Palo Alto Networks Essentials, Configuration and Management

€755.00
| /

________________________________________________________________

Do you want to take this course in another training mode?
Contact us

Other modes: Telepresence - Classroom

________________________________________________________________

Palo Alto Networks Fundamentals Course: Configuration and Administration | Palo Alto Networks

Palo Alto Networks is one of the world's leading manufacturers of cybersecurity solutions and Next-Generation Firewalls (NGFW). Its platforms enable the protection of corporate networks through segmentation, access control, traffic inspection, advanced security policies, secure connectivity between sites, and threat monitoring and analysis capabilities.

Palo Alto Networks technologies are used by organizations in every sector to protect critical infrastructure, control traffic between security zones, publish services securely, and ensure connectivity between users, offices, and applications. These capabilities are essential for IT, networking, operations, and cybersecurity departments.

This Palo Alto Networks course provides practical training focused on the configuration and administration of environments inspired by NGFW architectures, allowing students to understand essential concepts such as segmentation, security policies, NAT, routing, VPN, monitoring, and troubleshooting. The approach is designed to develop competencies applicable to real-world business environments and aligned with PAN-OS functionalities.

Furthermore, this training is eligible for funding via FUNDAE for companies that meet the established requirements, facilitating the training of professionals in secure network administration and corporate cybersecurity technologies.

Course Overview

The Palo Alto Networks Fundamentals: Configuration and Administration course provides the knowledge and skills necessary to understand the operation of next-generation firewalls and apply best practices for the design, segmentation, protection, and administration of corporate networks.

Throughout the training, participants will learn to work with key Palo Alto Networks concepts such as security zones, interfaces, routing, NAT, access policies, user management, monitoring, and troubleshooting. The program combines theoretical foundations with lab practices aimed at replicating common administration and operation scenarios for secure infrastructures.

The training also incorporates scenarios related to connectivity between sites, site-to-site VPN, observability, traffic analysis, change control, and technical documentation, providing a comprehensive view of modern security environment operations.

Upon completion of the course, students will be able to design segmented architectures, implement access controls based on least privilege, manage configurations securely, and understand the relationship between the concepts practiced and their functional equivalents within Palo Alto Networks solutions and PAN-OS.

What Nanfor courses include

At Nanfor, we offer a complete training experience that combines quality educational material, expert guidance, and our own learning platform, adapted for both individual and corporate training.

All our courses include official and complementary educational material, practical activities, learning assessments, forums, a virtual advisor, progress tracking, and personalized academic support throughout the training, in addition to a certificate of completion.

Learn about all the components

Advantages of Palo Alto Networks training

  • Understand the operating principles of Next-Generation Firewalls (NGFW) and their application in real business environments.
  • Learn to design segmented networks using security zones while applying the least privilege principle.
  • Develop skills to configure interfaces, zones, routing, and access policies following cybersecurity best practices.
  • Implement stateful security rules and deny-by-default strategies to control traffic between network segments.
  • Configure and validate Source NAT and Destination NAT scenarios commonly used in corporate infrastructures.
  • Design and protect DMZ environments for the secure publication of externally accessible services.
  • Understand the relationship between security policies, routing, NAT, and session establishment within an NGFW architecture.
  • Learn to implement secure connectivity between sites via site-to-site VPN and controlled access policies.
  • Develop monitoring, traffic analysis, and troubleshooting capabilities using logs, syslog, and packet captures.
  • Apply professional troubleshooting methodologies to diagnose connectivity, security, and performance issues.
  • Incorporate best practices for administration, documentation, change control, and configuration management using tools like Git.
  • Acquire knowledge transferable to Palo Alto Networks and PAN-OS environments, understanding the equivalence between practical labs and enterprise firewall functionalities.

Prerequisites

To make the most of this training, it is recommended that participants have:

  • Basic knowledge of TCP/IP networking, IPv4 addressing, and device connectivity.
  • Familiarity with general concepts of routing, network services, and system-to-system communications.
  • Basic knowledge of system administration or technological infrastructures.
  • An interest in cybersecurity, network segmentation, and protecting corporate infrastructures.
  • Basic knowledge of accessing Linux systems or using network tools will be useful during the practicals.
  • No prior experience with Palo Alto Networks is required to take the course.
  • No advanced programming knowledge or previous experience in next-generation firewall administration is required.

General Course Information

Who is this Palo Alto Networks course for?

This course is aimed at professionals who wish to acquire a solid foundation in next-generation firewall administration, network segmentation, and corporate infrastructure protection using concepts and methodologies associated with Palo Alto Networks.

  • Network administrators.
  • System technicians and administrators.
  • Cybersecurity professionals.
  • Support and infrastructure engineers.
  • Corporate communications and connectivity managers.
  • Network and security consultants.
  • Professionals looking to start working with Palo Alto Networks technologies.
  • IT operations teams tasked with corporate network administration.
  • Individuals interested in NGFW firewalls, segmentation, and perimeter security.
  • Individuals who want to acquire practical knowledge transferable to PAN-OS environments.

Training objectives: What will you learn?

Upon completing this training, you will be able to understand the fundamentals of Palo Alto Networks and apply best practices for design, segmentation, connectivity, and security in modern corporate infrastructures.

  • Understand the architecture and essential concepts of Next-Generation Firewalls (NGFW).
  • Design zone-segmented networks using the principle of least privilege.
  • Configure interfaces, security zones, and segmentation strategies.
  • Implement stateful filtering policies and deny-by-default models.
  • Manage security rules based on controlled access and authorized services.
  • Configure and validate Source NAT and Destination NAT scenarios.
  • Design and protect DMZ environments for the controlled publication of services.
  • Implement static routing and understand the fundamentals of OSPF and BGP.
  • Establish secure connectivity between sites via site-to-site VPN.
  • Monitor traffic and analyze network events using logs, syslog, and packet captures.
  • Apply structured troubleshooting methodologies to resolve connectivity and security incidents.
  • Manage configurations, backups, and change procedures in a controlled manner.
  • Use documentation, automation, and version control tools via Git.
  • Relate concepts practiced in the lab to the equivalent features available in PAN-OS.

Palo Alto Networks Fundamentals: Configuration and Administration course content — Program

Unit 1. Palo Alto Networks Fundamentals and Initial Configuration — 5 hours

Theoretical content

  • Evolution from the traditional firewall to NGFW.
  • General architecture of Palo Alto Networks: data plane, control plane, and PAN-OS.
  • Concepts of management interface, administration, roles, and initial configuration.
  • Zone model as a basis for policy enforcement.
  • Difference between vendor-specific knowledge and transferable firewall fundamentals.

Practice 1. Design, Addressing, and Initial Connectivity — 2 hours

  • Building the base topology in GNS3.
  • Creating Trust, DMZ, Untrust, and Management segments.
  • Configuring IPv4 addresses, gateway, IPv4 forwarding, and return routes.
  • Validation using ip addr, ip route, ping, and traceroute.

Evidence

  • Network diagram.
  • Addressing table.
  • Interface, route, and connectivity test outputs.

Relation to PAN-OS

Students associate the physical/logical segmentation in GNS3 with the subsequent configuration of Layer 3 interfaces, security zones, and Virtual Router in PAN-OS.

Unit 2. Interfaces, Zones, and Routing — 7 hours

Theoretical content

  • Physical, logical, and sub-interfaces.
  • Security zones and separation of trust domains.
  • Virtual Router and static routing.
  • Dynamic routing: purpose of OSPF and BGP in corporate environments.
  • Relationship between interface, zone, route, policy, and session.

Practice 2. Zone Segmentation and Deny-by-default — 2 hours

  • Defining zone-equivalent chains in nftables.
  • Permitting established,related traffic.
  • Default denial of new connections.
  • Logging relevant drops.
  • Temporary ICMP Trust–DMZ test and verifying the block after removing the rule.

Practice 3. Internal Segmentation with VLANs or Subnets — 2 hours

  • Expansion with a Servers zone: 10.10.30.0/24.
  • Separation between users, servers, DMZ, and management.
  • Selective permissions for HTTP/HTTPS, DNS, and administrative SSH.
  • Checking for blocked lateral movement attempts.

Practice 4. Static Routing and Route Troubleshooting — 1.5 hours

  • Adding a remote network, e.g., 172.16.50.0/24.
  • Configuring outbound and return routes.
  • Diagnosing a deliberate routing issue using ip route get, traceroute, tcpdump, and logs.

Practice 5. OSPF or BGP with FRRouting — 1.5 hours

  • Configuring FRRouting as an ISP router or remote site.
  • Establishing OSPF or BGP adjacencies.
  • Prefix advertisement, routing table verification, and analysis during a route failure or change.

Evidence

  • Segmentation matrix.
  • nftables and FRR configuration.
  • Routing table before/after and test evidence.

Relation to PAN-OS

These exercises prepare students for configuring Security Zones, static routes, Virtual Router, OSPF/BGP, and forwarding diagnostics in PAN-OS.

Unit 3. Objects, Security Policies, and NAT — 9 hours

Theoretical content

  • Address objects, service objects, and logical grouping.
  • Security rules, evaluation order, cleanup rule, and least privilege.
  • Stateful policies and the difference between allowing a new session versus return traffic.
  • Source NAT: SNAT, PAT, and masquerade.
  • Destination NAT: DNAT and controlled service publication.
  • Difference between routing, security policy, and NAT.

Practice 6. Objects, Groups, and Communications Matrix — 2 hours

  • Defining logical sets: clients, web server, DNS, and administration.
  • Creating DNS, HTTP, HTTPS, SSH, and ICMP services.
  • Designing the source–destination–service–action–justification matrix.
  • Replacing an overly broad rule with least-privilege policies.

Practice 7. Outbound NAT for internal users — 2 hours

  • Configuring Source NAT/PAT from Trust to Untrust.
  • Limited permission for DNS, HTTP, and HTTPS.
  • Validation using curl and dig.
  • Capture in Untrust to verify source address translation.
  • Verifying a blocked SSH attempt.

Practice 8. Secure publication of a server in the DMZ — 2.5 hours

  • Setting up Nginx in the DMZ.
  • Configuring DNAT from an external IP/port to the web server.
  • Creating the specific filtering rule for HTTP.
  • Verifying HTTP allowed and SSH blocked.
  • Analysis of original vs. translated IP/port using logs and captures.

Practice 9. Integrated Policy and NAT Case — 2.5 hours

  • Designing a complete policy for users, servers, DMZ, and a simulated external network.
  • Implementing controlled browsing, internal access to applications, and web publishing.
  • Introducing three deliberate failures: policy, NAT, and return route.
  • Diagnosis and documented correction.

Evidence

  • Communications matrix and rule justification.
  • Filtering and NAT configuration.
  • Traffic captures and allowed/blocked access logs.
  • Diagnostic report of the introduced failures.

Relation to PAN-OS

Conceptual equivalence to Address Objects, Service Objects, Security Policy Rules, Source NAT, Dynamic IP and Port, and Destination NAT.

Want to take this course? Request information now

If you wish to take this course virtually, you can purchase it at the top of the product page. If you have any questions, please contact us.

If you wish to take it in a classroom-based or tele-present mode, contact us:

Why choose Nanfor as a specialized ICT training center?

Nanfor is a specialized ICT training center with extensive experience in technological training for professionals and companies. Our programs combine up-to-date content, a practical approach, and expert guidance to facilitate the real-world application of knowledge in the workplace.

  • Expert tutors with real-world experience in projects, technologies, and professional certifications.
  • Personalized academic support throughout the training to track the student's progress.
  • Practical methodologies based on real-world cases and scenarios applicable to the job position.
  • Proprietary learning platform with resources, activities, assessments, and continuous monitoring.
  • Training aligned with technological trends and the current needs of organizations.
  • Flexible learning modalities: online, in-person, and telepresence.
  • Experience in corporate training programs and digital talent development.

Frequently asked questions about the course

What is Palo Alto Networks and what is it used for in companies?

Palo Alto Networks is a leading manufacturer of cybersecurity solutions specializing in Next-Generation Firewalls (NGFW). Organizations use Palo Alto Networks to protect networks, control traffic between security zones, prevent unauthorized access, and secure connectivity between users, applications, and corporate offices.

What sets Palo Alto Networks apart from other firewalls and security solutions?

Palo Alto Networks incorporates an NGFW approach that combines segmentation, advanced traffic control, application management, session analysis, and integrated security capabilities. The concepts learned in Palo Alto Networks are applicable to modern enterprise environments where visibility and control are fundamental.

Is the Palo Alto Networks course eligible for FUNDAE subsidies?

Yes. This Palo Alto Networks course can be eligible for FUNDAE subsidies for companies that meet the established requirements. This facilitates the training of networking, systems, and cybersecurity teams in enterprise protection technologies.

What is the duration of the Palo Alto Networks course and how long will I have access to the virtual campus?

The duration and access period for the Palo Alto Networks course are detailed in the training datasheet. During that time, participants will be able to access content, practical labs, support resources, and specialized academic support.

Is the Palo Alto Networks course included in Nanfor's LaaS?

Yes. This Palo Alto Networks course is part of Nanfor's LaaS (Annual Continuous Training License), allowing access to up-to-date training in cybersecurity, networking, and technology infrastructure administration.

Do I need prior experience with Palo Alto Networks to take this course?

No. The Palo Alto Networks course is designed for professionals who wish to acquire a solid foundation in NGFW firewall administration. It is recommended to have basic knowledge of TCP/IP networking, IP addressing, and connectivity.

What practical knowledge will I learn about Palo Alto Networks?

In this Palo Alto Networks course, you will learn how to work with network segmentation, security zones, access policies, NAT, routing, site-to-site VPN, monitoring, troubleshooting, and best practices for administration and change control.

How is Palo Alto Networks applied in the daily work of a network or security administrator?

Palo Alto Networks is used daily to control access between networks, protect corporate services, manage traffic, publish applications securely, monitor incidents, and ensure connectivity between users, applications, and corporate offices.

Does the Palo Alto Networks course include practical labs?

Yes. The Palo Alto Networks course incorporates numerous exercises oriented toward real-world scenarios, including zone-based segmentation, NAT configuration, VPN, routing, service publishing, log centralization, and incident resolution through traffic analysis.

What is the relationship between the course labs and a real Palo Alto Networks environment?

The Palo Alto Networks course uses labs that allow for an understanding of the technical fundamentals that are subsequently applied in PAN-OS. Participants learn concepts equivalent to Security Zones, Virtual Router, Security Policies, NAT, VPN, and monitoring used in enterprise environments.

Does this Palo Alto Networks course prepare for real administrative and operational tasks?

Yes. The Palo Alto Networks course is oriented toward the practical administration of secure infrastructures, including network design, security policies, observability, change control, technical documentation, and troubleshooting methodologies used in real organizations.

💡 Did you know this course is included in LaaS Cert?

Take this course and many more with our LaaS Cert annual license . Unlimited training for only €1,295!

✅ Microsoft, Linux-LPI, SCRUM, ITIL and Nanfor technical courses

✅ Personalized support always by your side

✅ 100% online, official and updated

Get your license now!

LaaS cert Formación ilimitada

Information related to training

Soporte siempre a tu lado

Training support

Always by your side

Modalidades Formativas

Training modalities

Self Learning - Virtual - In-person - Telepresence

bonificaciones

Bonuses

For companies