
Configure SNMP on the Palo Alto firewall, enable traps, and define a SNMP server profile using UDP 161/162 and version 2 (or 3) for monitoring.
Learn to configure syslog on a Palo Alto firewall by creating a syslog server profile, applying a log forwarding profile to a security policy, and understanding log severity levels 0–7.
Learn how to manage configuration backups for running and candidate configurations, save backup versions, and restore or revert to previous configurations using export, import, and config audit snapshots.
Learn to manage locks on Palo Alto firewall to restrict config changes and commits, understand candidate and running configs, and coordinate multi-admin backups and restores.
Discover how Palo Alto firewall user ID and captive portal enforce security policies by user identity, integrate with Active Directory, LDAP, Radius, and Kerberos, and provide detailed user-based logs.
Learn to read PanOS version numbers, distinguish major, minor, maintenance, and hotfix releases, and plan safe upgrades with release notes, hardware compatibility, backups, lab testing, and upgrade paths.
Demonstrate upgrading panos from 11.00 to 11.1.10 using panorama in a lab demo, with download or upload methods, base image dependencies (11.1.0), and software manager prechecks, installs, and reboots.
Explore Palo Alto firewall interface modes—layer 3, layer 2, vWire, tab, and sub-interface—and learn when to deploy each, including real-world use cases and security policies.
Configure a Palo Alto interface types lab in EVE-NG by building the topology, enabling L2 deployment with span and vwire modes, and configuring management via static IP.
Configure a Palo Alto vwire with inside and outside zones, enable dhcp, apply an interzone policy, and review logs, noting the two-interface limit and lack of routing or nat.
Explore deploying a Palo Alto firewall in layer 2 mode to switch internal vlan traffic, enforce zone-based security without routing, and compare layer 2 with vwire.
Configure a tap interface and monitor session to mirror traffic to the Palo Alto firewall, enabling traffic analysis, application identification, and preparation of security rules before migration.
Explore Palo Alto sub-interface deployment theory and lab: configure trunked interfaces, VLAN tagging, SVIs, inter-zone policies, and NAT for multi-VLAN networks.
Explore cryptography basics and its role in securing vpn connections on networks. Understand encryption, authentication, integrity, and key exchange with algorithms like aes and ChaCha20, and ipsec or tls.
Explore virtual private networks, including site-to-site and remote access VPNs, their overlay tunnels, encryption with IPsec/ESP, and protocols like OpenVPN, IKEv2, WireGuard, and GRE/IPsec.
Explore how to implement a site-to-site IPsec VPN between Palo Alto firewalls, covering phase 1 and phase 2 negotiations, IKE, DH, PSK, ESP, AH, and tunnel mode.
Learn to configure a Palo Alto firewall IPsec site-to-site VPN between two sites, including tunnel interfaces, VPN zones, static routes, IKE/IPsec crypto profiles, tunnels, and security policies.
Explore remote access vpn using GlobalProtect with a Palo Alto firewall, detailing client setup, gateway authentication, ipsec/ssl encryption, policy enforcement, and access to corporate resources.
Configure Palo Alto Global Protect VPN with inside, outside, VPN zones, tunnel interfaces, SSL certificates, authentication profiles, and portal and gateway setup; verify via Windows client with split tunneling.
Explore how Palo Alto firewalls achieve fault tolerance with high availability, covering active-passive and active-active deployments, failover triggers, and synchronization of network, object, and policy configurations.
Explore Palo Alto HA link types, including HA1 control, HA2 data, HA3 packet forwarding, and HA4 session cache synchronization, with backup links, dedicated vs in-band ports, and preemption rules.
Design and implement Palo Alto firewall active-passive high availability, configure ha1/ha2 links, inside and outside zones and interfaces, enable session state synchronization, and apply routing, NAT, and security policies.
Deploy panorama VM on ESXi by importing the 11.1.0 OVA from Palo Alto support; requires 16 GB RAM and 4-8 vCPUs, then configure management IP, DNS, gateway, license, and login.
Deploy panorama on vmware workstation by importing the panorama ova, configuring bridged management, and setting a static ip; allocate 4 cores and 8–16 gb ram, and change default credentials.
Panorama serves as a centralized management server for multiple Palo Alto firewalls and wildfire appliances. It enables centralized configuration, deployment, and logging with device groups, templates, and role-based access control.
Explore panorama models and deployment modes in Palo Alto Panorama, including panorama mode, management only mode, logger mode, and legacy mode, with M-series appliances supporting log collection, reports, and updates.
Learn how the panorama appliance centrally manages data centers, connects to lock collectors and firewalls, and uses port 3978 for device management, updates, and encrypted communication.
Configure panorama general settings by setting the management IP to 192.168.1.222, default gateway, DNS, time zone, and NTP, then commit and verify with show commands.
Master Panorama device groups and templates to centrally manage firewall configurations, licenses, content updates, including application threats, wildfire, antivirus, while understanding naming and resource requirements for Panorama modes and transitions.
Learn to add Palo Alto firewalls as Panorama managed devices by collecting management IPs and serial numbers, generating an auth key, and committing changes to establish connectivity.
Deploy a Palo Alto firewall on AWS using a new VPC with four subnets: mgmt, dmz, inside, and untrust; choose pay-as-you-go or BYOL licensing on EC2 with NAT.
Deploy a Palo Alto Networks firewall on AWS by building a four-subnet VPC (inside, outside, DMZ, management), configuring routing and IGW, then launching from the AWS marketplace.
Set up a Palo Alto firewall on AWS by attaching inside, DMZ, and outside interfaces, configuring DHCP, security groups, and disable source-destination checks.
Learn to deploy Palo Alto on AWS Part-3, attach an elastic IP to the outside interface, configure destination and source NAT, and enable private subnet RDP access.
Terminate the EC2 lab instances, cancel the Palo Alto VM series AWS marketplace subscription, and release elastic IPs to prevent charges and keep AWS billing minimal.
Important Notice
This course is Part-2 of the Palo Alto Firewall PAN-OS v11 – Zero-To-Hero series. It continues from Part-1 and focuses on advanced firewall configuration, High Availability (HA), VPNs, Panorama centralized management, logging, monitoring, troubleshooting, and cloud deployments. It is strongly recommended to complete Part-1 before enrolling in this course.
Course Overview
Once you understand the fundamentals of Palo Alto firewalls, the next step is mastering enterprise-grade configurations and real-world deployments.This course is designed to take you beyond the basics and help you work confidently with advanced Palo Alto Firewall features used in production environments.
In Part-2, you will dive deep into logging and reporting, User-ID and authentication, PAN-OS versioning, object management, VPN technologies, High Availability, advanced troubleshooting, and Panorama centralized management. You will also learn how Palo Alto firewalls are deployed in cloud environments such as AWS.
All topics are explained step by step, with practical demonstrations and real-world scenarios that reflect how Palo Alto firewalls are actually deployed and managed in enterprise networks.
What You’ll Learn in This Course
Configure and analyze traffic, threat, and system logs
Implement User-ID, Captive Portal, and authentication mechanisms
Understand PAN-OS versions, features, and upgrade strategies
Create and manage objects, address groups, and service objects
Perform backup and restore operations safely
Configure administrator accounts, roles, and RBAC
Understand and deploy Palo Alto firewall deployment modes
Configure Site-to-Site and Remote Access VPNs
Implement and test High Availability (HA) configurations
Perform advanced monitoring and troubleshooting using GUI and CLI
Deploy Panorama Virtual Machine
Manage multiple firewalls using Panorama (templates, device groups, policies)
Understand Palo Alto Firewall deployment in AWS cloud environments
Real-World & Enterprise Focus
This course is not theory-only. You will work with:
Realistic enterprise scenarios
Production-style configurations
Best practices used by network security professionals
By the end of the course, you will be able to design, deploy, manage, and troubleshoot Palo Alto firewalls confidently in complex environments.
Who This Course Is For?
Network & Security Engineers with Palo Alto basics
Students who completed Palo Alto Firewall PAN-OS v11 – Zero-To-Hero – Part-1
Firewall administrators managing enterprise networks
SOC, NOC, and IT operations professionals
Engineers preparing for advanced Palo Alto roles
Prerequisites:
Basic understanding of networking concepts
Basic familiarity with Palo Alto Firewall fundamentals
Completion of Part-1 is highly recommended
By the End of This Course
You will have the skills and confidence to work with Palo Alto firewalls in real enterprise and cloud environments, manage multiple firewalls using Panorama, implement HA and VPNs, and troubleshoot complex issues effectively.
Enroll now and continue your Zero-To-Hero journey with Palo Alto Firewall PAN-OS v11 – Part-2.