PAN-OS Networking Configuration
40%of exam
InterfacesZonesHigh AvailabilityRoutingGlobalProtectTunnels
PAN-OS Device Settings
40%of exam
AuthenticationVirtual SystemsLoggingUpdatesCertificatesUser-ID
Integration and Automation
20%of exam
DeploymentAPIsThird-Party ServicesPanoramaRule SetsACC
Quick Facts
- Credential
- NGFW Engineer
- Level
- Specialist
- Platform
- Network Security
- Seat time
- 90 min
- Networking
- 40%
- Device settings
- 40%
- Automation
- 20%
- Pass score
- 860/300-1000
- ESL extension
- 30 min
Blueprint Weights
Network 40, device 40, automate 20.
NetworkingDevice settingsIntegrationAutomation
Layer 2 vs Layer 3
Layer 2
- Switching mode
- VLAN-oriented
- No routed interface
Layer 3
- Routed mode
- IP addressing
- Virtual router
Switching vs routing
Interface Picker
- Need routed connectivity→Layer 3(IP routing)
- Need switching→Layer 2(VLAN design)
- Need transparent insertion→Virtual wire(Inline inspection)
- Need tunnel endpoint→Tunnel interface(Overlay traffic)
- Need link bundle→Aggregate Ethernet(AE)
- Need administration→Management interface(Admin path)
Interfaces and Zones
- Layer 2
- Switching interface mode
- Layer 3
- Routed interface mode
- Virtual wire
- Transparent inline deployment
- Tunnel interface
- Tunnel traffic endpoint
- Aggregate Ethernet
- Bundled Ethernet linksAE
- Management interface
- Administrative access path
- Security zone
- Policy trust boundary
GlobalProtect Split
Portal configures; gateway connects.
PortalConfigurationGatewayTunnel
Virtual Wire vs Tunnel
Virtual wire
- Transparent insertion
- Inline traffic
- No routed design
Tunnel
- Overlay endpoint
- Encapsulated traffic
- Tunnel interface
Inline vs overlay
Resiliency Picker
- One active peer→Active/passive(Standby peer)
- Both peers forward→Active/active(Dual forwarding)
- Watch interface health→Link monitoring(Link state)
- Watch path reachability→Path monitoring(Probe target)
- Learn routes→Dynamic routing(Protocol routes)
- Check route health→Route monitoring(Reachability)
HA and Routing
- Active/passive
- One traffic-forwarding peer
- Active/active
- Both peers forward
- Link monitoring
- Interface-health failover
- Path monitoring
- Reachability-health failover
- Dynamic routing
- Protocol-learned routes
- Redistribution
- Share route information
- Route monitoring
- Route reachability check
- Advanced Routing Engine
- PAN-OS routing framework
Active Passive vs Active Active
Active/passive
- One active peer
- Standby peer
- Failover design
Active/active
- Both peers active
- Traffic forwarding
- Dual-peer design
One forwarder vs two
GlobalProtect and Tunnels
- GlobalProtect portal
- Client configuration source
- GlobalProtect gateway
- Client tunnel endpoint
- GlobalProtect authentication
- Remote-user verification
- Split tunneling
- Selective tunnel traffic
- IPSec
- Encrypted IP tunnel
- GRE
- Generic routing overlay
- Quantum-resistant cryptography
- Post-quantum tunnel protection
Identity and Virtual Systems
- Authentication role
- Administrator privilege set
- Authentication profile
- Authentication service settings
- Authentication sequence
- Ordered authentication methods
- VSYS
- Virtual firewall instance
- Virtual router
- Independent routing table
- Logical router
- Routing abstraction
- Inter-VSYS routing
- Traffic between virtual systems
Logging Certificates Updates
- Strata Logging Service
- Cloud logging service
- Log forwarding
- Send selected logs
- Log collector
- Central log storage
- Collector group
- Log collector grouping
- PAN-OS updates
- Software update management
- PKI
- Certificate trust framework
- TLS profile
- TLS security settings
- Certificate profile
- Certificate validation rules
User-ID and Web Proxy
- Cloud Identity Engine
- Cloud identity integration
- On-premises User-ID
- Local user mapping
- Group mapping
- Directory group retrieval
- Directory sync
- Directory data synchronization
- User-to-IP mapping
- User address association
- User context
- Identity policy context
- Web proxy
- PAN-OS web proxy
Management Split
Templates shape; device groups govern.
TemplatesSettingsDevice groupsPolicies
Template vs Device Group
Template
- Device settings
- Interface configuration
- Shared configuration
Device group
- Policy configuration
- Object scope
- Shared policy
Settings vs policy
Management Picker
- Centralize device settings→Panorama templates(Shared settings)
- Centralize policies→Device groups(Policy scope)
- Automate deployment→APIs(Programmatic control)
- Deploy virtual firewall→VM-Series(Virtual form)
- Deploy cloud firewall→Cloud NGFW(Cloud form)
- View applications→ACC dashboard(Operational view)
Deployment and APIs
- PA-Series
- Hardware firewall deployment
- VM-Series
- Virtual firewall deployment
- CN-Series
- Cloud-native firewall deployment
- Cloud NGFW
- Cloud firewall deployment
- AI Runtime Security
- AI workload protection
- APIs
- Deployment automation interface
- Third-party services
- External deployment integrations
Pre-Rule vs Post-Rule
Pre-rule
- Before local rules
- Centralized policy
- Earlier evaluation
Post-rule
- After local rules
- Centralized policy
- Later evaluation
Before vs after
Panorama and Reports
- Panorama
- On-premises centralized management
- Template
- Shared device settings
- Device group
- Shared policy scope
- Pre-rule
- Rule before local rules
- Post-rule
- Rule after local rules
- ACC dashboard
- Application Command Center view
- Custom report
- Tailored operational report
Common Traps
Interface Trap
Layer 2 ≠ Layer 3 ≠ Virtual wire ≠ tunnel
HA Trap
Link monitoring ≠ path monitoring ≠ Active/passive ≠ active/active
Management Trap
Templates ≠ device groups ≠ Pre-rules ≠ post-rules
Identity Trap
User-ID ≠ administrator role ≠ Group mapping ≠ user mapping
Logging Trap
Log forwarding ≠ collector ≠ Software update ≠ log update
Score Trap
860 ≠ raw percentage ≠ Scaled ≠ percentage score
Last Minute
- 1.Blueprint: 40 / 40 / 20
- 2.Match interface to topology
- 3.Zones define policy boundaries
- 4.Separate link and path monitoring
- 5.Know portal versus gateway
- 6.Map VSYS routing boundaries
- 7.Know logging-service components
- 8.Separate User-ID mapping types
- 9.Templates configure; groups govern policy
- 10.Place pre and post rules
- 11.Match deployment form factor
- 12.Remember 860 is scaled
Same family resources
Explore More Palo Alto Networks Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
