All certifications / NGFW Engineer / Lessons
NGFW Engineer NGFW-Engineer lessons
Study NGFW Engineer for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the NGFW Engineer study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: PAN-OS networking configuration
- Interface types: Layer 3, Layer 2, virtual wire, tap, loopback, tunnel, VLAN and aggregate Ethernet (LACP); subinterfaces and 802.1Q tags
- Security zones: zone types, one zone per interface, intrazone vs interzone default rules, User-ID enablement per zone
- Zone protection profiles (flood, reconnaissance, packet-based) and interface management profiles
- Routing: virtual routers vs logical routers (Advanced Routing Engine), static routes, OSPF, BGP, administrative distance defaults, ECMP
- Policy-based forwarding with path monitoring; service routes; DHCP server/relay and DNS proxy
- NAT on Layer 3 interfaces: source NAT (DIPP, dynamic IP, static), destination NAT, U-turn NAT, pre-NAT IP vs post-NAT zone in security rules
- High availability: active/passive vs active/active, HA1/HA2/HA3 and backup links, priority and preemption, link and path monitoring, floating IPs
- Site-to-site IPsec: IKE gateway, IKE and IPsec crypto profiles, tunnel interfaces, proxy IDs, tunnel monitoring
- Quantum-resistant IKEv2 VPNs (post-quantum preshared keys) and GRE tunnels
- GlobalProtect: portal, gateways (internal/external), authentication, connect methods (user-logon, pre-logon, on-demand), split tunneling, HIP objects and profiles, IPsec vs SSL tunnels
Domain 2: PAN-OS device setting configuration
- Administrator accounts: dynamic roles vs admin role profiles, API and CLI permissions
- Server profiles (LDAP, RADIUS, TACACS+, SAML, Kerberos), authentication profiles and sequences, MFA
- Authentication policy and Authentication Portal
- Virtual systems: vsys creation, interfaces/zones/routers per vsys, shared gateway, inter-vsys traffic via external zones
- Logging: log types, log forwarding profiles, syslog/SNMP/email/HTTP server profiles, Device > Log Settings, Strata Logging Service
- Software and content updates: PAN-OS upgrade paths and base images, HA upgrade order, dynamic update schedules and thresholds
- Certificate management: CAs, forward trust/untrust, SSL inbound inspection, SSL/TLS service profiles, certificate profiles, OCSP/CRL
- Decryption exclusions for pinned and sensitive apps
- User-ID sources (server monitoring, syslog listener, GlobalProtect, XML API), group mapping and Cloud Identity Engine
- Management plane: permitted IPs, service routes, candidate vs running config, commits, partial commits, config locks and named snapshots
- Web proxy (explicit and transparent) on supported PAN-OS 11.x platforms
Domain 3: Integration and automation
- Panorama: device groups and hierarchy, pre-rules and post-rules, templates, template stacks, template variables and overrides
- Panorama commit and push workflow; Panorama modes (Panorama, Management Only, Log Collector) and version requirements
- PAN-OS XML API (keygen, config, op, commit) and REST API; API-only admin role profiles
- Infrastructure as code: Terraform panos provider, Ansible paloaltonetworks.panos collection, pan-os-python SDK
- External dynamic lists (IP, domain, URL) and dynamic address groups with tags
- Auto-tagging from log forwarding profiles and HTTP server profiles for webhooks and ticketing
- VM-Series bootstrapping (init-cfg.txt, bootstrap.xml, content/license/software/plugins folders) and Zero Touch Provisioning
- Form factors: PA-Series, VM-Series, CN-Series, Cloud NGFW for AWS and Azure
- Strata Cloud Manager and cloud-delivered management