Palo Alto NGFW

Next-generation firewall training taught by a former Palo Alto TAC engineer: policy, App-ID, VPN, NAT and real troubleshooting.

Enroll Now
Section
Network Security
Trained
3,000+

Course overview

Palo Alto NGFW is a intermediate-level course from Tungabadra Networks. It covers 7 modules, is delivered classroom, online (live), corporate (on-site), and includes 3 applied projects. It prepares for Palo Alto Networks PCNSA.

Palo Alto NGFW covers the platform from first principles: interfaces and zones, security policy, App-ID and Content-ID, NAT, VPN and the management plane. It is taught on physical Palo Alto equipment.

The course is led by an engineer who spent eight years in Palo Alto TAC, so the emphasis is on the failure modes support actually sees: policy that does not match, NAT that breaks return traffic, VPN phases that will not come up.

Troubleshooting sessions use the same tools TAC uses, including session browser, packet capture and traffic logs.

Who this course is for

  • Network engineers adding a security specialisation
  • Engineers supporting a Palo Alto estate
  • CCNA holders moving toward security roles
  • Anyone preparing for a Palo Alto associate-level exam

What you will be able to do

By the end of Palo Alto NGFW, you will be able to:

  • Configure interfaces, zones, virtual routers and security policy
  • Use App-ID and Content-ID to write policy on applications, not ports
  • Configure source and destination NAT and predict return-path behaviour
  • Build and troubleshoot IPsec site-to-site VPN through both phases
  • Read traffic logs and the session browser to isolate a policy fault
  • Take a packet capture on the firewall and interpret it

Skills covered

  • Security policy
  • App-ID
  • Content-ID
  • NAT
  • IPsec VPN
  • Zones and virtual routers
  • Traffic log analysis
  • Packet capture
  • Panorama concepts
  • Firewall troubleshooting

Curriculum

7 modules of instruction and lab work.

Firewall Fundamentals

6 topics
  • Hardware types
  • Interface types and zones
  • Interface management profiles
  • Life of a packet and session types
  • Upgrades and configuration backup
  • Basic traffic troubleshooting

SSL Decryption

4 topics
  • SSL/TLS and certificates
  • Forward proxy
  • Inbound inspection
  • Forward-proxy lab

URL Category & Filtering

4 topics
  • Pre-defined URL categories
  • Custom URL categories
  • URL filtering policies
  • URL filtering lab

IPSec VPN

4 topics
  • IPsec fundamentals
  • Phase 1 and Phase 2
  • Route-based vs policy-based
  • Site-to-site lab

GlobalProtect

4 topics
  • Agent, portal and gateway
  • Connection methods
  • Remote-site VPN
  • GlobalProtect lab

High Availability

4 topics
  • Active-Passive
  • Active-Active
  • High availability lab
  • Failover scenarios

Panorama

4 topics
  • Managed devices
  • Device groups and templates
  • Panorama lab
  • Logging, reporting and commit management

Projects you will complete

Policy build from a requirements sheet

Translate a written security requirement into a working, ordered policy set and prove each rule matches as intended.

VPN bring-up under fault

Establish a site-to-site tunnel against a misconfigured peer and diagnose each phase failure in turn.

TAC case simulation

Work a realistic support case end to end, from symptom to root cause to written resolution.

Prerequisites

  • Working knowledge of TCP/IP, routing and NAT
  • CCNA Advanced Training or equivalent experience
  • Comfortable reading a packet capture

Certification

Course completion certificate

Issued on completion. The certificate lists the modules completed and the skills applied. Tungabadra Networks is not an authorized training partner of this vendor and does not administer or issue the exam. Exams are booked and paid for directly with the vendor.

This course also covers the topic areas assessed by the following third-party exams:

  • Palo Alto Networks PCNSA

Tungabadra Networks is not an authorized training partner of these vendors and does not administer or issue their exams. Exams are registered and paid for directly with the vendor. See certification tracks.

Career opportunities

Roles this course is designed to prepare you for in the US job market:

Network Security Engineer

Owns firewall policy and secure connectivity.

Firewall Administrator

Day-to-day policy changes, reviews and audits.

Security Operations Engineer

Investigates alerts against firewall and threat logs.

Implementation Engineer

Deploys and migrates firewall estates for clients.

Job titles vary by employer. Tungabadra Networks does not guarantee employment and publishes no placement or salary statistics.

Frequently asked questions

Who teaches this course?

It is led by an engineer with eight years in Palo Alto TAC, which is why the troubleshooting content follows real support cases rather than textbook scenarios.

Is this hands-on or lecture based?

Hands-on. Labs run on physical Palo Alto equipment with 24/7 rack access, and the troubleshooting modules use live faults.

Do I need security experience?

No, but you do need solid TCP/IP, routing and NAT knowledge. CCNA Advanced Training covers that ground.

Questions about Palo Alto NGFW?

Tell us your background and we will confirm whether this course is the right level, or point you to a better starting point.