In PAN-OS 11.1, you can define authentication profiles and sequences to manage how users and administrators authenticate to the firewall. Authentication profiles specify the authentication service (e.g., LDAP, RADIUS, SAML, Kerberos, local database) and associated settings. Authentication sequences allow the firewall to attempt multiple authentication profiles in a specified order until one succeeds.
Set up server profiles for the authentication services you plan to use:
If using local authentication:
If using Kerberos single sign-on (SSO):
Steps to create an authentication profile:
Device > Authentication Profile
and click
Add
.
Steps to create an authentication sequence:
Device > Authentication Sequence
and click
Add
.
Assign the configured authentication profile or sequence to:
Device > Setup > Management
, edit the
Authentication Settings
, and select the authentication profile.
After configuration, verify that the firewall can authenticate users by testing the authentication server connectivity.