
Kick off the Palo Alto firewall administration course with hands-on labs using Gns3 to practice basic administration configuration and common firewall tasks.
Set up the lab with Gns3, import the Gns3 VM and the Gns3 all-in-one, and use the prerequisite folder to run Palo Alto and Cisco images.
Complete the GNS3 lab setup by linking the all-in-one with the GNS3 VM, configuring the Janus three VM in VMware, and importing Palo Alto, Cisco switch, and router images.
Build the lab topology and access the Palo Alto firewall via console and https. Configure a static management IP and admin credentials, then commit changes to apply the running configuration.
Change the Palo Alto firewall admin password securely using the GUI and CLI, commit the changes, enable public key authentication, and verify the new credentials.
Learn to create multiple admin accounts on a Palo Alto firewall, assign dynamic or rule-based roles, enforce password profiles, and ensure accountability via logs.
Back up and restore Palo Alto firewall configurations using revert, save, load, and export options. Understand candidate vs running configurations, named snapshots, and device state exports.
Learn to automate Palo Alto firewall backups using the API to export the configuration and save it securely, with cross‑platform steps for Linux and Windows.
Configure and verify the NTP server address on the Palo Alto firewall, establish primary and secondary NTP servers, and confirm correct time for logs and schedules.
Learn how security zones group firewall interfaces to control traffic between trusted LAN and untrusted networks, assign interfaces to zones, and create policies to permit inter-zone communication.
Create trusted and untrusted security zones in the Palo Alto firewall GUI, assign layer 3 type, configure interface membership, and commit changes for zone-based security.
Learn to configure a layer 3 interface on a Palo Alto firewall, assign it to trusted and untrusted zones, set static IPs, and verify connectivity using GUI and CLI.
Configure and test interface management profiles on a Palo Alto firewall, enabling ping, https, and ssh access; assign profiles to interfaces and verify connectivity.
The Palo Alto firewall can act as a DHCP server, assigning IP addresses, gateway, DNS, and other options via pools, reservations, and custom options.
Configure a Palo Alto firewall as a DHCP relay to forward client requests to an external DHCP server and enable DHCP traffic between trusted and DMZ zones.
Configure a default static route on the Palo Alto firewall to enable internet access from the trusted network via the untrusted egress interface, and test with a ping.
Learn to configure a pat nat policy on a palo alto firewall, translating 192.168.1.0/24 to a single public IP via interface address on Ethernet 1/1, with a CLI example.
Apply destination NAT to map a public IP to a private web server in the DMZ, enabling port forwarding and external access while testing connectivity through a Palo Alto firewall.
Configure a basic security policy on a Palo Alto firewall to allow trusted zone traffic to an untrusted zone, using stateful session tracking to permit returning traffic.
Configure destination nat from untrusted to untrusted to expose a dmz web server via a public ip, create translated addresses, and verify with security rules and cli.
Configure VLANs on a Cisco switch, enable IP routing with VLAN interfaces, assign hosts to VLANs, and implement static routes and Palo Alto firewall policies to provide internet access.
Configure inter vlan routing on a Palo Alto firewall to enable VLAN to VLAN traffic. Use either the intra-zone policy override or a dedicated inter-VLAN policy for granular control.
Configure vlan 100 dmz and vlan 200 trusted on switch and Palo Alto firewall, using a trunk, and enable DHCP relay to publish a web server.
Enable user-id with LDAP to map IP addresses to usernames from Active Directory, improving network visibility. Apply user-based policies in trusted and DMZ zones to tighten security and control access.
Learn to configure Palo Alto firewall User-ID via CLI, including LDAP source interface, enabling user identification in zones, LDAP server profile, user ID collector, group mapping, and LDAP authentication profiles.
Configure ldap over tls by issuing and importing a certificate on the Active Directory server. Apply it to the Palo Alto firewall and verify tls over port 636.
PaloAlto Firewall Administration Course is a course that will teach you how to administrate your PaloAlto firewall , from zero.
Because every lecture of this course is a LAB you will learn how to install, configure, manage and troubleshoot your PaloAlto firewall, that means that it's a practical course more than theoretical, so i want you to complete each lab and put your hands on configuration as soon as you can for a better understanding, because one of the best ways to learn is by doing.
We will use GNS3 to create labs i will show you how to setup it and use it, and for the course content we will see all the things that you as an administrator will need to deal with using PaloAlto firewall like :
- Basic setup.
- How To Access.
- Administrator Users Management.
- DHCP Server and Relay configuration.
- NTP Client Setup.
- Security Zones.
- interfaces configuration including vlans, Layer3 and more.
- Configuration Backup and Restore.
- Backup Automation.
- Routing.
- NAT
- Port Forwarding.
- Firewall Policies to allow or deny traffic.
- Authentication: User-ID With LDAP
AND Much More.
So without wasting your time i will let you start your journey with PaloAlto, if you have any question please don't hesitate to ask me and good luck.