This course introduces the essential knowledge and skills required to configure, manage, and monitor Palo Alto Networks next-generation firewalls. Participants explore firewall architecture, network interfaces, security zones, security policies, Network Address Translation (NAT), application control, user identification, and threat prevention. The course also covers logging, reporting, configuration maintenance, and basic troubleshooting to support everyday network security administration.
Duration 5 Days – 35 hrs.
Objectives
- Explain the purpose and core capabilities of Palo Alto Networks next-generation firewalls.
- Configure initial firewall settings and administrative access.
- Configure network interfaces, security zones, and basic routing.
- Create and manage security policies and NAT rules.
- Apply App-ID to identify and control application traffic.
- Explain User-ID and configure basic user-based access controls.
- Configure security profiles to protect against common network threats.
- Explain URL filtering, WildFire analysis, and encrypted traffic inspection.
- Use firewall logs and monitoring tools to investigate traffic and security events.
- Perform configuration backups, updates, and basic troubleshooting.
Target Audience
- Network administrators and network engineers.
- Security administrators and junior security engineers.
- IT support professionals responsible for firewall operations.
- Security operations center analysts seeking firewall administration knowledge.
- Systems administrators supporting secure network environments.
- IT professionals developing foundational Palo Alto Networks security skills.
Prerequisites
- Working knowledge of TCP/IP networking.
- Working knowledge of IP addressing and subnetting.
- Working knowledge of routing and switching.
- Working knowledge of DNS and common network protocols.
- Familiarity with firewalls, access control, and NAT is recommended.
- Familiarity with basic cybersecurity concepts is recommended.
- Previous experience with Palo Alto Networks products is not required.
Course Outline
Day 1: Network Security Foundations and Firewall Setup
Module 1: Next-Generation Firewall Fundamentals
- Network security challenges and common threats.
- Traditional and next-generation firewall capabilities.
- Palo Alto Networks firewall architecture.
- Introduction to PAN-OS.
- App-ID, User-ID, and Content-ID concepts.
Module 2: Initial Configuration and Administration
- Management interface configuration.
- Web interface and command-line interface navigation.
- Administrative accounts and role-based access.
- Licensing and dynamic updates.
- Configuration changes, commits, backups, and restoration.
Module 3: Network Interfaces and Security Zones
- Interface types and deployment options.
- Layer 2, Layer 3, and virtual wire concepts.
- Security zone configuration.
- Virtual routers and basic routing.
- Interface management profiles.
Day 2: Traffic Control and Policy Configuration
Module 4: Security Policy Fundamentals
- Security policy structure and rule evaluation.
- Source and destination zones.
- Address objects and address groups.
- Service objects and service groups.
- Default rules, logging, and policy organization.
Module 5: Network Address Translation
- Source NAT and destination NAT.
- Static and dynamic translation concepts.
- NAT rule matching and ordering.
- Relationship between NAT and security policies.
- Common outbound access and inbound publishing scenarios.
Module 6: Application-Based Policy with App-ID
- Application identification concepts.
- Application dependencies.
- Application groups and filters.
- Application-default services.
- Transitioning from port-based to application-based policies.
Day 3: Threat Prevention and Content Security
Module 7: Security Profiles
- Security policies and security profile relationships.
- Antivirus protection.
- Anti-spyware protection.
- Vulnerability protection.
- File blocking and security profile groups.
Module 8: URL Filtering and WildFire
- URL categories and filtering actions.
- Custom URL categories.
- Web access controls.
- WildFire analysis concepts.
- File submission and verdict interpretation.
- Subscription and update considerations.
Module 9: Decryption Fundamentals
- Encrypted traffic visibility.
- SSL forward proxy and inbound inspection concepts.
- Certificates and trust requirements.
- Decryption policies and profiles.
- Exceptions and common deployment considerations.
Day 4: User Identification and Operational Visibility
Module 10: User-ID and Authentication
- User-to-IP address mapping.
- Directory integration concepts.
- Group mapping.
- Authentication profiles.
- User-based security policies.
- Basic User-ID verification.
Module 11: Logging, Monitoring, and Reporting
- Traffic, threat, URL, and system logs.
- Log filtering and event investigation.
- Application Command Center.
- Session monitoring.
- Reports and log forwarding.
Module 12: Firewall Maintenance
- Configuration backup and recovery.
- PAN-OS and content update planning.
- Configuration comparison and change control.
- Device health and resource monitoring.
- Introduction to centralized management with Panorama.
Day 5: Availability and Troubleshooting
Module 13: High Availability Fundamentals
- High availability concepts.
- Active/passive deployment.
- High availability links and synchronization.
- Link and path monitoring.
- Failover behavior and operational checks.
Module 14: Basic Firewall Troubleshooting
- A structured troubleshooting process.
- Interface and routing verification.
- Security policy and NAT rule verification.
- Application and user identification issues.
- Security profile and decryption issues.
- Introduction to packet captures and diagnostic tools.
Module 15: Integrated Firewall Administration
- Applying network segmentation.
- Combining application-based and user-based controls.
- Applying consistent threat prevention profiles.
- Reviewing policy usage and rule organization.
- Maintaining documentation and operational readiness.

