
Master Palo Alto firewall version 11 essentials through hands-on configuration and monitoring in a lab. Prepare for PC and ESA certification with architecture, App ID, User ID, and SSL decryption.
Learn core network security terms such as assets, vulnerability, exploit, threat, attack, risk, and countermeasure, and how they relate to protecting an organization's assets.
Learn confidentiality, integrity, and availability as core goals of network security, with encryption and access controls protecting data at rest and in motion.
Explore core security concepts by examining malware types—viruses, worms, trojans, spyware, rootkits, keyloggers, ransomware, adware, scareware—and attack vectors like SQL injection, cross-site scripting, phishing, botnets, and data breach.
Explore firewall technologies across generations from packet filter and stateless to stateful and next-generation, covering hardware, software, cloud, and virtual solutions, including UTM, proxy, and application firewalls.
Explore how Palo Alto's next generation firewall extends traditional firewalls with App ID, User ID, Content ID, and deep packet inspection to control traffic by application, user, and content.
Understand why a web application firewall protects web applications from common vulnerabilities, and how WAFs differ from traditional and next generation firewalls.
Discover Palo Alto Networks, a leading USA cybersecurity company, offering a next-generation firewall with app ID, user ID, and content ID, capable of identifying 900+ applications, with 24/7 support.
Master zero trust security by enforcing strict identity verification for every person or device, inside or outside the network, with least privilege, multifactor authentication, and continuous monitoring.
Palo Alto firewall architecture uses SP3 single pass software and parallel processing hardware with separate control (management) and data planes to accelerate security checks.
Learn to download the EVE-NG community edition version 6.204 from the official site and install it on VMware Workstation Pro, including configuring hardware, ISO boot, and initial web access.
Learn how to upload ios switches to eve-ng using ftp with winscp, download and extract images, apply the license, set correct naming, and enable layer 3 functionality on l2 devices.
Learn to upload and configure ready-made lab images in EVE-NG, including pfSense with six interfaces and images for Linux, Kali, Windows Server, and Windows 11.
Learn to upload a Palo Alto firewall image to eve-ng using WinSCP, create the proper folder and naming, set permissions, and boot the device with admin/admin after startup.
Learn how to upload palo alto panorama to eve-ng via ftp using winscp, create the panorama folder with version 11, apply fixed permissions, and start panorama in the lab.
Set up a Palo Alto firewall lab with HQ, two WANs, a LAN, a DMZ, and a management subnet, using VLANs 40 and 50 on subinterfaces.
Export and import ready-made lab topologies into EVE-NG to quickly deploy Palo Alto firewall labs. Learn how to handle professional vs community editions, clouds, IP subnets, and pre-uploaded images.
Configure a lab network by assigning IP addresses to PCs, servers, and Active Directory; set up a DMZ switch with VLAN 40 and 50, and trunk to the HQ firewall.
Learn to configure Active Directory on Windows Server, install Active Directory Domain Services via Server Manager, and promote a server to a domain controller for a test.local forest.
Configure DNS after active directory with DNS Manager to create forward zone for test.local, reverse zone for 192.168.100, add host records for HQ firewall and server, and verify with nslookup.
Create organizational units, users, and groups in Active Directory, and assign users to their groups while configuring passwords and group memberships.
Configure Windows Server 2016 as an NTP server by enabling time provider, adjusting the announce flag and time service to automatic, and verifying with an NTP test tool.
Master the initial configuration of a Palo Alto firewall, using mgmt and console ports, default admin credentials, and cli or graphical setup for physical or virtual devices.
Demonstrates the initial configuration of the HQ firewall, including changing the admin password, and setting a static management IP (192.168.100.200) via CLI or graphical interface, then verifying with show commands.
Navigate the Palo Alto firewall dashboard to view software versions, interface status, resources, and logs with customizable widgets and layout.
Explain Palo Alto firewall cli access in operational and configuration modes, log in via ssh, telnet, or console, switch with configure, run show, request, and commit commands.
Configure DNS and NTP on the Palo Alto firewall using graphical or CLI approaches. Set primary and secondary DNS and NTP, then adjust hostname, domain, login banner, and time zone.
Palo Alto Firewall uses security zones to group interfaces, enforce inter-zone policies, and keep intra-zone traffic allowed.
Create four layer-three security zones (two internet zones, LAN, and DMZ) on the Palo Alto firewall, assign interfaces and subinterfaces, then commit changes.
Explore virtual routers in the Palo Alto firewall, showing how to group layer-3 interfaces, configure static and dynamic routes (rip, ospf, ospf3, bgp), and enable routing between subnets.
Create a second virtual router named VR one in the Palo Alto firewall, configure zones including DMZ and interfaces, then commit the changes via the web interface.
Configure Palo Alto firewall interfaces to route traffic using physical and virtual interfaces, including subinterfaces, VLANs, loopbacks, tunnels, and SD-WAN, with topology examples.
Configure layer 3 interfaces on the Palo Alto firewall, including two subinterfaces for VLANs 40 and 50 in DMZ. Verify connectivity via ping across LAN and DMZ.
Create interface management profiles to protect the firewall, defining permitted services and IPs on layer 3 interfaces, subinterfaces, loopback, and VLAN, with a ping-only and a secure management profile.
Configure dual default routes on a Palo Alto firewall for two ISPs, using static routes to 0.0.0.0/0 via interfaces 1/1 and 1/2 with next hops 1.254 and 2.254.
Explore how security policies in the Palo Alto firewall allow or deny traffic, evaluated top-to-bottom and left-to-right, with intra-zone, inter-zone, and universal rules.
Develop and commit four Palo Alto firewall security policies: LAN to DMZ, LAN to internet, DMZ to internet, internet to DMZ, and verify traffic via monitoring.
Understand network address translation on the Palo Alto firewall, translating private IPs to public addresses for internet access; includes source, destination, and u-turn NAT with static/dynamic IP and port translation.
Explain source network address translation for outbound traffic from internal subnets, detailing dynamic IP and port, dynamic IP, and static IP NAT on Palo Alto firewalls.
Explore destination NAT, translating public addresses to private servers in a DMZ, with static and dynamic IP options, port forwarding, and port translation for internet access to internal web servers.
Configure two source-nat policies on the Palo Alto firewall to translate LAN and DMZ traffic to the outside interfaces using dynamic IP and port for two internet service providers.
Configure destination net policy and static destination nat to expose two dmz web servers from the internet, test accessibility, and troubleshoot firewall rules and routing.
Explore SSL inspection, decrypting and inspecting encrypted traffic like HTTPS and TLS with a firewall acting as a man-in-the-middle.
Generate self-signed certificates on a Palo Alto firewall using device certificate management, creating trusted and untrusted certificates, exporting the trusted base64 certificate, and distributing via Active Directory for SSL/TLS inspection.
Export the certificate from the HQ firewall as base64, then install it on the client PC into the browser's trusted root certificate authority store and verify in the browser.
Configure decryption policies with ssl forward proxy on a palo alto firewall, applying to lan to dmz or when1/when2 destinations, and create exclusions for government, financial, and shopping sites.
Learn to generate and install Palo Alto self-signed certificates, create three decryption policies: trusted, untrusted, and excluded domains, and verify SSL decryption on client traffic.
Security profiles add checks such as antivirus, anti-spyware, vulnerability protection, URL filtering, file blocking, data filtering, and wildfire analysis to allowed traffic, with logs for monitoring.
Explore seven Palo Alto security profiles, including antivirus, anti spyware, vulnerability protection, URL filtering, file blocking, data filtering, and wildfire analysis, and how they inspect traffic after an allowed policy.
Configure an antivirus security profile AB profile on the HQ firewall, apply it to the LAN-to-internet policy, ensure licenses and updated signatures, then test and verify virus blocking via logs.
Configure and validate an anti spyware profile on a Palo Alto firewall version 11, attach it to the lan-to-internet policy, test with URLs, and verify spyware logs.
Configure a vulnerability protection profile on a Palo Alto firewall v11, attach it to the LAN-to-internet policy, and validate protection via threat monitoring and Kali-based vulnerability tests.
Create and attach a file blocking security profile to the LAN-to-internet policy in the Palo Alto firewall, then test by downloading seven zip to verify blocks and monitor logs.
Create and test a wildfire analysis profile on the Palo Alto firewall, attach it to the land-to-internet policy, and monitor submissions via logs and CLI during SSL-decrypted tests.
Learn to configure data filtering profiles on Palo Alto firewall, create data patrons (credit card, confidential regex, file properties), and attach them to a DMZ policy for DMZ LAN testing.
Consolidate multiple security profiles into a single security profile group to simplify policy application, enabling one-click assignment of antivirus, anti-spyware, URL filtering, data filtering, and more to security policies.
Create two security profile groups for a Palo Alto firewall lab—DMZ and WAN—and apply them to the corresponding policies to enforce group-based protection.
Block malicious URLs and phishing sites with Palo Alto URL filtering using Bright Cloud or Penn DB. Apply policies to block, allow, or continue with URL categories and logs.
Block malicious URLs with url filtering on Palo Alto firewall via a security policy, applying categories such as adult, extremism, hacking, and malware, then verify with logs and monitors.
Apply a url filtering profile to block malicious urls, configuring categories such as adult, command and control, extremism, malware, phishing, proxy, and peer-to-peer, and verify via logs.
Block custom URL categories through a security policy by creating a custom URL category, enabling URL filtering, and testing blocked sites like BBC, Fox News, Guardian, NBC, and CNN.
Block URLs via external dynamic list in a security policy, creating edl.txt with Yahoo, MSN, Bing, and Udemy, and applying it to the block URL policy.
Demonstrates using external dynamic lists and custom URL categories within a URL filtering profile to block sites or allow traffic through security policies, with CLI verification and monitor checks.
Understand app id, the Palo Alto next generation firewall’s method to identify, label, monitor, and control applications, enabling policy based on application across layer 7 visibility.
Discover how App-ID uses signature databases, protocol decoders, heuristics, and known/unknown protocol decoders to identify applications and enforce security policies, including SSL/TLS decryption.
Identify applications on a Palo Alto firewall using four methods—application signature, decryption policy for encrypted traffic, known protocol decoder, and unknown protocol decoder with heuristics—while validating security policy.
Track how a session shifts from web browsing to SSL to Facebook chat on a Palo Alto firewall, prompting a new security policy lookup and application match.
Explore how the application window shows YouTube and Facebook bases, their dependencies and implicit use, ports 80 and 443, and how to enable them in Palo Alto firewall version 11.
Identify dependent applications and their required partners, such as YouTube and Google base, or Office on demand with Office 365 base and SharePoint online in Palo Alto firewall policies.
Explain implicitly used applications in Palo Alto firewall, showing how dependencies like web browsing and SSL are automatically allowed to enable applications such as Facebook and Google Base.
Create static application groups in Palo Alto Firewall version 11 by combining multiple apps or groups with optional filters. Updates apply in policies automatically, while new apps require manual addition.
Create application filters in Palo Alto Firewall to group apps by category, subcategory, risk level, and tags. Apply these filters in policies to automatically include new apps without manual updates.
Enable the application block page on Palo Alto firewall, configure an interface management profile, and customize the banner to show the user or IP and blocked app when policy blocks.
Identify how Palo Alto firewall app ID detects applications in encrypted and decrypted SSL traffic using decryption policies, certificates, common name, SNI, and signature, decoder, and heuristic methods.
Explore how policy optimizer migrates legacy port-based rules to ep id application-based rules in palo alto firewall, through three phases: identify, top-of-rule creation, and monitoring before cleanup.
Create an app-id security policy for LAN to internet traffic, enable inter-zone logging and application block pages, and test with PC1 to allow Facebook, DNS, and SSL/web browsing.
Migrate port-based firewall rules to application-based policies on Palo Alto firewall using policy optimizer. Test SSH and web browsing across LAN to DMZ and replace old rules with app-based ones.
Course Overview:
Successful completion of this course should enhance the student’s understanding of how to configure and manage Palo Alto Networks next-generation firewalls. The student should learn and get hands-on experience configuring, managing, and monitoring a firewall in a lab environment. The Firewall Configuration and Management (PAN EDU 210) course covers all the content required for the PCNSA Palo Alto Networks Certified Network Security Administrator certification.
EDU-210 Course Description:
This training is the most important course as it covers all the fundamentals to understand the Next-Generation Firewall from the ground up. Even experienced firewall engineers take a lot out of this course as it includes, besides the architecture and management essentials, topics like Application Identification, Content ID (IPS, Anti-Virus/-Spyware, URL Filtering, File Blocking), SSL Decryption and User Identification which are all features usually not supported by legacy firewalls.
Outline:
01. Introduction and Initial Configuration
02. Palo Alto Architecture
03. Configuring Initial Firewall Settings
04. Managing Firewall Configurations
05. Interface Configuration
06. Managing Firewall Administrator Accounts
07. Connecting Firewall to Production Networks
08. Security Zones
09. Creating and Managing Security Policy Rules
10. Creating and Managing NAT Policy Rules
11. App-ID (Application Identity)
12. Security Profiles
13. URL Filtering
14. WildFire
15. User-ID (User Identity)
16. Encryption and Decryption
17. Monitoring and Reporting
Product Versions:
Palo Alto Firewall PAN-OS Version 11.0.0
Objectives:
After completing this course, you should be able to:
o Install and configure new Palo Alto Networks Next-Generation Firewalls.
o Manage the Palo Alto Next-generation Firewall’s configurations.
o Configure the Firewall to connect to your production network.
o Manage the Security Policy Rules used to protect your network.
o Manage Network Address Translation (NAT) Rules.
o Configure and manage Palo Alto Networks next-generation firewalls.
o Configuring, managing, and monitoring a firewall in a lab environment.
o Configure & manage essential features of Palo Alto next-generation firewalls.
o Configure and manage Security and NAT policies to enable approved.
o Configure and manage Threat Prevention strategies to block traffic.
o Configure Policy based on application (App-ID) and user identity (User-ID).
o Configure SSL Decryption on Firewall to inspect & control decrypted sessions.
o Monitor network traffic using the interactive web interface and firewall reports.
Prerequisites:
Students must be familiar with networking concepts, including routing, switching, and IP addressing. Students also should be familiar with basic security concepts. Experience with other security technologies (IPS, proxy, and content filtering) is a plus.
Lab Images:
Palo Alto Firewall: Paloalto-11.0.0
Palo Alto Panorama: Panorama-11.1.0
Cisco Switches: i86bi_linux_l2-ipbasek9-ms.high_iron_aug9_2017b.bin
Windows 11: Windows 11-x64-SE
Windows Server 2016: Winserver-S2016-R2-x64
Multiple WAN: Pfsense-2.6.0
Clients: Linux-slax-9.11.0
Web Servers: Linux-tinycore-6.4
Internet Link: NAT Cloud or Management Cloud