users with the explicit proxy: Kerberos, which requires a web proxy license. SAML 2.0, which requires Panorama, a Prisma Access license, the Cloud Services 3.2.1 plugin (and later versions), and the add-on web proxy license. Cloud Identity Engine, which requires Panorama, a Prisma Access license, the Cloud Services 3.2.1 plugin (and later versions), and the add-on web proxy license. https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/web-proxy#id3d1ea0dd-360f-44ee-8c48-30678c80d509_id2b5c6385-2ec6-4ba8-b1f1-2bea8b5139f5