Palo Alto Networks firewalls: troubleshooting with traffic logs, policy tests, sessions, packet captures and VPN events
How to answer 'is the firewall blocking it?' on PAN-OS using the vendor's own tools: read traffic log actions and session end reasons, understand incomplete and insufficient-data applications, write security rules correctly around NAT (pre-NAT addresses, post-NAT zone), test which security and NAT rules match without sending traffic, read session details, take filtered packet captures at each stage, and read IKE system log events to tell a key mismatch from a proxy ID problem.
- Level
- Advanced
- Length
- About 55 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- Palo Alto Networks
Skills you'll practise
- Interpret traffic log actions (allow, deny, drop) and session end reasons, including the priority rule when there are several causes
- Explain why an application shows as incomplete or insufficient-data and what to do about it
- Build a security rule for NATed traffic with the pre-NAT addresses and the post-NAT destination zone
- Use Security Policy Match and NAT Policy Match tests and show session output to confirm which rules apply
- Take a filtered custom packet capture across receive, firewall, transmit and drop stages, including with NAT
- Identify whether an IPsec failure is in phase 1 or phase 2 from system log event IDs
Course outline
- 1.PAN-OS troubleshooting with evidenceVideo · 2 min
- 2.Reading traffic logs like evidenceLesson · 17 min
- 3.Policy, NAT and session evidenceLesson · 19 min
- 4.Packet captures and VPN system logsLesson · 19 min
- 5.Palo Alto Networks firewalls: troubleshooting with traffic logs, policy tests, sessions, packet captures and VPN events: knowledge checkKnowledge check · 17 questions
- 6.Final exam12 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- PAN-OS Administrator's Guide: Log Types and Severity Levels (Traffic logs)
- PAN-OS Administrator's Guide: Traffic Log Fields (Session End Reason)
- PAN-OS Administrator's Guide: Manage Custom or Unknown Applications
- PAN-OS Administrator's Guide: Components of a Security Policy Rule
- PAN-OS Administrator's Guide: Take Packet Captures
- PAN-OS Administrator's Guide: Take a Custom Packet Capture
- PAN-OS Administrator's Guide: Disable Hardware Offload
- PAN-OS 11.1 Administrator's Guide (PDF): Test Policy Rules, session details in the PBF use case, Application Override Policy and System Log events (vpn)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.