NGFW Zones, NAT & App-ID
Palo Alto firewalls are notoriously hard to lab at home. PAN-OS licensing and hardware requirements price most students out. This lab gives you a live PAN-OS firewall to configure zones, NAT and App-ID policy against real traffic.
The problem
An internal host tries to reach a public web server through a configured NAT rule, but the session never completes, and the firewall's logs don't make it obvious why.
What you'll practice
- Design and configure security zones on PAN-OS
- Configure source NAT and destination NAT rules
- Write App-ID-based security policies instead of port-based rules
- Enable SSL decryption and inspect the resulting traffic
- Read and interpret PAN-OS traffic and threat logs
The topology
A PAN-OS firewall sits between an internal host and an external router, with distinct trust/untrust zones, the minimum real topology needed to configure zones, NAT and App-ID policy the way PCNSE expects.
Topology diagram
Frequently asked
Do I need my own PAN-OS license or image?
No. The firewall image and a working license are already in place. You focus on configuration, not procurement.
Does this help with the PCNSE exam?
Zones, NAT and App-ID policy are core PCNSE topics. This lab gives you hands-on repetition on exactly that scope.
Ready to run this lab yourself?
No setup, no image sourcing. Book a session or ask for a live demo.