Palo Alto Networks Firewall Administration
Specialist-level course
Building and operating a Palo Alto Networks next-generation firewall - zones and security policy, NAT, App-ID, User-ID, security profiles, URL filtering, WildFire and decryption, following the topics the vendor publishes for its Firewall Essentials: Configuration and Management (EDU-210) outline and the Next-Generation Firewall Engineer exam blueprint. Participants leave able to put a firewall into a production network, write its policy and read its logs.
- Registration
- Waiting list
- Duration
- 28 academic hours
- Format
- In personHybrid
- Level
- Specialist
- Certification
- Palo Alto Networks Certified Next-Generation Firewall Engineer
- Language
- Hebrew, course materials in English
- For organisations
- 5 intensive days - at the academy or hybrid
What you will be able to do
- Bring a firewall up from initial settings to a production network with security zones and interfaces
- Write and maintain security and NAT policy rules that match the design
- Control application usage with App-ID and tie policy to users with User-ID
- Block known and unknown threats with security profiles, URL filtering and WildFire
- Decrypt traffic with certificates to inspect what passes inside it
- Investigate an event through the logs, reports and the ACC, and manage configurations and administrator accounts
The syllabus
8 modules over 28 academic hours. Open a module for its topics.
- The Palo Alto Networks portfolio and firewall architecture
- Initial firewall settings - management access and content updates
- Managing firewall configurations - candidate and running configuration, commits
- Administrator accounts and roles
- Security zones and interface types - Layer 2, Layer 3, virtual wire and tunnel
- Routing - static routes, dynamic routing and the Advanced Routing Engine
- Security policy rules - creating, ordering and managing them
- NAT policy rules - source and destination NAT
- Controlling application usage with App-ID
- Writing policy by application
- User-ID - mapping users to addresses, and policy by user and group
- Cloud Identity Engine
- Blocking known threats with security profiles
- URL filtering for inappropriate web traffic
- WildFire for unknown threats
- Zone protection
- Certificate management on the firewall
- Decryption to block threats in encrypted traffic
- Web proxy
- Locating information in the logs
- Reports and the ACC
- Strata Logging Service
- IPSec site-to-site VPN and GRE tunnels
- GlobalProtect for remote users
- High availability - active/passive and active/active
- Virtual systems (VSYS)
- Panorama templates and device groups
- The API, Terraform and Ansible
- Deployment options - PA-Series, VM-Series, CN-Series and Cloud NGFW
- Exam preparation by blueprint domain
Who it is for
Who takes this course, and what you need before the first session.
Security and network administrators who have been handed a Palo Alto Networks firewall
Firewall engineers adding PAN-OS to what they already run
SOC analysts and support staff who read its logs and open tickets on it
Prerequisites
Familiarity with routing, switching, IP addressing and basic security concepts is enough to start.
The exam and the certification
The certification is Palo Alto Networks Certified Next-Generation Firewall Engineer, at the vendor's Specialist level; the blueprint is PAN-OS networking configuration 40%, PAN-OS device setting configuration 40%, integration and automation 20%. It has no prerequisite; the vendor recommends the Palo Alto Networks Certified Network Security Professional and Network Security Analyst certifications and two years of hands-on work with its firewalls before it, and participants new to the platform can sit Network Security Professional, the Professional-level certification, first. PCNSA and PCNSE were retired in 2025; the vendor states there is no direct equivalence between them and the current role-based certifications.
The certification
Palo Alto Networks Certified Next-Generation Firewall Engineer
How it is sat
In person at a Pearson VUE test centre, in English, with a 30-minute extension for candidates in non-English-speaking countries. 90 minutes of seat time; passing score 860 on a 300-1000 scale.
Validity
Two years from the pass date. Recertify by retaking the exam, or by passing a higher-level exam in the same track, which extends the lower ones.
Retakes
Retake waits: 15 days after a first failed attempt, 30 after the second, 90 after the third.
Where this course sits among the four levels of Palo Alto Networks' Network Security track. The lit rung is the one it prepares for.
- Foundational Cybersecurity Apprentice, Cybersecurity Practitioner
- Professional Network Security Professional
- Specialist Next-Generation Firewall Engineer, Network Security Analyst, SD-WAN Engineer, Security Service Edge Engineer This course prepares for Next-Generation Firewall Engineer
- Architect Network Security Architect
The labs
In the academy's virtual lab you work on a separate VM-Series firewall per seat, with a client network, a server segment and an internet edge behind it. You take the firewall from factory settings to production: zones and interfaces, security and NAT policy, App-ID and User-ID, security profiles, URL filtering and WildFire, decryption with your own certificates, then a site-to-site VPN and an HA pair. Panorama runs alongside for the central-management module, and the logs you read are the ones your own traffic wrote. A group from an organisation can practise on the same policy structure the team runs in production.
Two ways to take the course
The waiting list for the next open cohort, or an intensive format for a team - which a team can have on its own dates, whatever the open cohorts are doing.
The next cohort
The next cohort is in planning - 28 academic hours at the academy in Shoham. A hybrid option is available, with part of the sessions remote. Join the waiting list and you hear the dates first; the list is also what decides which course opens next.
For your team
5 intensive days - at the academy in Shoham, or hybrid with part of the sessions remote. Small groups, and a syllabus adjusted to your equipment and environment.
Related courses
FortiGate firewall administration (NSE 4)
Preparation for the NSE 4 certification - configuring, operating and troubleshooting a FortiGate firewall on real appliances in the lab. Participants leave able to run a FortiGate firewall on their own: policies, NAT, user authentication, content inspection, routing, IPsec VPN and a high-availability cluster.
Explore Associate Opening soonSOC Analyst, Tier 1-2
A course that trains a SOC analyst to work the SIEM on Splunk - reading alerts, triaging and enriching them, and handling an incident from the first sign to closure. Graduates can tell a real incident from a false positive, investigate it and pass it on to Tier 2, and sit prepared for the Splunk, CompTIA and Microsoft SOC certification exams.
Explore Professional Opening soonCloud Security on Azure and AWS
Cloud security on Azure and AWS - identity and access, networking, encryption, security posture and detection on both clouds. You leave able to build a secure cloud environment, audit an existing one against the vendor's recommendations and fix what the audit finds.
Explore