Palo Alto Networks Essentials, Configuration and Management

Palo Alto Networks Essentials, Configuration and Management

Brand: Nanfor
878.00 USD In stock Buy at Merchant

General objectives Upon completion of the course, the participant will be able to: 1. Explain the architecture and essential concepts of a next-generation firewall and the Palo Alto Networks ecosystem. 2. Design a zone-segmented network by applying the principle of least privilege. 3. Implement stateful filtering policies and a default deny rule. 4. Configure and validate outbound NAT, destination NAT, and controlled publishing of services in a DMZ. 5. Configure static routing and understand the relationship between routes, policies, and address translation. 6. Introduce dynamic routing using OSPF or BGP in an emulated environment. 7. Implement a site-to-site VPN with a focus equivalent to secure inter-site connectivity. 8. Centralize logs, use packet captures, and apply a troubleshooting methodology. 9. Manage changes in a controlled manner using reproducible configuration, validation, and Git. 10. Relate practiced competencies to their functional equivalents in PAN-OS. Competencies and limits Competencies directly addressed · NGFW architecture and network segmentation. · Security zones, layer 3 interfaces, and routing. · Stateful access policies, rule ordering, and deny-by-default. · Source NAT/PAT and Destination NAT. · DMZ design and secure service publishing. · Static and dynamic routing. · Inter-site VPN, routes, and authorization policies. · Logging, syslog, packet captures, and connectivity analysis. · Configuration management, documentation, and change control. . Integrated program Unit 1. Fundamentals of Palo Alto Networks and initial configuration — 5 hours Theoretical content · Evolution from traditional firewall to NGFW. · General architecture of Palo Alto Networks: data plane, control plane, and PAN-OS. · Concepts of management interface, administration, roles, and initial configuration. · Zone model as a basis for policy application. · Difference between vendor-specific knowledge and transferable firewall fundamentals. Practice 1. Design, addressing, and initial connectivity — 2 hours · Construction of the base topology in GNS3. · Creation of Trust, DMZ, Untrust, and Management segments. · Configuration of IPv4 addresses, gateway, IPv4 forwarding, and return routes. · Validation using ip addr, ip route, ping, and traceroute. Evidence · Network diagram. · Addressing table. · Interface outputs, routes, and connectivity tests. Relationship with PAN-OS The student associates the physical/logical segmentation in GNS3 with the subsequent configuration of Layer 3 interfaces, security zones, and Virtual Routers in PAN-OS. Unit 2. Interfaces, zones, and routing — 7 hours Theoretical contents · Physical, logical, and sub-interfaces. · Security zones and trust domain separation. · Virtual Router and static routing. · Dynamic routing: purpose of OSPF and BGP in enterprise environments. · Relationship between interface, zone, route, policy, and session. Practice 2. Zone-based segmentation and deny-by-default — 2 hours · Defining chains equivalent to zones in nftables. · Allowing established,related traffic. · Denying new connections by default. · Logging relevant drops. · Temporary Trust–DMZ ICMP test and verifying blocking after rule removal. Practice 3. Internal segmentation with VLANs or subnets — 2 hours · Expansion with a Servers zone: 10.10.30.0/24. · Separation between users, servers, DMZ, and administration. · Selective permissions for HTTP/HTTPS, DNS, and administrative SSH. · Verification of blocked lateral movement attempts. Practice 4. Static routing and route troubleshooting — 1.5 hours · Incorporation of a remote network, for example 172.16.50.0/24. · Configuration of forward and return routes. · Diagnosis of a routed incident caused with ip route get, traceroute, tcpdump and logs. Lab 5. OSPF or BGP with FRRouting — 1.5 hours · Configuration of FRRouting as an ISP router or remote site. · Establishing OSPF or BGP adjacencies. · Prefix advertisement, routing table verification, and analysis in case of a link failure or route change. Evidence · Segmentation matrix. · nftables and FRR configuration. · Routing table before/after and evidence of testing. Relation to PAN-OS The exercises prepare for the configuration of Security Zones, static routes, Virtual Router, OSPF/BGP, and forwarding diagnosis in PAN-OS. Unit 3. Objects, security policies and NAT — 9 hours Theoretical content · Address objects, service objects and logical grouping. · Security rules, evaluation order, cleanup rule and least privilege. · Stateful policies and difference between allowing a new session and return traffic. · Source NAT: SNAT, PAT and masquerade. · Destination NAT: DNAT and controlled service publication. · Difference between routing, security policy and NAT. Lab 6. Objects, groups and communication matrix — 2 hours · Definition of logical sets: clients, web server, DNS and administration. · Creation of DNS, HTTP, HTTPS, SSH and ICMP services. · Design of the source–destination–service–action–justification matrix. · Replacement of an overly broad rule with least privilege policies. Lab 7. Outbound NAT for internal users — 2 hours · Configuration of Source NAT/PAT from Trust to Untrust. · Limited permission for DNS, HTTP and HTTPS. · Validation with curl and dig. · Capture on Untrust to verify the source address translation. · Verification of a blocked SSH attempt. Practice 8. Secure publishing of a server in DMZ — 2.5 hours · Deployment of Nginx in the DMZ. · Configuration of DNAT from an external IP/port to the web server. · Creation of the specific filtering rule for HTTP. · Verification of allowed HTTP and blocked SSH. · Analysis of original and translated IP/port using logs and captures. Practice 9. Integrated case study on policies and NAT — 2.5 hours · Design of a complete policy for users, servers, DMZ, and a simulated external network. · Implementation of controlled navigation, internal access to applications, and web publishing. · Introduction of three deliberate errors: policy, NAT, and return path. · Diagnosis and documented correction. Evidence · Communications matrix and justification of rules. · Configuration of filtering and NAT. · Traffic captures and logs of allowed/blocked accesses. · Diagnostic report of the introduced errors. Relation to PAN-OS Conceptual equivalence with Address Objects, Service Objects, Security Policy Rules, Source NAT, Dynamic IP and Port, and Destination NAT. Unit 4. Security profiles and user management — 5 hours Theoretical contents · Purpose of AntiVirus, Anti-Spyware, Vulnerability Protection, URL Filtering, and application control. · User-ID, identity, administrative roles, and separation of duties. · What an NGFW brings compared to an L3/L4 filtering firewall. · Dependence on licenses, subscriptions, intelligence databases, and signature updates. · Design of compensatory controls in a free laboratory: least privilege, segmentation, allowed services, logging, and basic hardening. Practice 10. Secure management and administrative access control — 2 hours · Configuration of administrative SSH access only from Management. · Creation of accounts or differentiated keys for the administration of Linux nodes. · Administrative access restriction from Trust, DMZ, and Untrust. · Validation of permitted and blocked access via logs. Practice 11. Profile simulation using policies and logs — 2 hours · Application of policies by protocol, port, source, and destination. · DNS restriction to an authorized resolver. · Blocking of unauthorized services and verification via logs. · Guided discussion: which part would correspond to an L3/L4 policy and which part would require a subscription or NGFW engine in Palo Alto. Analysis activity — 1 hour · Use case: define a corporate browsing and application access policy. · Identify which controls could be implemented for free and which would require specific licensed Palo Alto features. Evidence · Administrative access matrix. · Tests of authorized and denied SSH. · Brief report on available controls, simulated controls, and controls not feasible without a license. Unit 5. Logs, monitoring, and troubleshooting — 8 hours Theoretical contents · Types of logs on an NGFW platform: traffic, threats, system, configuration, and sessions. · Utility of correlation: time, source, destination, service, rule, and action. · Troubleshooting methodology: interface, IP, route, DNS, policy, NAT, session, and destination service. · Use of packet captures and verification at each point of the flow. Practice 12. Observability with syslog and correlation — 2 hours · Deployment of rsyslog in the Management network. · Sending filtering events from the Linux firewall. · Generation of test traffic: HTTP allowed, SSH blocked, correct DNAT, and traffic without a route. · Elaboration of an event correlation table. Practice 13. Packet capture and comprehensive troubleshooting — 3 hours · Resolution of incidents prepared by the instructor. · Diagnosis of interface/zone, route, return, rule, NAT, DNS, service, or VPN. · Use of tcpdump, Wireshark, ip route, curl, dig, logs, and final validation. Lab 14. Incident project: end-to-end flow analysis — 2 hours · Selection of a business flow, for example: Trust user to published web service or remote server. · Documentation of each control point: source, gateway, route, policy, NAT, destination, and return. · Identification of the log or capture that would demonstrate each phase of the flow. Closing activity — 1 hour · Comparison between the evidence obtained in Linux/GNS3 and the elements that would be consulted in PAN-OS: Traffic Logs, Monitor, sessions, policy testing, and packet capture. Evidence · Anonymized syslog extracts. · Correlation table. · Incident reports including symptom, hypothesis, evidence, root cause, correction, and final test. Unit 6. Maintenance, updates, and best practices — 6 hours Theoretical content · Configuration management, backup/restore, and secure rollback. · Software, signature, and dynamic content updates: process, validation, and risks. · Secure operation: least privilege, documentation, traceability, change windows, and rollback plan. · Laboratory limitations versus production environment: performance, availability, licenses, and compliance. Lab 15. Site-to-site VPN with WireGuard — 2.5 hours · Deployment of two Linux firewalls and two site LANs. · Establishing the WireGuard tunnel. · Configuring routes to remote LANs. · Applying policies that only allow defined business flows. · Capture in Untrust to verify that application traffic is not sent in cleartext. · Diagnosing an incorrect key, route, or rule. Lab 16. Automation and change control — 2.5 hours · Versioning nftables.conf and lab configurations with Git. · Creating a branch for an HTTP publishing change. · Syntax validation, application, functional testing, and rollback. · Developing a Bash or Python inventory script: interfaces, routes, rules, and relevant connections. Final project — 1 hour presentation · Submission and defense of a corporate network design simulated with Trust, Servers, DMZ, Management, and remote site. · Must incorporate segmentation, policies, SNAT, DNAT, routing, VPN, logging, and a change/rollback procedure. Evidence · VPN configuration and inter-site connectivity test. · Git repository or exported change history. · Inventory/validation script. · Technical report of the final project. Evaluation Evaluable item Weight Indicators Topology and addressing design 15% Coherent segments, complete routes, and clear diagram Security and segmentation policies 20% Least privilege, correct order, and deny-by-default NAT and service publication 15% Functional SNAT/DNAT limited to the necessary service Routing and VPN 15% Connectivity, return routes, and controlled inter-site access Observability and troubleshooting 20% Proper use of logs, captures, and diagnostic methodology Documentation, automation, and change control 15% Reproducible evidence, Git, rollback, and technical clarity Passing requirements · Obtain at least 50% of the total score. · Submit the final project functional and documented. · Demonstrate that unauthorized services are blocked and logged. · Justify the policy design and the change rollback procedure. 10. Integrated final project Design and deploy in GNS3 a simulated corporate infrastructure with: · Trust zone for users. · Servers zone for internal services. · DMZ zone for a published web server. · Management zone for restricted administration. · Simulated Untrust/ISP zone. · A remote branch connected via WireGuard VPN. · Source NAT for controlled outbound traffic. · Destination NAT to publish the DMZ web service. · Least privilege policies and centralized logs. · Static routing; OSPF or BGP as an optional extension. · Versioned configuration and rollback procedure.

Specifications
100% subsidizable, 130-hour duration
Virtual 110 hs, Virtual bonificable 130 hs
Variants (2)
  • Virtual 110 hs — 878.00 USD — In stock
  • Virtual bonificable 130 hs — 1093.00 USD — In stock

How AI sees this product

The more complete this product's details, the more confidently AI assistants can understand and recommend it.

83%