Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Palo Alto Firewall
Rating: 4.3 out of 5(7 ratings)
35 students

Palo Alto Firewall

Manage & Secure networks
Created byMoiz Kareem
Last updated 7/2024
English
English [Auto],

What you'll learn

  • Palo Alto Firewall
  • Policies, vWire, virtual routers
  • VPN
  • Different types of interface modes with traffic tagged and untagged

Course content

1 section45 lectures7h 55m total length
  • Introduction4:12

    Explore the Palo Alto firewall architecture and installation, configure layer 2 and layer 3 zones with tagged interfaces, and study routing, VPNs, high availability, and panorama management.

  • Palo Alto Explanation12:13

    Palo Alto Networks next-generation firewall provides full visibility by inspecting traffic, application, and user identity, with app ID, URL filtering, GlobalProtect, and WildFire, enabled by SP3 single-pass architecture.

  • Installing Palo Alto in GNS34:55

    Install Palo Alto in GNS3 by obtaining the qcow or ovf files from the Palo Alto support center, then import the appliance and configure memory, ports, and console access.

  • Installing Palo Alto in EVE-NG4:05

    Install palo alto in eve-ng by following the event g documentation, creating the image, transferring and renaming qcow file, setting permissions, and building a topology with telnet or vnc access.

  • Installing Palo Alto in ESXI3:34

    Learn to install Palo Alto on ESXi using an OVA file, register the VM, select thin provisioning, allocate two vCPUs and six GB RAM, and configure networking and boot settings.

  • Setting up Firewall6:12
  • Firewall GUI12:46

    Explore the Palo Alto firewall GUI, including dashboard layout, widgets, objects and policies, interface configurations, device management, user roles, and commit workflows to apply changes.

  • Management Interface Overview4:21

    Explore the Palo Alto firewall management interface, including setup options, management IP, access methods (https, ssh, http, telnet), host-based access controls, commit/revert, telemetry, and basic session and decryption settings.

  • Zone and policy introduction9:09

    Explore how Palo Alto firewall zones and policies regulate traffic from inside to outside, using zone types, interface associations, and allow or block rules.

  • Layer 3 Interfaces7:25

    Configure layer 3 interfaces on a Palo Alto firewall, assign zones and IPv4 addresses, commit changes, enable ping with a management profile, and verify connectivity using OSPF, BGP, and RIP.

  • OSPF configuration3:11

    Configure OSPF on the Palo Alto firewall and Cisco router to form area 0, enable interface 1/1, and advertise the interface before committing. Monitor neighborship as it comes up.

  • BGP configuration7:04

    Configure BGP on a Palo Alto firewall and Cisco router by setting router IDs and AS numbers, creating peers, advertising a loopback network, and enabling BGP route installation.

  • RIP configuration7:11

    Enable rip on the palo alto default router, assign process id one, enable interface 1/3 with normal authentication, commit, and verify neighbors and loopback 120.1.1.1.

  • Redistribution Lab4:36

    Configure bidirectional redistribution between OSPF and BGP on a Palo Alto firewall, including loopback advertisement, redistribution profiles, and verifying routes with show commands.

  • Layer 2 interfaces with untagged traffic11:46

    Configure layer 2 interfaces on a Palo Alto using an untagged vlan object; establish l2 zones and a policy to allow inter-zone traffic between R1, R2, and R3.

  • Layer 2 interfaces with untagged traffic and multiple vlans3:49

    Configure the Palo Alto firewall as a layer 2 device to forward untagged traffic across multiple vlans, enabling communication between ten and twenty networks as a bridge in a zone.

  • Layer 2 interfaces with Tagged traffic27:14

    Configure layer 2 Palo Alto interfaces to tag vlan traffic using subinterfaces, trunks, and vlan ids ten and twenty; verify via a routing gateway and inter-vlan communication.

  • Layer 2 interfaces with Vlan interfaces13:33

    Move the default gateway to the Palo Alto by implementing layer 3 vlan interfaces for vlan ten and vlan twenty, assign ip addresses 10.1.1.254 and 20.1.1.254, and verify reachability.

  • Sub-interfaces4:35

    Configure layer three subinterfaces on a Palo Alto firewall, creating DMZ VLANs 10 and 20 with IPs 10.1.1.1/24 and 20.1.1.1/24, enable tagging on trunks, and verify reachability with management ping.

  • vWire with untagged traffic9:30

    Configure a Palo Alto virtual wire with untagged traffic by disabling trunking on switches, creating a vwire between interfaces, and using intra- and inter-zone policies to enable bidirectional traffic.

  • vWire with tagged traffic9:48

    configure Palo Alto firewall virtual wire to accept tagged traffic across VLANs, set interfaces 1/2 and 1/3 in the same virtual wire, then commit policies and verify inter-VLAN connectivity.

  • configuring static route7:48

    Configure a Palo Alto firewall with a layer 3 interface on 1/2, assign 192.168.122.1/24, create a default static route to the ISP, and verify via ping.

  • zone & policies overview3:40

    Configure layer three interfaces and subinterfaces on a palo alto firewall, assign dmz one and dmz two zones with 10.1.1.254/24 and 20.1.1.254/24, and enable management ping.

  • Creating loopback interface15:53

    Configure a loopback interface and loopback zone on the Palo Alto firewall, then apply bidirectional and unidirectional zone-based policies between DMZ zones to permit ping and traffic.

  • configuring zones & policies10:52

    Configure zones on a Palo Alto firewall to simplify policies, enabling DMZ one to DMZ two bidirectional traffic and inside to outside one-way access, across subinterfaces, with testing via ping.

  • Tunnel Interface7:40

    Configure a GRE tunnel between a Cisco router and a Palo Alto firewall, assign tunnel interfaces and IPs, enable keepalives, and verify connectivity with ping.

  • Lab Topology2:41

    Explore the Palo Alto firewall lab topology, an ESXi-based virtual setup with two management subnets and a DMZ domain controller running Active Directory, DNS, and certificate authority.

  • Configuring Lab Topology9:24

    Set up static routes and a default route on the Palo Alto to reach management networks, then create an inside-to-DMZ policy to allow internet access and verify connectivity.

  • NAT (PAT)11:09

    Configure natting (pat) on a Palo Alto firewall to allow inside and dmz traffic to access the internet using the public interface ip; test with ping and dns.

  • Destination NAT (one-to-one)14:53

    Configure destination net on a Palo Alto firewall to forward public IP 15.1.7.5 on port 443 to the domain controller web server, using a static net and net policy.

  • Decrypting traffic16:06

    Configure Palo Alto decryption policy to inspect SSL traffic by acting as a certificate authority, generate and trust the PA CA certificate, and decrypt 443 traffic.

  • Certificate profiles7:40

    Create and apply decryption and certificate profiles on Palo Alto firewall to block sessions with expired or untrusted certificates and enforce certificate trust settings.

  • Security profiles13:15

    Explore how security profiles in Palo Alto firewall enable antivirus, anti-spyware, vulnerability scanning, URL filtering, file blocking, and DDoS protection with traffic decryption and policy grouping.

  • Service profiles7:47

    Explore Palo Alto firewall service profiles, configuring SNMP, syslog, email, netflow, radius, LDAP, Kerberos, SAML, and multi-factor authentication with dedicated profile settings.

  • Network profiles17:50

    Learn to configure network profiles on a Palo Alto firewall, covering ipsec and ike phase one, vpn attributes, interface management, zone protection, qos, lldp, and bfd profiles.

  • Site-to-Site VPN40:54

    Learn how to configure a Palo Alto site-to-site IPsec VPN with IKE v2, set up tunnel interfaces, define gateways and policies, and verify encrypted traffic between headquarters and data center.

  • High availability active/standby17:35

    Learn how to configure Palo Alto firewall high availability in active/standby mode, using control and data links, with config synchronization between two identical devices.

  • High availability active/standby with single interface8:37

    Explore configuring high availability on Palo Alto firewall in active/standby with single interface, test failover, and validate synchronization as you remove backup data and control links.

  • High availability active/active8:49

    Explore configuring active-active high availability on a Palo Alto firewall, switching from active-passive, syncing devices, and troubleshooting nat policies and static translation during commits.

  • Floating IPs in active/active for NAT18:37

    Learn how active-active Palo Alto firewalls share floating IPs for inside and outside NAT, configure dynamic IP NAT rules, and rely on router-based load balancing.

  • User ID18:40

    Learn to configure Palo Alto user ID by directly integrating with Active Directory, including DNS resolution, user mapping, LDAP profiles, and using domain users in policies.

  • User Policy & ACC12:52

    Apply a domain user block policy on a Palo Alto firewall to deny http/https access from inside to external servers, verify with user IDs, logs, and application center insights.

  • Virtual routers lab16:25

    Explore configuring two virtual routers (VR1 and VR2) to segregate routing tables for inside, dmz, and outside networks, with static routes and connectivity checks.

  • Panorama introduction10:13

    Panorama centralizes management for Palo Alto firewalls, aggregates logs for analysis and reporting to enable threat response, and enables distributed administrators with templates and policies across virtual and physical deployments.

  • Panorama installation in EVE-NG4:59

    Download Palo Alto panorama image and transfer it to the eve-ng host. Create a 100 GB hard disk, allocate 8 CPUs and 16 GB RAM, then boot panorama node.

Requirements

  • Basic Networking

Description

Palo Alto Networks is a renowned company, recognized as a leader in cybersecurity protection. They offer a range of products and solutions, including the Palo Alto firewall. This firewall is known for its advanced security features, such as App-ID and PAN-OS. App-ID provides application visibility and control, enabling precise identification of nearly 3,000 applications, even those using non-standard ports. PAN-OS is the operating system that drives Palo Alto Networks' next-generation firewalls, providing a wide array of security features in a single platform. The Palo Alto firewall is designed to prevent known and unknown threats, providing comprehensive security for your network. It also offers a Panorama Administrator's Guide for easy management and configuration. Palo Alto Networks is committed to protecting organizations of all sizes from cyber threats, with locations worldwide, including Palo Alto, California, and Australia.

The Palo Alto firewall is a next-generation firewall that goes beyond traditional firewall capabilities. It integrates essential security functions, such as network firewall, URL filtering, and intrusion prevention system, into one platform. This integration helps simplify security management and improve operational efficiency.

Another important feature is the PAN-OS, the operating system that powers the Palo Alto firewall. PAN-OS provides a wide range of security features, including advanced threat prevention, URL filtering, and WildFire, a cloud-based threat analysis service. These features work together to provide comprehensive protection against known and unknown threats.

The Palo Alto firewall also offers a centralized management system, Panorama, which allows administrators to configure, manage, and monitor multiple firewalls from a single interface. This feature simplifies administration and helps ensure consistent security policies across the network.

In addition to its advanced security features, Palo Alto Networks is also committed to providing excellent customer support and resources. Their website offers a comprehensive Administrator's Guide, as well as other resources, to help users get the most out of their firewall. With its robust features and strong commitment to customer support, the Palo Alto firewall is a top choice for many organizations looking to enhance their network security.

Who this course is for:

  • Beginners
  • Firewall Admins
  • Network Engineers
  • IT Help desk or support