Home About For organisations The labs Gallery FAQ Contact
Palo Alto Networks Certified Next-Generation Firewall Engineer

Palo Alto Networks Firewall Administration
Specialist-level course

Building and operating a Palo Alto Networks next-generation firewall - zones and security policy, NAT, App-ID, User-ID, security profiles, URL filtering, WildFire and decryption, following the topics the vendor publishes for its Firewall Essentials: Configuration and Management (EDU-210) outline and the Next-Generation Firewall Engineer exam blueprint. Participants leave able to put a firewall into a production network, write its policy and read its logs.

Registration
Waiting list
Duration
28 academic hours
Format
In personHybrid
Level
Specialist
Certification
Palo Alto Networks Certified Next-Generation Firewall Engineer
Language
Hebrew, course materials in English
For organisations
5 intensive days - at the academy or hybrid

What you will be able to do

  • Bring a firewall up from initial settings to a production network with security zones and interfaces
  • Write and maintain security and NAT policy rules that match the design
  • Control application usage with App-ID and tie policy to users with User-ID
  • Block known and unknown threats with security profiles, URL filtering and WildFire
  • Decrypt traffic with certificates to inspect what passes inside it
  • Investigate an event through the logs, reports and the ACC, and manage configurations and administrator accounts

The syllabus

8 modules over 28 academic hours. Open a module for its topics.

  • The Palo Alto Networks portfolio and firewall architecture
  • Initial firewall settings - management access and content updates
  • Managing firewall configurations - candidate and running configuration, commits
  • Administrator accounts and roles

  • Security zones and interface types - Layer 2, Layer 3, virtual wire and tunnel
  • Routing - static routes, dynamic routing and the Advanced Routing Engine
  • Security policy rules - creating, ordering and managing them
  • NAT policy rules - source and destination NAT

  • Controlling application usage with App-ID
  • Writing policy by application
  • User-ID - mapping users to addresses, and policy by user and group
  • Cloud Identity Engine

  • Blocking known threats with security profiles
  • URL filtering for inappropriate web traffic
  • WildFire for unknown threats
  • Zone protection

  • Certificate management on the firewall
  • Decryption to block threats in encrypted traffic
  • Web proxy

  • Locating information in the logs
  • Reports and the ACC
  • Strata Logging Service

  • IPSec site-to-site VPN and GRE tunnels
  • GlobalProtect for remote users
  • High availability - active/passive and active/active
  • Virtual systems (VSYS)

  • Panorama templates and device groups
  • The API, Terraform and Ansible
  • Deployment options - PA-Series, VM-Series, CN-Series and Cloud NGFW
  • Exam preparation by blueprint domain
Palo Alto Networks Firewall Administration Opening soon +972 8-669-8400

Who it is for

Who takes this course, and what you need before the first session.

Security and network administrators who have been handed a Palo Alto Networks firewall

Firewall engineers adding PAN-OS to what they already run

SOC analysts and support staff who read its logs and open tickets on it

Prerequisites

Familiarity with routing, switching, IP addressing and basic security concepts is enough to start.

The exam and the certification

The certification is Palo Alto Networks Certified Next-Generation Firewall Engineer, at the vendor's Specialist level; the blueprint is PAN-OS networking configuration 40%, PAN-OS device setting configuration 40%, integration and automation 20%. It has no prerequisite; the vendor recommends the Palo Alto Networks Certified Network Security Professional and Network Security Analyst certifications and two years of hands-on work with its firewalls before it, and participants new to the platform can sit Network Security Professional, the Professional-level certification, first. PCNSA and PCNSE were retired in 2025; the vendor states there is no direct equivalence between them and the current role-based certifications.

Palo Alto Networks Certified Next-Generation Firewall Engineer

The certification

Palo Alto Networks Certified Next-Generation Firewall Engineer

How it is sat

In person at a Pearson VUE test centre, in English, with a 30-minute extension for candidates in non-English-speaking countries. 90 minutes of seat time; passing score 860 on a 300-1000 scale.

Validity

Two years from the pass date. Recertify by retaking the exam, or by passing a higher-level exam in the same track, which extends the lower ones.

Retakes

Retake waits: 15 days after a first failed attempt, 30 after the second, 90 after the third.

Where this course sits among the four levels of Palo Alto Networks' Network Security track. The lit rung is the one it prepares for.

  1. Foundational Cybersecurity Apprentice, Cybersecurity Practitioner
  2. Professional Network Security Professional
  3. Specialist Next-Generation Firewall Engineer, Network Security Analyst, SD-WAN Engineer, Security Service Edge Engineer This course prepares for Next-Generation Firewall Engineer
  4. Architect Network Security Architect

The labs

In the academy's virtual lab you work on a separate VM-Series firewall per seat, with a client network, a server segment and an internet edge behind it. You take the firewall from factory settings to production: zones and interfaces, security and NAT policy, App-ID and User-ID, security profiles, URL filtering and WildFire, decryption with your own certificates, then a site-to-site VPN and an HA pair. Panorama runs alongside for the central-management module, and the logs you read are the ones your own traffic wrote. A group from an organisation can practise on the same policy structure the team runs in production.

The SpotAcademy classroom in Shoham - rows of workstations, and the equipment rack behind them
The classroom in Shoham. The sessions run here, and the lab environment is reached from the workstations and from home.

Two ways to take the course

The waiting list for the next open cohort, or an intensive format for a team - which a team can have on its own dates, whatever the open cohorts are doing.

The next cohort

The next cohort is in planning - 28 academic hours at the academy in Shoham. A hybrid option is available, with part of the sessions remote. Join the waiting list and you hear the dates first; the list is also what decides which course opens next.

For your team

5 intensive days - at the academy in Shoham, or hybrid with part of the sessions remote. Small groups, and a syllabus adjusted to your equipment and environment.

Leave us your details

A few lines about what you are after - a course for yourself or training for a team - are enough. The message reaches the academy team directly.

Who is this for