External authentication objects for Cloud-Delivered Firewall Management Center

An external authentication object is a security configuration element that

  • enables the Cloud-Delivered Firewall Management Center to verify user credentials with LDAP or RADIUS servers

  • supports multiple objects for web interface access, allowing users from any configured object to authenticate, and

  • restricts CLI access to a single external authentication object, permitting authentication only through the first object in the list.

External authentication object usage and configuration

External authentication objects can be used by the Cloud-Delivered Firewall Management Center and Firewall Threat Defense devices. You can either share the same object across different devices or create distinct objects for each device type.

For the Cloud-Delivered Firewall Management Center, enable the external authentication objects directly on the Administration > Users > External Authentication tab. This setting affects only Cloud-Delivered Firewall Management Center usage. You do not need to enable it on this tab for managed device usage. For Firewall Threat Defense devices, enable the external authentication object in the platform settings that you deploy to the devices.

Define web interface users and CLI users separately in the external authentication object. For RADIUS, pre-configure the list of CLI usernames in the object. For LDAP, set up a filter on the LDAP server to match CLI users.

Note

Users with CLI access can gain Linux shell access with the expert command. Linux shell users can obtain root privileges. This access creates a security risk. Make sure you:

  • Restrict the list of users with CLI or Linux shell access.

  • Do not create Linux shell users.

External authentication object configuration example

If you have five external authentication objects configured for web interface access, users from any of them can be authenticated to access the web interface. For CLI access, only the first external authentication object in the list is used for authentication.

Unsupported external authentication object scenario

You cannot use an LDAP object for CLI access if it is also configured for CAC authentication.

External authentication object analogy

An external authentication object functions as a control point, permitting access only to users with valid credentials from specified sources.