Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Palo Alto Firewall PCNSE New V9 & V10 Training
Bestseller
Rating: 4.5 out of 5(4,598 ratings)
29,420 students

Palo Alto Firewall PCNSE New V9 & V10 Training

Learn Palo Alto Firewall V9 & V10 with Step by Step Lab Workbook
Created byAhmad Ali
Last updated 7/2026
English
Arabic [Auto],English [Auto],

What you'll learn

  • Configure and Manage Palto Alto Firewall
  • Understand Palo Alto Firewalls Deployment Methods
  • How to setup a Lab Environment
  • Understand how to deploy Palo Alto Firewalls in GNS3 & EVE NG
  • Understand Palo Alto Firewalls Security Policies
  • Understand Palo Alto Firewalls NAT configuration
  • Understand User ID Integration
  • Configure user ID integration using User ID Agent
  • Configure Captive Portal to authenticate users
  • Understand AntiSpyware, AntiVirus, IPS configuration
  • Configure AntiSpyware, Antivirus and IPS
  • Configuring SSL Decryption

Course content

1 section103 lectures36h 34m total length
  • Before Starting This Course1:22
  • Lecture-01: Conman Network Security Terms.21:20

    Define core security terms—asset, vulnerability, exploit, threat, attack, risk, and countermeasure—and show how to protect assets, address vulnerabilities, and apply ssh and https as secure countermeasures.

  • Lecture-02:Identify Malware Malicious Software.30:52

    Explore malware, a broad category of malicious software, including viruses, worms, trojans, ransomware, spyware, adware, rootkits, and botnets, and how they threaten systems.

  • Lecture-03:Introduction to Firewall Technology.20:20

    Explore firewall technology, from basic definitions to generations, including stateful, stateless, and next generation firewalls, with focus on user ID, content ID, and deep packet inspection.

  • Lecture-04:About Palo Alto Networks Firewall.14:34

    Explore palo alto networks firewall architecture and features, including app id, user id, content id, and single pass software with parallel processing, plus pcnse certification overview.

  • Lecture-05:Install Palo Alto Firewall In VMware.17:12

    Install Palo Alto firewall in VMware workstation, import the image, allocate RAM and cores, configure three interfaces as VMX, boot, and log in with admin/admin.

  • Lecture-06:Install Palo Alto On EVE-NG:14:38
  • Lecture-07:Install Palo Alto in GNS3:6:26

    Install and configure the Palo Alto firewall in Gns3 by importing the pa vm image, creating a template, launching the vm, and accessing the management interface via https.

  • Lecture-08:Install Palo Alto On ESXI.11:50

    Learn how to deploy Palo Alto on ESXi using OVF or OVA templates, configure networking and provision settings, and compare type 1 and type 2 hypervisors alongside VMware options.

  • Lecture-09:CLI Access Modes & Basic Commands.18:00

    Learn to access a Palo Alto firewall via SSH, switch between operational and configuration modes, and use show commands, nesting, and tab completion to obtain system information.

  • Lecture-10:Introduction to Dashboard Tab.21:42

    Learn how the Palo Alto firewall dashboard organizes seven tabs, customize login and main logos, manage commits, and tailor widgets, layout, and logs for real-time monitoring.

  • Lecture-11:Palto Alto Initial Configuration.4:18

    Deploy a Palo Alto firewall virtually in VMware, iSCSI, or Gns3 and configure initial access via console or management port with the default 192.168.1.1 and admin credentials.

  • Lecture-12:Configure DNS & NTP in Palto Firewall.19:54

    Configure dns and ntp on Palo Alto firewall to ensure name resolution and time synchronization; learn dns concepts, root servers, A records, CNAME, and nslookup, and ntp settings.

  • Lecture-13:Activate Licenses and Subscriptions.23:02

    Master activating Palo Alto firewall licenses and subscriptions to enable updates, signatures, threat prevention, and global protect, while using session browser to view logs without a license.

  • Lecture-14:Dynamic Updates and Software Updates.20:30

    License and activate the Palo Alto firewall to enable dynamic updates and download antivirus, application, wildfire, and GlobalProtect signatures. Explain upgrading OS software using base images and major/minor releases.

  • Lecture-15:Initial Working of Palo Alto Firewall.22:27

    Create a two-zone topology on a Palo Alto firewall in VMware Workstation, configure interfaces, IP addresses, routing, net policy, and security policy, then commit and verify using logs.

  • Lecture-16:Management Interface Configuration.26:42

    Configure and secure the Palo Alto management interface, including dhcp and static IPs, access methods (https, ssh, telnet, http), access controls, and related network services like ping, dns, and snmp.

  • Lecture-17:Palo Alto Firewall Interfaces Details.32:13

    Explore Palo Alto firewall interfaces, including physical, logical, and virtual types, with layer 2 and layer 3 configurations and management profiles. Explore tape mode, virtual wire, subinterfaces, VLANs, and loopback.

  • Lecture-18:Palo Alto Firewall Zones Details.12:04

    Zone based firewalls organize interfaces into zones, enforce policies, and control traffic; one interface belongs to one zone, with intra-zone and inter-zone defaults guiding access.

  • Lecture-19:Routing Protocols,AD,Metric & Routing Tables.20:51

    Explore routing concepts on Palo Alto firewalls, including routed vs routing protocols, static and default routes, dynamic protocols, administrative distance, metrics, and routing tables.

  • Lecture-20:Virtual Routers in Palo Alto Firewall.11:12

    Explore virtual routers in Palo Alto firewalls, enabling routing between interfaces with different subnets using static and default routes, supporting dynamic protocols like RIP, OSPF, BGP, and IPv4 or IPv6.

  • Lecture-21:Configure & Verify Static Routing in PA Firewall.49:12

    Configure and verify static routing on a Palo Alto firewall, including creating inside and outside zones, assigning interfaces, setting default routes, and validating reachability with show ip route and ping.

  • Lecture-22:Configure & Verify Default Routing in PA Firewall.14:07

    Configure and verify a default route on the edge firewall, forwarding unknown destinations to the ISP via 0.0.0/0, using a next-hop IP and routing table checks.

  • Lecture-23:Configure & Verify Dynamic Protocol RIP in PA.23:53

    Explore dynamic routing with Rip on Palo Alto firewalls, configure version 2, advertise interfaces, manage default routes, and secure exchanges with authentication while comparing static vs dynamic routing.

  • Lecture-24:Configure & Verify RIP Authentication in PA.17:44

    Demonstrates securing rip routing with authentication on Palo Alto firewall, configuring keychains on routers and an authentication profile, and verifying with debug ip rip to prevent unauthorized updates.

  • Lecture-25:Configure & Verify Dynamic Protocol OSPF in PA.34:47

    Explore how to configure and verify OSPF on a Palo Alto firewall, including area zero backbone, router IDs, LSA exchange, DR/BDR election, hello/dead timers, and key verification commands.

  • Lecture-26:Configure and Verify Redistribute in PA.14:06

    Enable redistribution to merge routing domains by allowing a device to run multiple protocols (OSPF, RIP, static) and exchange routes, using a Palo Alto firewall redistribution profile and export rules.

  • Lecture-27:Security Policy Concept & Theory in PA.51:48
  • Lecture-28:Security Policy Granular Criteria and Control.44:36

    Learn to design Palo Alto firewall security policies, from top-to-bottom rule evaluation across intra, inter, and universal zones, to granular rules with source, destination, app, port, URL category, and user.

  • Lecture-29:Security Policy Action Setting Options.29:02

    Explains security policy action options on Palo Alto firewalls, including deny, drop, drop silently, and ICMP unreachable, with guidance on testing traffic to observe the differences.

  • Lecture-30:Security Policy Shadows Rule in PA.5:05

    Identify how a shadow rule forms in Palo Alto firewall policies when a broad allow-all rule renders a lower web browsing rule useless.

  • Lecture-31:Security Policy Test Policy Match Option.6:08

    Explore Palo Alto firewall version nine's test policy match feature to verify which top rule matches traffic by entering source, destination, port, user, protocol, and application.

  • Lecture-32:Security Policy View Rulebase as Groups.9:02

    Explore viewing Palo Alto firewall policies as grouped rule bases using tags, enabling bulk actions like move, clone, and delete by tag across departments in version 9 and above.

  • Lecture-33:Security Policy Policy Optimizer Option.5:15

    learn how policy optimizer helps identify unused firewall rules, disable them, test for a week, and delete stale policies, with version nine introducing usage export, reset, and timeframe options.

  • Lecture-34:Introduction to SSL and TLS certificates.16:31

    Grasp ssl and tls basics, how certificates encrypt and authenticate browser communications, and how a firewall uses a pushed certificate to intercept tls traffic.

  • Lecture-35:Configure SSL Forward Proxy in PA Firewall.25:19

    Learn to configure ssl forward proxy in pa firewall to decrypt https traffic. Push a trusted certificate to clients and enable a decryption policy to inspect traffic.

  • Lecture-36:Introduction to Security Profiles Content-ID.10:15

    Learn how security profiles augment policies with content ID, enabling antivirus, spyware, vulnerability checks, URL filtering, file blocking, and wildfire analysis to inspect and control encrypted traffic.

  • Lecture-37:Configure Security Profile (Antivirus Profile).21:02
  • Lecture-38:Configure Security Profile (Anti-Spyware).24:56

    Configure anti-spyware profiles in Palo Alto firewalls, including default and custom profiles, and attach them to security rules. Create custom spyware signatures and test using monitoring and packet capture.

  • Lecture-39:Configure Security Profile (Vulnerability).35:23

    Configure vulnerability protection profiles on Palo Alto firewalls to block threats in internal networks and DMZs. Create signatures and updates, and manage licenses, then verify protection by applying policy changes.

  • Lecture-40:Configure Security Profile (URL Filtering).36:37

    Configure url filtering to block or allow websites using Palo Alto Networks database or Bright Cloud. Apply categories and custom lists, verify licenses, and monitor logs with password-protected overrides.

  • Lecture-41:Configure Security Profile (File Blocking).19:00

    Configure file blocking in a Palo Alto security profile, applying block, alert, or continue actions to monitor and restrict uploads and downloads of selected file types.

  • Lecture-42:Configure Security Profile (WildFire Analysis).35:47

    Configure wildfire analysis on Palo Alto firewall by creating profiles, enabling dynamic update, and testing unknown threats using public or private wildfire, with file-type testing and reporting.

  • Lecture-43:Configure Security Profile (Data Filter).26:16

    Configure data filtering profiles to detect sensitive data such as credit card and social security numbers, using predefined patrons, regular expressions, and file properties, and enforce alert and block thresholds.

  • Lecture-44:Configure Security Profile (Security Group).9:35

    Learn to use security profile groups to attach antivirus, anti spyware, vulnerability, url filtering, file blocking, and data filtering to multiple policies at once, improving efficiency.

  • Lecture-45:DoS & Zone Protection and Packet Buffer Theory.17:52

    Explore how zone protection profiles and packet buffer protection defend against DoS and DDoS, reconnaissance attacks, and flooding attacks (UDP, ICMP, ICMPv6) with aggregate and classified policies.

  • Lecture-46:Configure & Verify DoS Protection Profile.43:16

    Configure and verify a DoS protection profile on Palo Alto firewall, enabling sync flood, UDP, and ICMP protections with random early drop and block durations; test against a web server.

  • Lecture-47:Configure & Verify Zone Protection Profile.26:08

    Configure a zone protection profile to shield zones from flood and reconnaissance attacks, using thresholds and actions to block or alert on TCP/ICMP/UDP floods and port scans.

  • Lecture-48:Configure & Verify Packet Buffer Protection.10:29

    Enable packet buffer protection via device-wide settings and zone protection profiles to guard against buffer overflow and ddos attacks. Configure alerts, blocking duration, and test with icmp flooding.

  • Lecture-49:Palo Alto Firewall Layer 2 Deployment.30:42

    Deploy the Palo Alto firewall as a layer two switch with VLAN ten, two zones (LAN and server), and a policy to permit ping and http between zones.

  • Lecture-50:Palo Alto Firewall Tap Mode Deployment.24:45
  • Lecture-51:Palo Alto Firewall V-Wire Mode Deployment.22:37

    Deploy Palo Alto firewall in virtual wire mode to create a bump-in-the-wire topology, linking inside and outside zones with two interfaces, DHCP assignment, and bidirectional security policies.

  • Lecture-52:Palo Alto Firewall Sub-Interface Mode.22:41

    Configure Palo Alto firewall sub-interfaces on a trunk to support VLAN ten, twenty, and thirty with zones hr it sales and a default route to the internet.

  • Lecture-53:NAT Theory & Source Network Address Translation Types.18:04

    Learn how Palo Alto firewalls perform network address translation to conserve IPv4 space, covering source and destination NAT, dynamic and static IP translation, port address translation, and port forwarding.

  • Lecture-54:Source NAT Type Dynamic IP and Port (DIPP) Theory & Lab.46:18

    Explore source nat dynamic ip and port (dipp) theory with a hands-on lab, translating inside addresses to a single public ip or a pool of public ips on Palo Alto.

  • Lecture-55:Source NAT Type Dynamic IP(DIP) Theory and Lab.10:32

    Explore how source nat uses dynamic ip (dip) for 1-to-1 mapping, first-come, first-served traffic, and an interface-based fallback to maximize concurrent sessions with limited public ips.

  • Lecture-56:Source NAT Type Static IP Theory and Lab.11:15

    Demonstrate static IP source NAT with 1:1 translation, assigning unique public IPs to each internal PC, and compare with dynamic IP behavior in the lab.

  • Lecture-57:Destination Network Address Translation Static IP.21:05

    Learn destination network address translation on a Palo Alto firewall, including static IP DNAT, port forwarding, and port translation to reach private internal servers.

  • Lecture-58:DNAT Port Forwarding and Port Translation.10:44
  • Lecture-59:U-Turn NAT-Network Address Translation Theory & Lab.18:21

    Learn how u-turn nat lets internal clients reach external or dmz resources using both source and destination translations, with practical palo alto firewall configuration and verification.

  • Lecture-60:Objects (Address, Address Groups,Regions,Service, Service Group).45:53

    Learn to organize a Palo Alto firewall with objects: addresses, address groups, regions, services, and service groups; create static and dynamic address groups using tags for reusable, scalable policies.

  • Lecture-61:Introduction to App-ID in Palo Alto Firewall.39:04

    Introduce app-id in Palo Alto firewall, showing how app-based traffic identification replaces port-based rules, using signatures, unknown protocol decoding, and decryption to control apps like Facebook, web browsing, and DNS.

  • Lecture-62: Walk-through and Details of Applications in PA Firewall.13:02

    Navigate the Palo Alto firewall application window, exploring object, application group, and filter, and review categories, subcategories, and risk factors while using search, disable/enable, and tagging for policy management.

  • Lecture-63: Walk-through and Details of Applications Window in PA.18:29

    Explore the Palo Alto firewall applications window, identify Skype by name, port type, and tcp/udp usage, then manage dependencies and validate required apps before committing changes.

  • Lecture-64:Application Shifts in Palo Alto Firewall.12:15

    Demonstrate application shift in Palo Alto firewall, where TCP-based applications reclassify mid-session from web browsing to services like Facebook or YouTube, using the TCP three-way handshake and SSL transitions.

  • Lecture-65:Dependent Applications in Palo Alto Firewall.6:23

    Identify dependent applications in Palo Alto firewall rules, recognizing that some apps like YouTube require Google base to work; verify dependencies in both application window and policy before committing.

  • Lecture-66:Implicitly Use Applications in Palo Alto Firewall.1:57

    Explain implicitly use of applications and how apps like Facebook enable ssl and web browsing automatically. Identify implicitly use via object application and type in the application window.

  • Lecture-67:Application Groups in Palo Alto Firewall.14:27

    Create and nest static application groups to simplify management, reuse across policies, and secure traffic, using network and web groups as examples.

  • Lecture-68: Application Filters in Palo Alto Firewall.14:33

    Learn how application filters dynamically group apps by category and subcategory, allowing automatic blocking of new apps without manual updates.

  • Lecture-69:Custom Applications in Palo Alto Firewall.8:37

    Learn to create and register a custom application in Palo Alto firewall, including naming, category, risk, port/protocol, and optional signature, to control non-listed apps.

  • Lecture-70:Application Override in Palo Alto Firewall.14:28

    Learn how to use application override in Palo Alto firewall to bypass layer 7 checks for new or signature-free apps, applying layer 3/4 inspection via a policy.

  • Lecture-71:Application Updates in Palo Alto Firewall.4:14

    Update your Palo Alto firewall application signatures using manual downloads or schedule-based updates, verify downloads and installations via device dynamic updates and the dashboard, and review release notes for changes.

  • Lecture-72:Security Policy based on Application in PA.11:46

    Create and test security policies based on application in PA, demonstrating application-based blocking for Facebook and LinkedIn by source IP.

  • Lecture-73:Introduction to User-ID (User Identification).6:27

    Introduce user-id as the third pillar of the next-generation firewall, enabling policies based on users or groups rather than ip addresses, with improved visibility, logging, and reporting.

  • Lecture-74:Captive Portal User-ID in Palo Alto Firewall.25:37

    Implement captive portal user-id on a Palo Alto firewall using local database users, create visitor groups, and redirect inside users to a portal with temporary credentials, enabling user-based access control.

  • Lecture-75:AD,DNS, Users and Groups Configuration.16:16

    Learn to configure Active Directory on Windows Server, set up DNS and promote a domain controller, and integrate Palo Alto Firewall with a service account.

  • Lecture-76:Palo Alto Firewall Active Directory Integration.42:42

    Learn how to integrate Palo Alto firewall with Active Directory using LDAP, create service accounts, configure LDAP server profiles, authentication and user/group mapping, and enforce domain-based access.

  • Lecture-77:DHCP(Dynamic Host Configuration Protocol) Theory.15:48

    Explore how DHCP automates IP address, subnet mask, and DNS via UDP-based Dora and how Palo Alto firewall can act as a DHCP server, client, or relay.

  • Lecture-78:DHCP(Dynamic Host Configuration Protocol) Server Lab.28:39

    Explore how to configure a Palo Alto firewall as a Dhcp client, server, and relay within a three-zone topology, including Dora process, Dhcp server pools, and policy rules.

  • Lecture-79:DHCP(Dynamic Host Configuration Protocol) Relay Lab.17:07

    Configure the Palo Alto firewall as a DHCP relay agent to forward broadcast DHCP requests to an external DHCP server, with a DMZ server and policy for relay traffic.

  • Lecture-80:Configure Interface Mgmt (Management) Profile.8:54

    Configure interface management profiles to control admin access on specific interfaces by enabling services like http, https, ssh, telnet, ping, snmp, and syslog with permitted ip addresses.

  • Lecture-81:Service Features Service Route Configuration.8:37

    Configure service routes on Palo Alto firewalls to route DNS, syslog, updates, and other services to the correct interfaces (management, DMZ, inside), including IPv4/IPv6.

  • Lecture-82:Administrator Accounts & Dynamic Roles Configuration.16:31

    Discover administrator accounts and dynamic roles on the Palo Alto firewall, including super user, super user read only, device administrator, and device administrator read only, with automatic feature inheritance.

  • Lecture-83:Administrator Accounts & Role Based Configuration.15:32

    Explore administrator accounts and role based configuration on Palo Alto firewall, comparing static predefined roles with custom roles and dynamic rule bases, including web UI and rest API access.

  • Lecture-84:Administrator Accounts Window Walk-through.9:46

    Walk through administrator accounts window, configuring users with password, certificate, and public key authentication, attaching authentication profiles, and testing login via PuTTY and automatic certificate-based login.

  • Lecture-85:Administrator Accounts Password Complexity.26:06

    Enforce administrator password complexity with minimum eight characters, upper and lower case, digits, and special characters; apply global and per-user password profiles, and configure change, expiration, and grace rules.

  • Lecture-86:Redundancy High Availability (HA) Theory.33:04

    Explore redundancy and high availability for Palo Alto firewalls, including H1/H2 control and data links, active-passive and active-active modes, heartbeat and failover concepts.

  • Lecture-87:High Availability (HA) Active-Passive Lab.45:40

    Configure two firewalls in an active-passive high availability setup, enable preemption, and verify failover via heartbeat and link monitoring across inside and outside zones.

  • Lecture-88:Cryptography, Encryption and Hashing Concepts.36:48

    Explains cryptography basics, defines plaintext and ciphertext, explains encryption and decryption algorithms, describes Caesar cipher and vinegar cipher, contrasts symmetric and asymmetric encryption, and covers hash for integrity.

  • Lecture-89:Internet Key Exchange, Version & Phases Theory.9:39

    Explore how internet key exchange negotiates security policies, algorithms, and keys between ipsec peers for site-to-site vpn, covering ike v1 vs v2, isakmp, and phase one and two.

  • Lecture-90:VPN, Types, Protocols,Classification etc Theory.6:47

    Explore how virtual private networks secure data over the internet, using IPsec and SSL VPNs for site-to-site and remote access, with hub-and-spoke and land-to-land architectures, and key classifications and benefits.

  • Lecture-91:IPSec Protocols, Features,Modes,Encryption Theory.5:57

    Explore IPsec as an open standard for site-to-site and remote access VPNs, detailing confidentiality, integrity, authentication, anti-replay, esp vs ah, tunnel vs transport modes, and key exchange with Diffie-Hellman groups.

  • Lecture-92:IPSec Site-to-Site Virtual Private Network VPN Lab.36:31

    Configure a site-to-site ipsec vpn between two Palo Alto firewalls, linking 192.168.1.x and 192.168.2.x networks via a 172.16.x tunnel, with ike phase one and ipsec phase two; verify with ping.

  • Lecture-93:Remote-Access VPN GlobalProtect Theory and Lab.1:26:19

    Explore remote access vpn concepts with Palo Alto's GlobalProtect, including ssl vs ipsec, client-based vs browser-based access, portal and gateway architecture, and split tunneling.

  • Lecture-94:Log Types (Traffic,Threat, User-ID etc) in Monitor Tab.34:49

    Learn how to use the monitor tab to access traffic, threat, and user-id logs, with filters, columns, and export options, plus url filtering, data filtering, wildfire, and unified logs.

  • Lecture-95:Configure and Verify Syslog in Palo Alto Firewall.23:48

    Configure and verify syslog on a Palo Alto firewall, forward traffic, system, and policy logs to external servers (syslog, Panorama, SNMP) using UDP 514, with per-zone and service route considerations.

  • Lecture-96:Configure and Verify NetFlow in Palo Alto Firewall.15:07

    Configure NetFlow on Palo Alto by creating and applying a NetFlow server profile to interfaces, enabling traffic monitoring to identify top bandwidth users, applications, and endpoints.

  • Lecture-97:Configure and Verify SNMP in Palo Alto Firewall.16:26

    Configure and verify snmp on a Palo Alto firewall using versions 2 and 3. Use get, get next, get bulk, set, and trap messages with snmp manager, agents, and nms.

  • Lecture-98:Configure and Verify Packet Capture GUI and CLI.35:35

    Configure and verify Palo Alto firewall packet capture via graphical user interface and command line interface. Filter by interface, source ip, destination ip, port, protocol, drop, receive, transmit, firewall stages.

  • Lecture-99:App Scope (Summary,Change,Threat,Network Monitor).4:39

    Explore the Palo Alto firewall monitoring features, including summary, change, and threat monitors. Learn to view top gainers and losers, bandwidth by application, and exportable network maps.

  • Lecture-100:ACC (Application Command Center ) Tab Walk-through.17:17

    Explore the application command center tab to monitor network, application, and user activity with widgets, apply local and global filters, and export reports to pdf using customizable tapes.

  • Lecture-101:Configure Backup and Restore in Palo Alto Firewall.40:00

    Explore how backup and restore work on a Palo Alto firewall, using candidate and running configurations, commit processes, and saving, loading, and exporting device state snapshots.

  • EVE-NG Installation, Configuration & Images31:15

    Explore eve-ng installation and configuration for emulated networks, compare eve-ng with gns3, choose community edition, set up prerequisites, import router and switch images, and build CCNP labs.

Requirements

  • Basic IP and security knowledge is nice to have.
  • Students need to understand basic networking.
  • Students needs to understand Networking Fundamentals.

Description

Master Palo Alto Networks Next-Generation Firewalls (NGFW) through comprehensive hands-on labs and learn how to deploy, configure, secure, manage, and troubleshoot enterprise firewall environments.

This course is designed for network engineers, security professionals, firewall administrators, and anyone preparing for the Palo Alto Networks Certified Network Security Engineer (PCNSE) certification. Whether you are completely new to Palo Alto firewalls or looking to deepen your enterprise security expertise, this course provides a practical, step-by-step learning experience.

Starting from the fundamentals, you'll progress through advanced firewall deployment, policy configuration, threat prevention, VPNs, routing, high availability, SSL decryption, and troubleshooting using real-world enterprise scenarios.

Every lesson combines detailed theory with live demonstrations and hands-on lab exercises so that you gain the confidence to deploy and manage Palo Alto firewalls in production environments.

What You'll Learn

  • Understand Palo Alto Networks firewall architecture

  • Install and perform the initial firewall configuration

  • Configure management and data plane interfaces

  • Configure Layer 2, Layer 3, Virtual Wire, and TAP deployment modes

  • Configure Security Zones and Interfaces

  • Configure Virtual Routers and Static Routing

  • Configure Dynamic Routing (OSPF, BGP, and RIP)

  • Configure Source NAT (SNAT), Destination NAT (DNAT), and NAT Policies

  • Create and manage Security Policies

  • Configure Application Identification (App-ID)

  • Configure User Identification (User-ID)

  • Configure Content Identification (Content-ID)

  • Configure Security Profiles

  • Configure Antivirus, Anti-Spyware, Vulnerability Protection, URL Filtering, DNS Security, and WildFire

  • Configure SSL/TLS Decryption Policies

  • Configure Authentication Policies

  • Integrate with Microsoft Active Directory and LDAP

  • Configure Site-to-Site IPsec VPNs

  • Configure GlobalProtect Remote Access VPN

  • Configure High Availability (Active/Passive and Active/Active)

  • Configure Policy-Based Forwarding (PBF)

  • Monitor traffic, threats, logs, and sessions

  • Generate reports and dashboards

  • Perform packet captures and advanced troubleshooting

  • Apply Palo Alto best practices for enterprise deployments

This Course Includes

  • Complete firewall installation

  • Step-by-step configuration demonstrations

  • Hands-on enterprise labs

  • Real-world deployment scenarios

  • Security policy implementation

  • NAT configuration

  • VPN implementation

  • Routing configuration

  • High Availability deployment

  • SSL Decryption

  • Threat Prevention

  • Monitoring and logging

  • Packet capture and troubleshooting

  • Downloadable PDF study materials

  • Downloadable lab files and configurations

  • Lifetime course updates

Course Curriculum

Module 1 – Palo Alto Firewall Fundamentals

  • Palo Alto Architecture

  • Initial Setup

  • Licensing

  • Software Updates

  • Interface Configuration

  • Security Zones

Module 2 – Network Configuration

  • Virtual Routers

  • Static Routing

  • OSPF

  • BGP

  • RIP

  • Policy-Based Forwarding (PBF)

  • NAT Configuration

Module 3 – Security Policies

  • Security Rules

  • Application-Based Policies

  • User-Based Policies

  • Security Profiles

  • URL Filtering

  • WildFire

  • Antivirus

  • Anti-Spyware

  • Vulnerability Protection

  • DNS Security

  • SSL/TLS Decryption

Module 4 – VPN and High Availability

  • Site-to-Site IPsec VPN

  • GlobalProtect VPN

  • Active/Passive High Availability

  • Active/Active High Availability

  • Synchronization

  • Failover Testing

Module 5 – Monitoring and Troubleshooting

  • Traffic Logs

  • Threat Logs

  • System Logs

  • ACC (Application Command Center)

  • Packet Capture

  • Session Browser

  • CLI Troubleshooting

  • Performance Monitoring

  • Best Practices

Why Learn Palo Alto Networks?

Palo Alto Networks is one of the world's leading cybersecurity companies and its Next-Generation Firewalls are trusted by enterprises, financial institutions, healthcare organizations, governments, cloud providers, and service providers around the globe.

Unlike traditional firewalls, Palo Alto Networks uses technologies such as App-ID, User-ID, Content-ID, WildFire, and Threat Prevention to identify applications, users, and threats while providing granular security control and visibility across enterprise networks.

Learning Palo Alto Networks technologies will help you build highly sought-after skills in:

  • Enterprise Firewall Administration

  • Network Security

  • Threat Prevention

  • Zero Trust Architecture

  • Secure Remote Access

  • Cloud Security

  • VPN Technologies

  • Security Operations

  • Cybersecurity Engineering

Who This Course Is For

  • PCNSE certification candidates

  • PCNSA certification candidates

  • Network Security Engineers

  • Firewall Administrators

  • Network Engineers

  • Cybersecurity Professionals

  • SOC Analysts

  • Security Analysts

  • System Administrators

  • IT Infrastructure Engineers

  • Anyone interested in mastering Palo Alto Networks firewalls

Prerequisites

To get the most from this course, you should have:

  • Basic networking knowledge

  • Understanding of TCP/IP and IP addressing

  • Familiarity with routing and switching concepts

  • Basic firewall knowledge is helpful but not required

No previous Palo Alto experience is required. Every concept is explained from the ground up with practical demonstrations.

By the End of This Course

By completing this course, you will confidently deploy, configure, manage, monitor, and troubleshoot Palo Alto Networks firewalls in enterprise environments. You will gain practical experience implementing advanced security policies, NAT, routing, VPNs, SSL decryption, Threat Prevention, WildFire, High Availability, and centralized monitoring using industry best practices.

Whether your goal is to earn the PCNSE certification, deploy Palo Alto firewalls in production, or advance your career as a network security professional, this course provides the practical skills and real-world experience needed to succeed.

Who this course is for:

  • This course is for students trying to obtain the PCNSE.
  • This course is for students trying to learn the Palo Alto Firewall.
  • Any Network or Security Engineer want to learn or polish their Skills.