Palo Alto Networks Network Security Administration

Inquire now

This course introduces the essential knowledge and skills required to configure, manage, and monitor Palo Alto Networks next-generation firewalls. Participants explore firewall architecture, network interfaces, security zones, security policies, Network Address Translation (NAT), application control, user identification, and threat prevention. The course also covers logging, reporting, configuration maintenance, and basic troubleshooting to support everyday network security administration.


Duration 5 Days – 35 hrs.

Objectives

  • Explain the purpose and core capabilities of Palo Alto Networks next-generation firewalls.
  • Configure initial firewall settings and administrative access.
  • Configure network interfaces, security zones, and basic routing.
  • Create and manage security policies and NAT rules.
  • Apply App-ID to identify and control application traffic.
  • Explain User-ID and configure basic user-based access controls.
  • Configure security profiles to protect against common network threats.
  • Explain URL filtering, WildFire analysis, and encrypted traffic inspection.
  • Use firewall logs and monitoring tools to investigate traffic and security events.
  • Perform configuration backups, updates, and basic troubleshooting.

 

Target Audience 

  • Network administrators and network engineers.
  • Security administrators and junior security engineers.
  • IT support professionals responsible for firewall operations.
  • Security operations center analysts seeking firewall administration knowledge.
  • Systems administrators supporting secure network environments.
  • IT professionals developing foundational Palo Alto Networks security skills.

 

Prerequisites 

  • Working knowledge of TCP/IP networking.
  • Working knowledge of IP addressing and subnetting.
  • Working knowledge of routing and switching.
  • Working knowledge of DNS and common network protocols.
  • Familiarity with firewalls, access control, and NAT is recommended.
  • Familiarity with basic cybersecurity concepts is recommended.
  • Previous experience with Palo Alto Networks products is not required.


Course Outline
 

Day 1: Network Security Foundations and Firewall Setup

Module 1: Next-Generation Firewall Fundamentals

  • Network security challenges and common threats.
  • Traditional and next-generation firewall capabilities.
  • Palo Alto Networks firewall architecture.
  • Introduction to PAN-OS.
  • App-ID, User-ID, and Content-ID concepts.

 Module 2: Initial Configuration and Administration

  • Management interface configuration.
  • Web interface and command-line interface navigation.
  • Administrative accounts and role-based access.
  • Licensing and dynamic updates.
  • Configuration changes, commits, backups, and restoration.

 Module 3: Network Interfaces and Security Zones

  • Interface types and deployment options.
  • Layer 2, Layer 3, and virtual wire concepts.
  • Security zone configuration.
  • Virtual routers and basic routing.
  • Interface management profiles.

 

Day 2: Traffic Control and Policy Configuration

Module 4: Security Policy Fundamentals

  • Security policy structure and rule evaluation.
  • Source and destination zones.
  • Address objects and address groups.
  • Service objects and service groups.
  • Default rules, logging, and policy organization.

 Module 5: Network Address Translation

  • Source NAT and destination NAT.
  • Static and dynamic translation concepts.
  • NAT rule matching and ordering.
  • Relationship between NAT and security policies.
  • Common outbound access and inbound publishing scenarios.

 Module 6: Application-Based Policy with App-ID

  • Application identification concepts.
  • Application dependencies.
  • Application groups and filters.
  • Application-default services.
  • Transitioning from port-based to application-based policies.

 

 Day 3: Threat Prevention and Content Security

Module 7: Security Profiles

  • Security policies and security profile relationships.
  • Antivirus protection.
  • Anti-spyware protection.
  • Vulnerability protection.
  • File blocking and security profile groups.

 Module 8: URL Filtering and WildFire

  • URL categories and filtering actions.
  • Custom URL categories.
  • Web access controls.
  • WildFire analysis concepts.
  • File submission and verdict interpretation.
  • Subscription and update considerations.

 Module 9: Decryption Fundamentals

  • Encrypted traffic visibility.
  • SSL forward proxy and inbound inspection concepts.
  • Certificates and trust requirements.
  • Decryption policies and profiles.
  • Exceptions and common deployment considerations.

  

Day 4: User Identification and Operational Visibility

Module 10: User-ID and Authentication

  • User-to-IP address mapping.
  • Directory integration concepts.
  • Group mapping.
  • Authentication profiles.
  • User-based security policies.
  • Basic User-ID verification.

 Module 11: Logging, Monitoring, and Reporting

  • Traffic, threat, URL, and system logs.
  • Log filtering and event investigation.
  • Application Command Center.
  • Session monitoring.
  • Reports and log forwarding.

 Module 12: Firewall Maintenance

  • Configuration backup and recovery.
  • PAN-OS and content update planning.
  • Configuration comparison and change control.
  • Device health and resource monitoring.
  • Introduction to centralized management with Panorama.

Day 5: Availability and Troubleshooting

Module 13: High Availability Fundamentals

  • High availability concepts.
  • Active/passive deployment.
  • High availability links and synchronization.
  • Link and path monitoring.
  • Failover behavior and operational checks.

 Module 14: Basic Firewall Troubleshooting

  • A structured troubleshooting process.
  • Interface and routing verification.
  • Security policy and NAT rule verification.
  • Application and user identification issues.
  • Security profile and decryption issues.
  • Introduction to packet captures and diagnostic tools.

 Module 15: Integrated Firewall Administration

  • Applying network segmentation.
  • Combining application-based and user-based controls.
  • Applying consistent threat prevention profiles.
  • Reviewing policy usage and rule organization.
  • Maintaining documentation and operational readiness.

 

Inquire now

Best selling courses

CLOUD COMPUTING

Terraform

Terraform is a configuration orchestration tool for building and managing infrastructure on cloud & data centers. The course is instructor-led, live training (onsite or remote), and is designed for Engineers with little or no previous experience managing infrastructure. The course talks about in-depth Terraform syntax and techniques used to automate the setup and deployment of infrastructure.

Duration  3 days – 21 hrs    Overview    The ITIL Leadership – Digital and IT Strategy training course is designed for senior IT professionals, managers, and leaders who seek to navigate the complex landscape of digital transformation and IT strategy. This course focuses on providing strategic insights, leadership skills, and practical approaches for aligning...

PROGRAMMING / CODING

Spring Architecture and Design

Spring Cloud is a platform for building Java-based distributed systems and microservices. Building complex enterprise applications is challenging. Any change made to a part of the systems could trigger the need for changing the design of the entire system. By the end of this training, participants will have a solid understanding of Service-Oriented Architecture (SOA) and Microservice Architecture as well practical experience using Spring Cloud and related Spring technologies for rapidly developing their own cloud-scale, cloud-ready microservices.

BUSINESS INTELLIGENCE

Dax

Duration 5 days – 35 hrs   Overview The DAX (Data Analysis Expressions) Training Course is designed to provide participants with a comprehensive understanding of DAX, the powerful formula language used in Power BI, Excel, and SQL Server Analysis Services. This course covers the essential concepts, functions, and techniques required to create advanced calculations and...

OPERATING SYSTEMS

Linux Fundamentals

Linux Fundamental provides students a thorough introduction to Linux™ for those who are new to the Linux environment. Delegates will learn how to manage files and directories, utilize the vi editor, work with Linux security mechanisms to protect files and programs, work with the Linux shell to control the flow and processing of data through pipelines, design and write shell programs of moderate complexity, and manage multiple concurrent processes in order to achieve higher utilization of Linux. They will learn how to perform basic operations on the system and how quickly to solve problem.

PROGRAMMING / CODING

Google Apps Script

The Google Apps Script training course give you a detailed knowledge on coding like Automating data calculation, Fetching and sending data from third party software like Trello & Salesforce, connecting different sheets, Documents and other tools, Setting a trigger based on an event. This course is ideal for someone who use google sheets and have no coding background.

This workshop teaches the participants how to design and develop server side applications using the event-driven, non-blocking model framework Node.js. This program inducts the participant in some of the advanced concepts of the JavaScript language so that the participant is well equipped to build end-to-end application using JavaScript.

Duration: 3 days – 21 hrs   Overview This training course is designed to provide participants with a comprehensive understanding of Portfolio Management and Contract Management, focusing on best practices, tools, and techniques. The course covers the strategic alignment of projects within a portfolio, effective management of contracts, risk management, and optimization of resources to...

// BG EARTH WHEN NOT PLAYING

We use cookies on our website to personalize your experience by storing your preferences and recognizing repeat visits. By clicking “Accept”, you agree to the use of all cookies. You can also select “Cookie Settings” to adjust your preferences and provide more specific consent. Cookie Policy