Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Palo Alto Firewall PCNSE Training
Rating: 4.5 out of 5(2,053 ratings)
13,240 students

Palo Alto Firewall PCNSE Training

Learn Palo Alto Firewall with Step by Step Lab Workbook
Created byAhmad Ali
Last updated 7/2026
English
English [Auto],Spanish [Auto],

What you'll learn

  • Configure and Manage Palto Alto Firewall
  • Understand Palo Alto Firewalls Deployment Methods
  • How to setup a Lab Environment
  • Understand Palo Alto Firewalls Deployment Methods
  • Understand how to deploy Palo Alto Firewalls in GNS3 & EVE NG
  • Understand Palo Alto Firewalls Security Policies
  • Understand Palo Alto Firewalls NAT configuration
  • Understand User ID Integration
  • Configure user ID integration using User ID Agent
  • Configure Captive Portal to authenticate users
  • Understand AntiSpyware, AntiVirus, IPS configuration
  • Configure AntiSpyware, Antivirus and IPS
  • Configuring SSL Decryption

Course content

1 section53 lectures31h 53m total length
  • Before Starting This Course1:22
  • Overview2:01

    Dear all students welcome to Palo Alto Firewall PCNSE course, This course is based on Real World labs and examples. This is online class recording not a typical course recording. In every lecture you will find from scratch to advanced configuration. Also, with every lecture you will find step by step notes and workbook.

  • Lecture 1:Common Network Security Terms & Malware43:03
  • Lecture 2: Introduction to Firewall Technologies25:36
  • Lecture 3: About Palo Alto Networks & PCNSE16:04
  • Lecture 4: Install Palo Alto Firewall On VMware Workstation19:20
  • Lecture 5: Install Palo Alto Firewall in GNS312:16

    Install a Palo Alto firewall in GNS3, enable KVM support, integrate VMware, and configure RAM and network settings for a smooth simulation.

  • Lecture 6: Install Palo Alto Firewall On EVE-NG15:01
  • Lecture 7: CLI Access Modes, DNS & NTP Configuration43:23
  • Lecture 8: Introduction to Dashboard Tab36:56

    Explore the Palo Alto firewall dashboard and customize widgets, layout, and logo. Monitor system information, top applications and risk factor, and use commit, save, and refresh options.

  • Lecture 9: Palo Alto Firewall Licenses and Updates26:51

    Explore Palo Alto firewall licenses and updates, including threat prevention licenses (antivirus, anti-spyware, vulnerability protection), URL filtering (PAN URL and BrightCloud), WildFire, GlobalProtect, and dynamic updates.

  • Lecture 10: Palo Alto Firewall Initial Working Lab28:40

    Build an initial working lab for a Palo Alto firewall, configuring two zones, interfaces, routing, and security policy; commit changes, assign IPs, test with logs and sessions to verify traffic.

  • Lecture 11: Palo Alto Firewall Interfaces and Zones44:09

    Explore Palo Alto firewall interfaces and zones, including virtual wire, layer two, layer three, and tab mode, with loopback and tunnel interfaces, IP assignment, and zone-based policies.

  • Lecture 12: Configure & Verify Static Routing & RIPV257:08
  • Lecture 13: Configure & Verify Redistribution & OSPF32:58
  • Lecture 14: Configure & Verify Security Policy Rules1:14:29

    Create and verify Palo Alto security policy rules across intra zone, inter zone, and universal scopes, focusing on source, destination, application, and user criteria with logging and security profiles.

  • Lecture 15: Configure & Verify NAT and PAT1:44:12

    Explore network address translation on Palo Alto firewalls, covering source NAT, destination NAT, dynamic IP and port, static NAT, port forwarding, and NAT policies.

  • Lecture 16: Configure Object (Address,Service,Tags)1:05:14

    Learn to create and reuse objects for addresses, services, and tags, including static and dynamic address groups, region and geolocation, fully qualified domain names, and scheduled policy control.

  • Lecture 17: Configure Antivirus Security Profile33:23

    Learn to configure antivirus security profiles as part of content ID in a next-generation firewall, applying virus, spyware, and file checks to allowed traffic and using wildfire analysis.

  • Lecture 18: Configure Anti-Spyware Security Profile25:01

    Configure and attach an anti-spyware security profile to allowed policies, customize rules (default and strict), and test with packet capture while monitoring threats and signatures.

  • Lecture 19: Configure Vulnerability Security Profile21:39

    Configure vulnerability protection profiles in Palo Alto Firewall PCNSE Training by cloning default rules, creating custom signatures, and tuning actions from allow to alert or drop while capturing logs.

  • Lecture 20: Configure URL Filtering Security Profile35:59

    Configure a Palo Alto url filtering profile using pan db or brightcloud licenses, manage categories and override rules, and apply profiles to policies while noting ssl decryption limits and logs.

  • Lecture 21: Configure File Blocking Security Profile14:34

    block unwanted file transfers with a file blocking security profile, attach it to an allowed policy, and test with pdf and x files using predefined rules or custom rules.

  • Lecture 22: Configure WildFire Analysis Security Profile26:55

    Explore wildfire analysis in Palo Alto firewalls, comparing cloud and appliance deployments, and learn how zero-day files are quarantined and classified as benign, greyware, or malware.

  • Lecture 23: Configure Data Filter Security Profile25:46

    Configure data filtering profiles to block sensitive data like credit card numbers and social security numbers using predefined patterns, regular expressions, or file properties, providing alerts and blocks based on thresholds.

  • Lecture 24: Configure Security Group Security Profile5:28

    Create a security profile group to attach antivirus, anti-spyware, vulnerability, URL filtering, data filtering, and wildfire analysis at once, then apply the group to the policy.

  • Lecture 25: Configure and Attach Interface Mgmt12:57

    Create and attach an interface management profile to loopback, tunnel, and physical interfaces. Configure allowed management protocols such as http, https, ping, telnet, and ssh, with IP-based access restrictions.

  • Lecture 26: Configure DoS Protection & Zone Protection1:21:53

    Learn to configure DDoS protection and zone protection on Palo Alto firewalls, including dust protection, buffer protection, and aggregate versus classified DDoS profiles, with practical flood testing.

  • Lecture 27: SSL Forward Proxy1:02:42
  • Lecture 28: Palo Alto Firewall App-ID Introduction15:06

    This lecture explains Palo Alto's App-ID as part of a next generation firewall, identifying applications by signatures, protocol decoding, decryption, and behavior to enforce policies without relying on port numbers.

  • Lecture 29: Palo Alto Firewall App-ID Labs1:32:41
  • Lecture 30: Palo Alto Firewall Layer 2 Deployment30:48
  • Lecture 31: Palo Alto Firewall Tap Mode Deployment19:10

    Deploy Palo Alto firewall in tape mode to mirror and monitor network traffic, providing visibility into applications, users, and top activities without enforcing policies.

  • Lecture 32: Palo Alto Firewall Virtual Wire Deployment16:25

    Deploy Palo Alto firewalls as a virtual wire to bridge two interfaces in a transparent layer-2 path between inside and outside networks, enabling policy-driven traffic inspection.

  • Lecture 33: Palo Alto Firewall User-ID Captive Portal37:28

    Explore user ID and captive portal for traffic visibility, guest access, and user-based policies, with local or AD authentication and comprehensive logging.

  • Lecture 34: Palo Alto Firewall User-ID LDAP Integration1:07:00

    Learn how to integrate Active Directory with a Palo Alto firewall using User-ID LDAP, configure Kerberos and DNS, and enforce policy by user or group.

  • Lecture 35: Service Route Configuration9:00

    Explore service route configuration in Palo Alto firewalls, learn how to redirect DNS, Kerberos, LDAP, syslog, and updates from the management interface to other interfaces when internet access is limited.

  • Lecture 36: Administrator Accounts Part-132:36

    Explain administrator accounts on Palo Alto firewalls, compare dynamic vs role-based roles, create and assign predefined and custom administrator roles, and control access to monitor, device, and security tabs.

  • Lecture 37: Administrator Accounts Part-229:35

    Explain administrator accounts, dynamic and built-in roles (super user, super user read-only, device administrator, and device administrator read-only), role-based access, and password profiles with expiration and warnings, and complexity rules.

  • Lecture 38: Configure RADIUS Authentication25:02

    Configure radius authentication on Palo Alto firewalls by using a centralized radius server, creating a radius profile, and applying it to administrator access for authentication, authorization, and accounting.

  • Lecture 39: Configure and Verify DHCP Server & Relay39:06

    Learn to configure and verify a Palo Alto firewall as a dhcp server, dhcp client, and dhcp relay across inside, outside, and DMZ zones, with lab topology and packet captures.

  • Lecture 40: High Availability Theory41:16

    Explore redundancy and high availability concepts for Palo Alto firewalls, including failover and backup links. Understand active-passive and active-active deployments, control and data links, heartbeat, and synchronize session data.

  • Lecture 41: High Availability Lab49:34
  • Lecture 42: Link and Path Monitoring Lab16:07
  • Lecture 43: Backup and Restore in Palo Alto Firewall1:00:28

    Explore backup and restore for Palo Alto firewall, including candidate and running configurations, commit and save workflows, and using snapshots, named configurations, and device state export/import for safe recovery.

  • Lecture 44: Logs Type in Palo Alto Firewall30:12

    Learn to navigate Palo Alto firewall logs in the monitor tab, including traffic, session details, and url, thread, and wildfire logs. Filter, save, and export for troubleshooting.

  • Lecture 45: Configure and Verify Syslogs31:12
  • Lecture 46: Configure and Verify NetFlow20:08

    Configure netflow on Cisco devices, capture source and destination details, ports, layer 3 info, and top talkers, then push data to a netflow collector or soc for analysis.

  • Lecture 47: Packet Capture in Palo Alto Firewall32:23

    Learn how to perform packet capture on a Palo Alto firewall for troubleshooting. Use manage filter and four stages—drop, firewall, receive, and transmit—to capture targeted traffic via GUI or CLI.

  • Lecture 48: ACC(Application Command Center) Tab31:30

    Explore the Palo Alto firewall's application command center tab, a hub for monitoring applications, user activity, logs, and traffic; export to PDF and track network, thread, block, and tunnel activities.

  • Lecture 49: Site-to-Site VPN Theory Concept42:12

    Learn site-to-site and remote access vpn concepts on Palo Alto firewalls, including ipsec with encryption, integrity, authentication, anti-replay, ike phases, and dh groups.

  • Lecture 50: Site-to-Site VPN Configuration Lab1:02:56
  • Lecture 51: Remote Access VPN Global Protect1:26:19

Requirements

  • Students need to understand basic networking
  • Students needs to understand Networking Fundamentals

Description

Master Palo Alto Networks Next-Generation Firewalls (NGFW) through comprehensive hands-on labs and learn how to deploy, configure, secure, manage, and troubleshoot enterprise firewall environments.

This course is designed for network engineers, security professionals, firewall administrators, and anyone preparing for the Palo Alto Networks Certified Network Security Engineer (PCNSE) certification. Whether you are completely new to Palo Alto firewalls or looking to deepen your enterprise security expertise, this course provides a practical, step-by-step learning experience.

Starting from the fundamentals, you'll progress through advanced firewall deployment, policy configuration, threat prevention, VPNs, routing, high availability, SSL decryption, and troubleshooting using real-world enterprise scenarios.

Every lesson combines detailed theory with live demonstrations and hands-on lab exercises so that you gain the confidence to deploy and manage Palo Alto firewalls in production environments.

What You'll Learn

  • Understand Palo Alto Networks firewall architecture

  • Install and perform the initial firewall configuration

  • Configure management and data plane interfaces

  • Configure Layer 2, Layer 3, Virtual Wire, and TAP deployment modes

  • Configure Security Zones and Interfaces

  • Configure Virtual Routers and Static Routing

  • Configure Dynamic Routing (OSPF, BGP, and RIP)

  • Configure Source NAT (SNAT), Destination NAT (DNAT), and NAT Policies

  • Create and manage Security Policies

  • Configure Application Identification (App-ID)

  • Configure User Identification (User-ID)

  • Configure Content Identification (Content-ID)

  • Configure Security Profiles

  • Configure Antivirus, Anti-Spyware, Vulnerability Protection, URL Filtering, DNS Security, and WildFire

  • Configure SSL/TLS Decryption Policies

  • Configure Authentication Policies

  • Integrate with Microsoft Active Directory and LDAP

  • Configure Site-to-Site IPsec VPNs

  • Configure GlobalProtect Remote Access VPN

  • Configure High Availability (Active/Passive and Active/Active)

  • Configure Policy-Based Forwarding (PBF)

  • Monitor traffic, threats, logs, and sessions

  • Generate reports and dashboards

  • Perform packet captures and advanced troubleshooting

  • Apply Palo Alto best practices for enterprise deployments

This Course Includes

  • Complete firewall installation

  • Step-by-step configuration demonstrations

  • Hands-on enterprise labs

  • Real-world deployment scenarios

  • Security policy implementation

  • NAT configuration

  • VPN implementation

  • Routing configuration

  • High Availability deployment

  • SSL Decryption

  • Threat Prevention

  • Monitoring and logging

  • Packet capture and troubleshooting

  • Downloadable PDF study materials

  • Downloadable lab files and configurations

  • Lifetime course updates

Course Curriculum

Module 1 – Palo Alto Firewall Fundamentals

  • Palo Alto Architecture

  • Initial Setup

  • Licensing

  • Software Updates

  • Interface Configuration

  • Security Zones

Module 2 – Network Configuration

  • Virtual Routers

  • Static Routing

  • OSPF

  • BGP

  • RIP

  • Policy-Based Forwarding (PBF)

  • NAT Configuration

Module 3 – Security Policies

  • Security Rules

  • Application-Based Policies

  • User-Based Policies

  • Security Profiles

  • URL Filtering

  • WildFire

  • Antivirus

  • Anti-Spyware

  • Vulnerability Protection

  • DNS Security

  • SSL/TLS Decryption

Module 4 – VPN and High Availability

  • Site-to-Site IPsec VPN

  • GlobalProtect VPN

  • Active/Passive High Availability

  • Active/Active High Availability

  • Synchronization

  • Failover Testing

Module 5 – Monitoring and Troubleshooting

  • Traffic Logs

  • Threat Logs

  • System Logs

  • ACC (Application Command Center)

  • Packet Capture

  • Session Browser

  • CLI Troubleshooting

  • Performance Monitoring

  • Best Practices

Why Learn Palo Alto Networks?

Palo Alto Networks is one of the world's leading cybersecurity companies and its Next-Generation Firewalls are trusted by enterprises, financial institutions, healthcare organizations, governments, cloud providers, and service providers around the globe.

Unlike traditional firewalls, Palo Alto Networks uses technologies such as App-ID, User-ID, Content-ID, WildFire, and Threat Prevention to identify applications, users, and threats while providing granular security control and visibility across enterprise networks.

Learning Palo Alto Networks technologies will help you build highly sought-after skills in:

  • Enterprise Firewall Administration

  • Network Security

  • Threat Prevention

  • Zero Trust Architecture

  • Secure Remote Access

  • Cloud Security

  • VPN Technologies

  • Security Operations

  • Cybersecurity Engineering

Who This Course Is For

  • PCNSE certification candidates

  • PCNSA certification candidates

  • Network Security Engineers

  • Firewall Administrators

  • Network Engineers

  • Cybersecurity Professionals

  • SOC Analysts

  • Security Analysts

  • System Administrators

  • IT Infrastructure Engineers

  • Anyone interested in mastering Palo Alto Networks firewalls

Prerequisites

To get the most from this course, you should have:

  • Basic networking knowledge

  • Understanding of TCP/IP and IP addressing

  • Familiarity with routing and switching concepts

  • Basic firewall knowledge is helpful but not required

No previous Palo Alto experience is required. Every concept is explained from the ground up with practical demonstrations.

By the End of This Course

By completing this course, you will confidently deploy, configure, manage, monitor, and troubleshoot Palo Alto Networks firewalls in enterprise environments. You will gain practical experience implementing advanced security policies, NAT, routing, VPNs, SSL decryption, Threat Prevention, WildFire, High Availability, and centralized monitoring using industry best practices.

Whether your goal is to earn the PCNSE certification, deploy Palo Alto firewalls in production, or advance your career as a network security professional, this course provides the practical skills and real-world experience needed to succeed.

Who this course is for:

  • This course is for students trying to obtain the PCNSE.
  • This course is for students trying to learn the Palo Alto Firewall.
  • Any Network or Security Engineer want to learn or polish their Skills.