Practical training on the implementation and administration of Palo Alto PA-545 Next-Generation firewalls. Includes NGFW architecture, segmentation, routing, security policies, NAT, service publishing, Site-to-Site VPN, monitoring, logging, and troubleshooting. The GNS3 labs culminate in a final project involving the design and deployment of a secure corporate infrastructure.
Implementation and Administration of Palo Alto PA-545 Next-Generation Firewalls
Unit 1. NGFW Architecture and Lab Preparation
Contents
- Introduction to Palo Alto Networks.
- Architecture of a Next-Generation Firewall.
- PAN-OS components.
- Traffic processing flow.
- Security zones.
- Virtual Router.
- Design of corporate topologies.
Lab 1. Building the base topology
- GNS3 installation and configuration.
- Creation of the Trust network.
- Creation of the Untrust network.
- Creation of the DMZ.
- Creation of the Management network.
- IP addressing configuration.
- Connectivity validation. [ofertapaloalto545 | Word]
Unit 2. Network segmentation and access control
Contents
- Principle of least privilege.
- Zone-based design.
- User and server segmentation.
- Deny by Default.
- Security best practices.
Lab 2. Implementing segmentation
- Creation of Trust, Servers, and DMZ segments.
- Traffic separation between zones.
- Allowed access testing.
- Denied access testing.
- Validation via packet captures. [ofertapaloalto545 | Word]
Unit 3. Corporate routing
Contents
- Static routing.
- Default routes.
- Routing tables.
- OSPF concepts.
- BGP concepts.
- Routing troubleshooting.
Lab 3. Static routing
- Remote network configuration.
- Route configuration.
- Connectivity validation.
- Routing error resolution.
Lab 4. Dynamic routing
Unit 4. Security policies
Contents
- Security Policies.
- Network objects.
- Service objects.
- Allow rules.
- Deny rules.
- Communications matrix.
Lab 5. Policy implementation
Unit 5. NAT and service publishing
Contents
- Source NAT.
- Destination NAT.
- Secure application publishing.
- DMZ design.
- Best practices for exposing services.
Lab 6. Outbound NAT
- Source NAT configuration.
- Controlled browsing.
- Address translation validation.
- Traffic analysis.
Lab 7. Secure DMZ publishing
- Web server implementation.
- Destination NAT configuration.
- Controlled application publishing.
- Access verification.
- Analysis via Wireshark. [ofertapaloalto545 | Word]
Unit 6. Site-to-Site VPN
Contents
- Corporate VPN concepts.
- Site-to-site tunnels.
- Associated routing.
- Communications security.
Lab 8. Secure site-to-site connectivity
Unit 7. Logging and monitoring
Contents
- Traffic logs.
- Security logs.
- Monitoring.
- Event correlation.
- Packet capture.
Lab 9. Log centralization
Unit 8. Operational troubleshooting
Contents
- Incident resolution methodology.
- Connectivity diagnosis.
- Routing diagnosis.
- NAT diagnosis.
- Policy diagnosis.
- VPN diagnosis.
Lab 10. Incident resolution
Final integrative project
Design and implementation of a complete corporate infrastructure in GNS3:
- Trust Zone.
- Servers Zone.
- DMZ Zone.
- Management Zone.
- Untrust Zone.
- Static and dynamic routing.
- Security policies.
- Outbound NAT.
- Service publishing.
- Site-to-Site VPN.
- Log centralization.
- Incident resolution. [ofertapaloalto545 | Word]
Expected result
Upon completion of the training, the participant will be able to design, deploy, and administer a corporate security infrastructure applying the operating principles of Palo Alto firewalls, including segmentation, routing, NAT, VPN, monitoring, and troubleshooting through practical labs developed entirely in GNS3