Many of the services that Palo Alto Networks firewalls and Panorama provide require authentication, including administrator access to the web interface and end user access to Captive Portal, GlobalProtect portals, and GlobalProtect gateways. The authentication methods that you can configure vary by service, and can include Kerberos single sign-on (SSO), external authentication services, certificates and certificate profiles, local database accounts, RADIUS Vendor-Specific Attributes (VSAs), and NT LAN Manager (NTLM).
The following topics describe authentication methods that are common to most firewall and Panorama services, procedures to configure them, how to test authentication profiles, and how to troubleshoot authentication issues:

Related Documentation