Palo Alto Networks Extended Firewall Management (PAN-EDU 205)
During the 3-day PAN-EDU-205 class, students will learn advanced configuration topics that are used on the PA-2000, PA-4000 and PA-5000 devices including VSYS and OSPF. Students will also learn advanced troubleshooting topics and reporting structures on Palo Alto Networks firewall products. Students will configure into high end deployment scenarios by deploying networking, security, threat prevention, reporting and logging features of PAN-OS in an advanced network design. Using a combination of instructor lecture and hands-on labs, this class will give students an in-depth understanding of how App-ID, User-ID and Content-ID can enable policy based visibility and control over applications, users and content.
Prerequisites:
Students must have a basic familiarity with networking concepts including routing, switching, and IP addressing. Students should also be familiar with basic port-based security concepts. Experience with other security technologies (IPS, proxy, and content filtering) is a plus. Completion of PAN-EDU-201 or equivalent experience is required.
Requirements:
Students are required to bring a laptop to each class. To access the lab portion of the class, a laptop with a wireless card that supports (802.11 A/B/G-‘N’ access also available) and an RDP client will be required.
Agenda:
| Day 1 | Subjects Covered |
| Introduction & Overview | |
| Administration | Service Route Configuration, Virtual Systems, and Log Forwarding |
| Interface Configuration | VLAN’s and QoS |
| Layer 3 Concepts: NAT, OSPF, and DNS Proxy | Working with NAT, OSPF, and DNS proxies |
| Application-ID | Custom Application Signatures, Application Filters and Groups |
| Content-ID | Custom Threat ID, Data Filtering, DLP, Botnet, and DoS |
| Days 2 & 3 |
Subjects Covered |
| User-ID | LDAP and Custom API |
| High Availability | Active/Active |
| GlobalProtect |
GlobalProtect concepts and configuration |
| Panorama | Panorama shared Policy, Device Groups, Access Control, and Reporting |

