|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/palo-alto-firewall-pcnsa-v11-training/
课程评论:没有评论
**课程名称:Palo Alto 防火墙 PCNSA V11 培训** **课程概述:** 本课程旨在全面提升学员对 Palo Alto Networks 下一代防火墙的配置和管理能力。学员将学习并获得实践经验,掌握防火墙的安装、配置、管理、维护和监控,以有效保护网络安全。课程内容深入,涵盖了下一代防火墙的架构和管理要点,以及传统防火墙不具备的应用识别 (App-ID)、内容识别 (Content ID,包括 IPS、防病毒/反间谍软件、URL 过滤、文件阻止)、SSL 解密和用户识别 (User-ID) 等关键功能。 **课程大纲:** 1. 简介与初始配置 2. Palo Alto 架构 3. 防火墙初始设置配置 4. 防火墙配置管理 5. 接口配置 6. 防火墙管理员账户管理 7. 防火墙连接生产网络 8. 安全区域 9. 不同区域类型 10. 安全策略规则的创建与管理 11. NAT 策略规则的创建与管理 12. App-ID (应用识别) 13. 安全配置文件 14. 对象 15. URL 过滤 16. WildFire 17. User-ID (用户识别) 18. 加密与解密 19. 监控与报告 20. 备份与恢复 21. Panorama 简介 22. 动态更新 **产品版本:** Palo Alto 防火墙 V11.0.0 **学习目标:** 完成本课程后,您将能够: * 安装和配置新的 Palo Alto Networks 下一代防火墙。 * 管理 Palo Alto 下一代防火墙的配置。 * 配置防火墙以连接到您的生产网络。 * 管理用于保护网络的策略规则。 * 维护和增强虚拟或逻辑路由器的配置。 * 创建并应用安全区域到策略。 * 维护防火墙配置。 * 管理网络地址转换 (NAT) 规则。 * 配置和管理 Palo Alto Networks 下一代防火墙。 * 在实验室环境中配置、管理和监控防火墙。 * 配置和管理 Palo Alto 下一代防火墙的关键功能。 * 配置和管理安全及 NAT 策略以启用授权访问。 * 配置和管理威胁防护策略以阻止流量。 * 基于应用 (App-ID) 和用户身份 (User-ID) 配置策略。 * 在防火墙上配置 SSL 解密,以检查和控制解密后的会话。 * 使用交互式 Web 界面和防火墙报告监控网络流量。 **先修知识:** 学员应熟悉网络基本概念,包括路由、交换和 IP 地址。同时,学员应熟悉基本的安全概念。具备其他安全技术(IPS、代理和内容过滤)的经验者优先。推荐参加 Firewall Essentials: Configuration and Management (EDU-210) 课程。 **考试大纲:** * 管理与服务:22% * 管理对象:20% * 策略评估与管理:28% * 安全流量:30%
PCNSA Version 11:Successful completion of this course should enhance the student's understanding of how to configure and manage Palo Alto Networks next-generation firewalls. The student should learn and get hands-on experience installing, configuring, managing, maintaining and monitoring Palo Alto Networks next-generation firewalls to protect the networks.PCNSA Course Description:This training is the most important course as it covers all the fundamentals to understand the Next-Generation Firewall from the ground up. Even experienced firewall engineers take a lot out of this course as it includes, besides the architecture and management essentials, topics like Application Identification, Content ID (IPS, Anti-Virus/-Spyware, URL Filtering, File Blocking), SSL Decryption and User Identification which are all features usually not supported by legacy firewalls.Outline:01. Introduction and Initial Configuration02. Palo Alto Architecture03. Configuring Initial Firewall Settings04. Managing Firewall Configurations05. Interface Configuration06. Managing Firewall Administrator Accounts07. Connecting Firewall to Production Networks08. Security Zones09. Different Zone Types10. Creating and Managing Security Policy Rules11. Creating and Managing NAT Policy Rules12. App-ID (Application Identity)13. Security Profiles14. Objects15. URL Filtering16. WildFire17. User-ID (User Identity)18. Encryption and Decryption19. Monitoring and Reporting20. Backup and Restore21. Introduction to Panorama22. Dynamic UpdatesProduct Versions:Palo Alto Firewall Version 11.0.0Objectives:After completing this course, you should be able to:o Install and configure new Palo Alto Networks Next-Generation Firewalls.o Manage the Palo Alto Next-generation Firewall's configurations.o Configure the Firewall to connect to your production network.o Manage the Security Policy Rules used to protect your network.o Maintain and enhance the configuration of a virtual or logical router.o Create and apply security zones to policies.o Maintain firewall configurations.o Manage Network Address Translation (NAT) Rules.o Configure and manage Palo Alto Networks next-generation firewalls.o Configuring, managing, and monitoring a firewall in a lab environment.o Configure & manage essential features of Palo Alto next-generation firewalls.o Configure and manage Security and NAT policies to enable approved.o Configure and manage Threat Prevention strategies to block traffic.o Configure Policy based on application (App-ID) and user identity (User-ID).o Configure SSL Decryption on Firewall to inspect & control decrypted sessions.o Monitor network traffic using the interactive web interface and firewall reports.Prerequisites:Students must be familiar with networking concepts, including routing, switching, and IP addressing. Students also should be familiar with basic security concepts. Experience with other security technologies (IPS, proxy, and content filtering) is a plus. Recommended training includes the Firewall Essentials: Configuration and Management (EDU-210) course.Exam Blueprint:Management and Services 22%Managing Objects 20%Policy Evaluation and Management 28%Securing Traffic 30%