Skip to content
Palo Alto Networks Certified Network Security Engineer  cover image

Palo Alto Networks Certified Network Security Engineer
Fortray Global Services LTD

Training on Real Equipment with Subject Matter Expert Trainer and Consultant

Summary

Price
£3,499.99 inc VAT
Or £291.67/mo. for 12 months...
Study method
Online + live classes
Course format
Video
Duration
3 months · Part-time
Certification
Certified Network Security Engineer (CNSE)
Professional certification What's this?

Add to basket or enquire

Buy with Apple Pay
Buy with Google Pay

Overview

Palo Alto Networks is a next-generation security company, leading a new era in cybersecurity by safely enabling applications and preventing cyber breaches for tens of thousands of organizations worldwide. Gartner has positioned it in the "Leader’s" quadrant of May 25, 2016, as "Magic Quadrant for Enterprise Network Firewalls" for the fifth consecutive year and is trusted by over 31,000 customers in 140 countries.

Fortray’s Palo Alto Networks Certified Network Security Engineer (PCNSE) course covers topics in PAN-OS 8.x, Panorama 8.x, GlobalProtect, and other aspects of the Palo Alto Networks network security platform that a firewall administrator.

Fortray’s Palo Alto PCNSE- Security Professional course will ensure that the learner gains extensive hands-on experience on the Real & Licensed hardware along with an industry-experienced trainer with only one vision in mind.

Successful completion of this hands-on, instructor-led course will enhance the student’s understanding of how to configure and manage Palo Alto Networks®
Next-Generation firewalls on Panorama. The student will learn and get hands-on experience configuring, managing, and monitoring a firewall in a live environment.

Certification

Certified Network Security Engineer (CNSE)

Awarded by Palo Alto Networks

Description

Detailed Course Outline

Module 1: Platforms and Architecture

  • Security platform overview
  • Next-generation firewall architecture
  • Zero Trust security model
  • Public cloud security
  • Firewall offerings

Module 2: Initial Configuration

  • Administrative controls
  • Initial access to the system
  • Configuration management
  • Licensing and software updates
  • Account administration
  • Viewing and filtering logs

Module 3: Interface Configuration

  • Security zones and interfaces
  • Tap interfaces
  • Virtual Wire interfaces
  • Layer 2 interfaces
  • Layer 3 interfaces
  • Virtual routers
  • VLAN interfaces
  • Loopback interfaces
  • Policy-based forwarding

Module 4: Security and NAT Policies

  • Security policy fundamental concepts
  • Security policy administration
  • Network Address Translation
  • Source NAT configuration
  • Destination NAT configuration

Module 5: App-IDâ„¢

  • Application Identification (App-ID) overview
  • Using App-ID in a Security policy
  • Identifying unknown application traffic
  • Updating App-ID

Module 6: Basic Content-IDâ„¢

  • Content-ID overview
  • Vulnerability Protection Security Profiles
  • Antivirus Security Profiles
  • Anti-Spyware Security Profiles
  • File Blocking Profiles
  • Attaching Security Profiles to Security policy rules
  • Telemetry and threat intelligence
  • Denial of service protection

Module 7: URL Filtering

  • URL Filtering Security Profiles
  • Attaching URL Filtering Profiles

Module 8: Decryption

  • Decryption concepts
  • Certificate management
  • SSL Forward Proxy decryption
  • SSL Inbound Inspection
  • Other decryption topics:
    • Unsupported applications
    • No decryption
    • Decryption port mirroring
    • Hardware security modules
    • Troubleshooting SSL session terminations

Module 9: WildFireâ„¢

  • WildFire concepts
  • Configuring and managing WildFire
  • WildFire reporting

Module 10: User-IDâ„¢

  • User-ID overview
  • User mapping methods overview
  • Configuring User-ID
  • PAN-OS® Integrated agent configuration
  • Windows-based agent configuration
  • Configuring group mapping
  • User-ID and Security policy

Module 11: GlobalProtectâ„¢

  • GlobalProtect overview
  • Preparing the firewall for GlobalProtect
  • Configuration: GlobalProtect Portal
  • Configuration: GlobalProtect Gateway
  • Configuration: GlobalProtect agents

Module 12: Site-to-Site VPNs

  • Site-to-site VPN
  • Configuring site-to-site tunnels
  • IPsec troubleshooting

Module 13: Monitoring and Reporting

  • Dashboard, ACC, and Monitor
  • Log forwarding
  • Syslog
  • Configuring SNMP

Module 14: Active/Passive High Availability

  • HA components and operation
  • Active/passive HA configuration
  • Monitoring HA state

Who is this course for?

Network Security Engineer

Network Analyst

Firewall Engineer

Requirements

Students must have a basic familiarity with networking concepts including routing, switching, and IP address. Students also should be familiar with basic security concepts. Experience with other security technologies (IPS, proxy, and content filtering) is a plus

Questions and answers

Currently there are no Q&As for this course. Be the first to ask a question.

Reviews

Currently there are no reviews for this course. Be the first to leave a review.

FAQs

Interest free credit agreements provided by Zopa Bank Limited trading as DivideBuy are not regulated by the Financial Conduct Authority and do not fall under the jurisdiction of the Financial Ombudsman Service. Zopa Bank Limited trading as DivideBuy is authorised by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and the Prudential Regulation Authority, and entered on the Financial Services Register (800542). Zopa Bank Limited (10627575) is incorporated in England & Wales and has its registered office at: 1st Floor, Cottons Centre, Tooley Street, London, SE1 2QG. VAT Number 281765280. DivideBuy's trading address is First Floor, Brunswick Court, Brunswick Street, Newcastle-under-Lyme, ST5 1HH. © Zopa Bank Limited 2026. All rights reserved.