Palo Alto Networks firewalls: zones, security policy, App-ID, profiles and safe commits
How PAN-OS next-generation firewalls use zones, top-down first-match security policy rules and the intrazone and interzone default rules; how App-ID, application-default, User-ID and security profiles change what a rule means; and how the candidate configuration, preview, validate, commit, snapshots and revert keep changes safe, with Panorama for many firewalls.
- Level
- Intermediate
- Length
- About 55 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- Palo Alto Networks
Skills you'll practise
- Predict whether a flow is allowed from zones, rule order and the default rules
- Write rules with App-ID and application-default rather than open ports, and attach security profiles to allow rules
- Explain what User-ID adds to policy and when it can't map users
- Use preview, validate and commit, and recover with revert or a saved snapshot
- Identify shadowed rules and other errors in a rulebase or change request
- Describe how Panorama device groups and templates divide policy from network settings
Course outline
- 1.Palo Alto Networks firewalls: policy and safe commitsVideo · 2 min
- 2.Zones and security policy rulesLesson · 18 min
- 3.App-ID, application-default, User-ID and security profilesLesson · 18 min
- 4.Candidate configuration, commit, snapshots, revert and PanoramaLesson · 19 min
- 5.Palo Alto Networks firewalls: zones, security policy, App-ID, profiles and safe commits: knowledge checkKnowledge check · 17 questions
- 6.Final exam8 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- PAN-OS Administrator's Guide: Security Policy (rule evaluation and default rules)
- PAN-OS Administrator's Guide: Segment Your Network Using Interfaces and Zones
- PAN-OS Administrator's Guide: App-ID Overview
- PAN-OS Administration: Safely Enable Applications on Default Ports (application-default)
- PAN-OS Administration: Manage New App-IDs Introduced in Content Releases
- PAN-OS Administrator's Guide: User-ID Overview
- PAN-OS Administrator's Guide: Security Profiles
- PAN-OS Administrator's Guide: Manage Configuration Backups
- PAN-OS Administrator's Guide: Save and Export Firewall Configurations
- PAN-OS Administrator's Guide: Revert Firewall Configuration Changes
- PAN-OS Administrator's Guide: Commit, Validate, and Preview Firewall Configuration Changes
- Panorama Administrator's Guide: Panorama Overview
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.