
Panorama deployment options—physical, virtual, and cloud—cover licenses, management and log collectors, device groups, templates, policy order, onboarding, HA, upgrades, and RBAC.
Panorama centralizes management of multiple Palo Alto firewalls, enabling consolidated policy, central log management, template-based provisioning, and centralized updates across devices.
Explore panorama deployment options across physical, virtual, and cloud environments, including M200 and M600 appliances, esxi, kvm, hyper-v, nutanix, oci, and aws, azure, google, alibaba, with resource requirements.
Explore the three Panorama deployment modes - Panorama, management only, and log collector - and how each mode handles firewall management and log management across physical, virtual, or cloud appliances.
Deploy two identical Panorama appliances in active and passive roles with same hardware and reachability to managed firewalls, then manually sync configurations and assign primary and secondary priorities for failover.
Explore Palo Alto firewall licenses, including threat prevention, url filtering with dynamic url categories, wildfire sandboxing, dns security, autofocus, and Panorama device management licensing.
Configure Panorama's management interface, secure default credentials, set a static IP, and access via CLI or web to push firewall configurations and monitor logs.
Learn how to license a Panorama appliance online or offline, by entering the serial number to retrieve keys or registering CPU ID and UUID on the support portal.
Onboard a Palo Alto firewall into Panorama by adding it with its serial number and IP, configure primary and secondary Panorama servers and an authentication key, then commit.
Explore the panorama web UI, navigate core tabs like dashboard, monitor, and ACC, and learn to configure panorama settings, manage device groups and templates, and monitor connected firewalls.
Manage Palo Alto firewalls and virtual systems as device groups in Panorama, applying shared policies and objects across group members and supporting AWS, GCP, and Azure deployments.
Learn how Palo Alto Panorama uses a four-level device group hierarchy to inherit policies and objects from top to bottom, including a shared group for common configurations across firewalls.
Explore how Panorama templates manage network and device settings, enabling streamlined provisioning by applying templates and template stacks to multiple firewalls while reducing duplication of syslog, radius, and NTP configurations.
Group multiple templates into Panorama template stacks, assign stacks to firewall groups, and push global, DC-specific, and internet templates with ordered precedence so higher-level templates override lower-level ones.
Learn to create and map templates and template stacks in panorama, assign interfaces, virtual routers, zones, and syslog profiles, and push template-driven network settings to firewalls.
Learn to configure multiple firewalls with Palo Alto Panorama, using device groups, templates, and template stacks to manage four firewalls across two data centers.
Build a four-firewall lab topology in Palo Alto Panorama across two data centers, creating a multi-level device group hierarchy and multiple template stacks to manage policies and templates.
Create and configure Panorama templates—global, DC1 firewalls, and DC1 core five volts—set syslog, ntp, management, banner, and domain; build a template stack and commit to DC1 core firewall.
Build the DC2 core firewall in Palo Alto Panorama by configuring a template stack with DC2 firewall templates, including syslog and NTP settings, interfaces, zones, routing, and template variables.
Panorama template variables power a single template stack to configure multiple internet and dmz firewalls. Replace values via csv for interfaces, routing, ha group ids, and ike gateways.
Use template variables to build internet and dmz firewalls in DC1 and DC2 labs. Export and import csv files, push template stacks from Panorama, and manage overrides.
Learn how Panorama merges configurations from multiple templates in a template stack, with higher-priority templates taking precedence, and pushes the merged configuration to the firewall.
Explore how Panorama manages firewall policies and objects across device groups, detailing shared, parent, and child rules, pre and post sections, and push order for security, nat, and PBF.
Learn to create policies and objects in Panorama by using device groups, shared versus specific rules, top-down inheritance, and setting targets and zones on firewalls.
Master Panorama policy and object creation across DC1 and DC2 core and DMZ firewalls. Define zones, addresses, universal rules, test with ping, and verify logs after commits to devices.
Panorama modes include Panorama, management only, and log collector only; use device groups and templates, including template stacks, to manage policies, objects, and network settings across firewalls with scope controls.
Compare the running and candidate configurations in Palo Alto Panorama, showing how admins modify the candidate, commit changes to activate them, and how versioned backups enable rollback.
Learn how to manage firewall configurations with Panorama by using commit to Panorama, push to devices, and commit and push to activate candidate configurations across Panorama and devices.
Analyze the panorama configuration audit to compare running, candidate, and versioned configs for audit and troubleshooting, using red for removed, green for added, yellow for modified, and white for unchanged.
Learn to audit and compare Panorama configurations by choosing local versus running configs, selecting committed versions, and using color-coded diffs to identify changes during outages.
Learn to manage Panorama configurations by backing up, restoring, loading, exporting, and importing configurations across devices and templates, including candidate and snapshot saves, versioned exports, and scheduled auto backups.
Convert a panorama-managed firewall to direct management while preserving panorama post configurations and local objects. Backup, disable panorama settings, remove from template stacks and device groups, and commit changes.
Onboard a locally managed firewall to Panorama for central management, import its running configuration, and push the device config bundle to remove local firewall settings.
Palo Alto is a leading Network Security vendor providing next generation Firewalls and other products. Panorama is an offering of Palo Alto for central device and log management of the various Palo Alto products. In this course, we will cover -
1. Panorama's key features, the 3 Panorama modes, deployment options and licensing the Panorama
2. Onboard 4 x Firewalls onto Panorama and then use Panorama features like device groups, templates, template stacks and template variables to build 2 DCs with 2 firewalls in each
3. Understand the Pre and Post rule base on Panorama and how to use those for policy management of managed firewall
4. HA pre-requisites and how to setup Panorama HA across 2 appliances
5. Software upgrade of Standalone Panorama as well as Panorama HA cluster
6. Upgrading managed firewall from Panorama
7. Onboard locally managed firewall into Panorama for central management
8. Remove Panorama managed firewall for local firewall management keeping the Panorama pushed configurations
9. Use of Panorama for Log Management and how to setup Panorama as a local Log collector
10. Configuring the managed firewalls to forward various types of logs like traffic logs, system logs to Panorama
11. Role Based Access Control to Panorama appliance using the dynamic and custom roles to provide different access for different set of users
12. Common issues and ways to troubleshoot along with some useful tips
The course will comprise of theory and lab sessions to cover the above topics wherever possible and applicable