Palo Alto Networks NGFW Firewall Engineering
Master Next-Generation Firewall Engineering, App-ID Logic, and Panorama Central Management

Enroll in Palo Alto NGFW Training
Get started with a free demo class.
Course Overview
This deep-dive technical engineering course focuses on deploying and managing Palo Alto Networks Next-Generation Firewalls running PAN-OS. Security professionals will transition from traditional port-based filtering to advanced identity- and application-aware enforcement models. The curriculum progresses systematically through platform initialization via GUI and CLI, physical and logical interface mapping, and security zone segmentation. Participants will gain experience configuring structural Traffic Processing vectors, including App-ID mapping, User-ID context gathering, and active Content-ID threat prevention profiles. Additionally, the course provides instruction on establishing high-availability clusters and utilizing Panorama to manage distributed multi-firewall deployments.
Who Should Learn
Prerequisites
- Solid understanding of standard TCP/IP networking, subnet routing layout, and packet transmission dynamics
- Familiarity with foundational cybersecurity concepts like network address translation (NAT), DNS resolution, and cryptographic SSL/TLS parameters
Learning Outcomes
Course Curriculum
1Module 1: PAN-OS Architecture & Management Interfaces4 topics
- Core capabilities and architectural single-pass processing framework of Palo Alto Networks firewalls
- Navigating administrative channels: Programmatic REST APIs, terminal CLI commands, and the web GUI
- Managing operational software configurations, system backups, and localized PAN-OS version updates
- Configuring service route redirections and system log forwarding profiles to centralized infrastructure
2Module 2: Interface Topology & Security Zone Segmentation4 topics
- Configuring specialized physical interfaces: Passive Tap lines and transparent Virtual Wire (Vwire) modes
- Deploying standard Layer 2 switching boundaries and routing-capable Layer 3 logical endpoints
- Defining interface management profiles and organizing security zone segmentation boundaries
- Implementing localized VLAN configurations, DHCP services, and Quality of Service (QoS) bandwidth throttles
3Module 3: Core Packet Routing, Dynamic NAT & DNS Proxying3 topics
- Configuring Virtual Routers, static interface routing lines, and multi-tenant Virtual Systems (VSYS)
- Implementing Source and Destination Network Address Translation (NAT) alongside policy-based forwarding rules
- Setting up DNS Proxy profiles to manage network-internal name resolution mappings
4Module 4: Application Control via App-ID Frameworks3 topics
- Deep dive into the App-ID evaluation timeline and signature-matching phases
- Constructing layered Security Policies using specific application constraints over legacy port rules
- Authoring custom application signatures and establishing strict application override guidelines
5Module 5: Content-ID Threat Prevention & Traffic Decryption4 topics
- Tuning security profiles: Antivirus, Anti-Spyware, Vulnerability Protection, and File Blocking behaviors
- Deploying dynamic URL Filtering and WildFire sandbox tracking for cloud-based file analysis
- Enforcing Zone Protection metrics and DoS mitigation rules to shield edge zones
- Configuring SSL Decryption policies for inbound server arrays and outbound user web traffic
6Module 6: Identity Mapping with User-ID & Captive Portal3 topics
- Architecting User-ID frameworks: Deploying server-based directory agents and API scrapers
- Mapping directory group attributes directly into access policies to eliminate IP reliance
- Configuring web-redirect Captive Portals to catch unknown network traffic points
7Module 7: Site-to-Site IPsec VPNs & GlobalProtect Mobility3 topics
- Establishing encrypted site-to-site communication lines using static or dynamic IPsec tunnels
- Deploying GlobalProtect portal components and secure endpoint gateway interfaces
- Configuring client software installation packages, authentication vectors, and connection rules
8Module 8: High Availability Clusters & Panorama Central Orchestration3 topics
- Configuring Active/Passive High Availability (HA) connections with live heartbeat session sync
- Deploying Panorama central management: Designing Device Groups, Templates, and shared objects
- Consolidating distributed logging profiles, tracking analytical metrics, and building compliance audit reports
Certification
Earn the SkillSurf Certified Network Security Professional designation upon completing all lab deployment milestones and clearing the comprehensive firewall configuration assessment.
