T Techclick ← All lessons
Palo Alto · PAN-OS · Prisma · Cortex · Operator + interview

One Palo Alto stack. Four jobs. One ticket.

The ticket says “user cannot reach the app.” Half the room opens Threat Prevention. A third talks Prisma Cloud. Someone mentions Cortex XSOAR. The session is still empty. This page is the improved F5-style operator map for Palo Alto: which engine owns the packet, which log closes the change, and which interview answer is actually strong.

24 min read · L2 primary · Quiz at end

After this page you can

Hero · four jobs on one ticket
User traffic entering a session factory, then splitting toward a cloud security path and a SOC desk
The box builds a session. Prisma steers and inspects in the cloud. Cortex hunts and automates after the fact. Mixing those three is how interviews and tickets both die.
Quick answer (say this out loud)

PAN-OS is a session factory. First packet builds the slot; later packets ride it. App-ID / User-ID / Content-ID are stamps on that slot, not three firewalls. A Security Allow is the door — profiles only scan after Allow. Prisma Access is the cloud-delivered firewall (Mobile Users, Remote Networks, Service Connections). Prisma SASE is Access plus Prisma SD-WAN. Prisma Cloud is CNAPP, not SASE. Cortex XDR detects, XSOAR automates, Xpanse maps the internet-facing surface. Green close is a log field, not a Commit.

1. Why four products is one ticket

F5 taught “a VIP is a listener.” Palo Alto’s equivalent is harder: the same vendor sells the box, the cloud firewall, the cloud-posture product, and the SOC suite. A weak answer treats them as one brand. A strong answer names the job.

The production failure is the same as the interview failure. Someone disables Vulnerability Protection because a scanner tripped one Threat ID. Someone rebuilds GlobalProtect because Prisma Mobile Users cannot reach a DC app — and the Service Connection was never onboarded. Someone patches “the firewall” for CVE-2026-0300 on Prisma Access, which is not impacted.

Journey · request, inspect, verdict, access
Four glass panels showing request, inspect, verdict, and access
Allow is not inspect. Inspect is not a verdict. A verdict is not proof until Monitor → Logs shows the session and the Threat / URL / WildFire row.
Hard words before the runbook

Session — 6-tuple slot (src/dst IP, port, protocol, plus zone/vsys). First packet is slow path. Later packets are fast path until App-ID shifts or decrypt starts.

Security profile — attached to an Allow rule. Official docs: profiles are not match criteria. Deny never “scans then blocks.”

Threat ID — signature number in Monitor → Logs → Threat and Threat Vault. Exception one ID. Do not disable the profile.

Service Connection (CAN) — Prisma Access IPSec to HQ/DC. Required for private apps and often for internal LDAP/DNS before Mobile User auth works.

Authentication Portal — formerly Captive Portal. Device → User Identification → Authentication Portal Settings. This is the CVE-2026-0300 surface on PA-Series / VM-Series.

2. Mental model · session + four planes

Hold four planes. Interviews fail when people dump product names instead of the plane that owns the symptom.

1. Content plane (inspect)

Anti-Spyware (C2 leaving), Vulnerability Protection (exploit entering), Antivirus + WildFire (files), URL Filtering (site access), DNS Security (malicious domains), Zone / DoS Protection (floods before a session exists).

2. Forwarding plane (steer)

Zones, VR, static / OSPF / BGP, PBF + Symmetric Return, multi-VR + next-vr, QoS on egress, HA A/P vs A/A, GlobalProtect Portal vs Gateway, IPSec + Proxy ID, certificates.

3. Cloud plane (Prisma)

Prisma Access = SSE / FWaaS (MU, RN, SC). Prisma SASE = Access + Prisma SD-WAN. Prisma Cloud = CNAPP (posture / runtime in cloud accounts). Different license, different console, different ticket.

4. SOC plane (Cortex)

XDR stitches endpoint + network + identity detections. XSOAR runs playbooks. Xpanse finds internet-facing assets you forgot. None of these replace an Allow + profile on the NGFW.

Say this out loud

The firewall builds a session and stamps App-ID, User-ID, and Content-ID. Prisma Access is that same inspection moved to a PoP. Cortex is what you do after the log exists. I do not tune XSOAR to fix a missing Security rule.

Flow 1 · four planes on one packet
User / app first packet Zone + VR ingress / FIB / PBF Session slot App · User · Content Allow then scan Prisma Access PoP MU · RN · Service Connection NGFW / Cloud NGFW PA · VM · CN · Cloud Cortex desk XDR · XSOAR · Xpanse Same packet. Three destinations. One owner per symptom.

Read left → right. The session is built once. Prisma and Cortex are not extra stamps — they are different planes.

3. Decision · which engine owns this packet

Flowchart first. Do not open every console.

Decision · Path A or Path B
A decision diamond splitting into two labeled paths
Path A = the packet never became a session (zone, route, HA, tunnel). Path B = a session exists and something stamped it (rule, NAT, profile, URL, threat).
Flow 2 · ticket to engine
show session all filter… Session exist? c2s / s2c bytes NO YES Path A · no slot Zone / VR / FIB / PBF IKE / Proxy ID / GP portal HA3 / floating IP Prisma SC / RN tunnel First: routing + tunnel, not IPS Path B · slot exists Rule / NAT / App-ID shift URL / Threat / WildFire session_end_reason XDR only after the log First: match tests + Threat log

Diamond = decision. If there is no session, profiles and Cortex playbooks will not save you.

4. How to choose NGFW vs Prisma vs Cortex

One comparison table per plane. Pick, then go to the matching runbook.

You needUseDo not use
Inspect allowed apps on a DC / campus / cloud VPC you ownPA-Series, VM-Series, CN-Series, or Cloud NGFWPrisma Cloud (that is posture, not the packet path)
Users and branches to a Palo Alto PoP, no box at every sitePrisma Access (MU + RN + SC). Prisma SASE if you also need Prisma SD-WANStanding up random VM-Series in every branch “because Prisma”
Branch last-mile SLA, DIA, app-aware pathPrisma SD-WAN (ION) feeding AccessPBF on a single PA as if it were SASE
CSPM / CWPP / cloud misconfig and runtime in AWS/Azure/GCP/K8sPrisma CloudA Security profile on the NGFW
Endpoint + network detection, isolate a hostCortex XDRDisabling Threat Prevention to “let SOC see it”
Ticket enrichment, block-list push, playbookCortex XSOARManual SSH on every firewall as the process
Forgotten public RDP / Auth Portal / shadow assetCortex XpanseAssuming Panorama inventory is the internet
Form factorWhere it livesOperator note
PA-SeriesHardware NGFWFull PAN-OS. HA, GP, IPSec, Auth Portal. CVE-2026-0300 in scope if portal is enabled.
VM-SeriesYour hypervisor / IaaSSame PAN-OS jobs. Same portal CVE surface. License + dataplane cores matter more than “it’s virtual.”
CN-SeriesKubernetesMP + DP pods. Traffic not in the CNI path never hits policy.
Cloud NGFWAWS / Azure managedNot your PAN-OS box. Official CVE-2026-0300 status: not impacted.
Unsafe shortcut

Do not say “we have Palo Alto, so Prisma and Cortex are included.” Access, Cloud, XDR, XSOAR, and Xpanse are separate products. Interviewers fail you for collapsing the catalog.

5. Runbook · Side A threat/content, Side B network/access

Side A is what you attach. Side B is how the packet is steered. Side C is proof — next section.

Side A — threat / content (attach to Allow)

Source: official Security Profiles help — profiles scan after the Security rule allows the application.

  1. Build the three Threat Prevention engines

    Path: Objects → Security Profiles. Anti-Spyware = C2 / phone-home leaving (DNS sinkhole lives here). Vulnerability Protection = exploits entering (CVE, buffer overflow). Antivirus uses WildFire verdicts on decoders (HTTP/FTP/SMB block by default; SMTP/IMAP/POP3 alert). Predefined default vs strict (strict blocks critical/high/medium).

  2. Forward unknowns with WildFire Analysis

    Path: Objects → Security Profiles → WildFire Analysis. Verdicts: benign / grayware / malicious / phishing. Attach on the same Allow. A file that never forwards will never get a new signature.

  3. URL Filtering + DNS Security

    URL site-access actions are allow, alert, block, continue, override. Credential phishing needs decrypt. DNS Security is the cloud DNS engine — wire it through Anti-Spyware DNS Policies / DNS Security, not a random Security deny on udp/53 that only names the resolver.

  4. Zone Protection vs DoS Protection

    Zone Protection attaches to the zone. Official: pps thresholds count packets that do not match an existing session. DoS Protection profile (flood + resource protection) attaches to a DoS policy for SYN/UDP/ICMP and concurrent-session caps. Zone ≠ DoS policy.

  5. Exception one Threat ID

    Path: profile → Exceptions → Show all signatures → override one ID (optionally one unicast Exempt IP). Action Allow on a signature does not write a Threat log — use Alert while you investigate. Never remove the profile from the rule.

https://fw.lab.example/php/login.php · Objects › Security Profiles › Vulnerability Protection
Training mock · not live

Objects → Security Profiles → Vulnerability Protection → VP-L2-Strict → Exceptions

Exceptions · one Threat ID

40001
alert
203.0.113.40 /32
single-packet
CancelOK · then Commit

Source: Set Up Antivirus, Anti-Spyware, and Vulnerability Protection — Exceptions tab, Show all signatures. One ID, one scanner IP. Profile stays on the Allow.

Side B — network / access (steer the same session)

JobPath / objectChoose when
StaticNetwork → Virtual Routers → Static RoutesFew prefixes, VPN spokes, default to ISP.
OSPFVR → OSPF area / interfaceCampus / DC IGP. Keep it inside one VR unless you intend redistribution.
BGPVR → BGPISP dual-home, Azure/AWS, Prisma SC. Proof is show routing protocol bgp loc-rib, not “peer is Established.”
PBFPolicies → Policy Based ForwardingOverride the FIB (dual-ISP, send SaaS out ISP2). L3 ingress only. Enforce Symmetric Return + Next Hop Address List (up to 8) when return would otherwise take another path. Traffic flags 0x00020000 / 0x00010000 / 0x00000800.
Multi-VRTwo VRs + next-vrOverlapping tenants or isolated ISP tables. Inter-VR is a route, not magic; Security still needs a zone pair.
QoSQoS profile on the egress interfaceProtect voice / GP control. Classification without an egress profile does nothing.
HA A/PDevice → High AvailabilityDefault. Official: simpler to troubleshoot than A/A. Same Group ID → virtual MAC + GARP on failover.
HA A/ASession Owner + Session Setup + HA3 + floating IPOnly if both boxes must forward. Official recommendation to behave like A/P: Session Owner and Session Setup = Primary Device. Lowest floating-IP priority value owns the address.
GlobalProtectNetwork → GlobalProtect → Portals / GatewaysPortal = client config. Gateway = tunnel + HIP. Internal gateway = User-ID / HIP without internet VPN. HIP Profiles = Boolean of HIP Objects in Security policy.
IPSec S2SIKE Gateway + IPSec Tunnel + tunnel interface + routePAN-OS is route-based. Against policy-based peers you must set Proxy IDs (default 0.0.0.0/0 both ways will fail Phase 2).
Azure ↔ PAIKEv2 + route-based Azure VPNAzure dynamic routing requires IKEv2. Traffic selectors = Proxy IDs. Phase 1 up / Phase 2 empty is almost always selector mismatch, not “IKE crypto.”
Certificates / PKIDevice → Certificate ManagementForward Trust / Forward Untrust for decrypt. GP portal and Auth Portal need a cert the client trusts. A self-signed portal cert is a ticket generator, not a lab flex.
Panorama, upgrades, BPA

Panorama — Device Groups push policy; Templates / Template Stacks push network + device. Local override on the firewall is why “I pushed it” is not proof — check the device’s running rule hit, not only Panorama.

PAN-OS upgrades — content (Apps & Threats, Antivirus, WildFire) is not PAN-OS. On A/P using a data port for updates, schedule both and Sync To Peer so the passive actually gets content. Suspend the active, upgrade passive, fail over, then the peer.

BPA — Best Practice Assessment against the running config (profiles on every Allow, decrypt coverage, admin auth, logging). It is a gap list, not a Commit button.

6. Runtime · 7-step + evidence desk

After Commit, the packet either became a session or it did not. This is the ladder. Do not skip steps.

Pipeline · branch to box to cloud to desk
Packets flowing from a branch through a firewall and cloud node to a SOC desk
Ops order is the same as the picture: box session first, Prisma tunnel second, Cortex third. Reverse that order and you waste the change window.
Flow 3 · 7-step traffic not passing
1 Session show session 2 Detail show session id 3 Policy test sec-match 4 NAT test nat-match 5 FIB fib-lookup 6 Drops counter delta 7 Proof logs / pcap If c2s has bytes and s2c is 0 — the firewall forwarded. Return path is the ticket. If action=allow and session_end_reason=threat — open Threat, not another Allow rule.

Memorise the order. Reboot and “clear session all” are not on this ladder.

Dummy tmsh-style ladder (PAN-OS CLI)
show session all filter source 203.0.113.10 destination 198.51.100.20
show session id 12345
test security-policy-match from trust to untrust source 203.0.113.10 destination 198.51.100.20 protocol 6 destination-port 443 application ssl
test nat-policy-match from trust to untrust source 203.0.113.10 destination 198.51.100.20 protocol 6 destination-port 443
test routing fib-lookup virtual-router default ip 198.51.100.20
show counter global filter severity drop delta yes
debug dataplane packet-diag set filter match source 203.0.113.10 destination 198.51.100.20
debug dataplane packet-diag set log feature flow basic
debug dataplane packet-diag set log on
# reproduce, then:
debug dataplane packet-diag set log off
debug dataplane packet-diag aggregate-logs
Evidence deskPage / fieldGreen close looks like
Session BrowserMonitor → Session Browser · show session idRule name, App-ID (not insufficient-data), ingress/egress zones, NAT, c2s and s2c bytes
Trafficaction, session_end_reason, flagsallow + tcp-fin / aged-out expected. threat / policy-deny / decrypt-cert-validation named
ThreatThreat ID, Severity, Action, Rule, ProfileThe ID you exceptioned now alerts; everything else still reset-both
URL / WildFirecategory / verdictCategory matches the profile action; WildFire verdict returned, not “pending” forever
GP / IPSecMonitor → GlobalProtect / System; show vpn ike-sa / ipsec-saPortal auth + gateway tunnel; Phase 2 SA exists for the Proxy ID pair
PrismaStrata Cloud Manager · MU / RN / SC statusTunnel Active on the expected PoP; username not unknown; SC up before private-app test
Logging / reportingLog Forwarding profile on the rule + Device → Log SettingsSame session-id in Traffic and Threat, and in the SIEM. Commit is not a log.
Operational failures that look like “policy”

incomplete — TCP handshake never finished (path / server). insufficient-data — handshake finished, payload too small for App-ID. flow_fwd_zonechange — packet arrived in a different zone than the session (A/A without HA3, or PBF without Symmetric Return). tcp-rst-from-server — the server reset; the firewall is a witness.

7. Prisma / Cortex / PA interview map

Scenario answers only. Trivia is banned. Each block is what you say, what production cares about, the weak trap, and the evidence to name.

Ops desk · proof is a green log, not a story
Operations desk with a monitor showing abstract health checks
Strong interview answers name a page and a field. Weak answers name a product.

Q1 · Prisma Access architecture

Mobile Users connect. Internet works. Payroll in the DC does not. Tunnel to the PoP is up. What did the design miss?

Direct answer
A Service Connection (Corporate Access Node) to the DC. MU and RN reach private apps through SC. SC is also how Prisma reaches internal LDAP/DNS if you did not move identity to Entra/Okta first.
Why production cares
PDF/lab failure: onboard MU before SC, GP auth against internal LDAP fails, or private apps never have a path. Order is infrastructure → SC → RN/MU.
Weak answer / trap
“Add another Remote Network” or “open Threat Prevention.” RN is the branch. SC is the DC.

Strong framing (say this)

Internet for MU is the MU-SPN. Private apps need an SC. I check SC status in SCM before I touch the GP portal.

Evidence to name

SCM: Service Connection tunnel Active; MU username resolved; traffic log on the SC device / Access logs for the DC prefix.

Q2 · Prisma SASE vs Prisma Cloud

A hiring manager says “we bought Prisma.” They want branch SD-WAN plus CSPM. What do you actually sell / design?

Direct answer
Prisma SASE = Prisma Access + Prisma SD-WAN. Prisma Cloud is the CNAPP. Two SKUs, two consoles, two success metrics.
Why production cares
Mixing them produces a branch that has no ION and a cloud account that has no CSPM — both called “Prisma is down.”
Weak answer / trap
Calling Prisma Cloud “the SASE portal.”

Strong framing (say this)

Access inspects user/branch traffic at a PoP. SD-WAN picks the underlay. Cloud scores the AWS account. I will not troubleshoot an S3 public bucket in SCM Access.

Q3 · Prisma SD-WAN interview

Voice is bad on the cheap DIA. Why is a Security Allow on the DC PA the wrong first fix?

Direct answer
Path quality is an SD-WAN policy (latency / jitter / loss on the virtual interface), not an NGFW Allow. Check show sdwan connection / session distribution against the SLA, then the Access path.
Weak answer / trap
Raising QoS on the DC PA for a problem that never enters that PA.

Q4 · Cortex trio

A laptop beacons to a sinkhole IP. Who does what?

Direct answer
NGFW Anti-Spyware sinkhole + Traffic log names the host. XDR isolates the endpoint and shows the process. XSOAR opens the ticket and can push a block. Xpanse is irrelevant unless that host also published a service to the internet.
Weak answer / trap
“XSOAR blocked the C2” as if playbooks inspect packets inline.

Q5 · PA scenario · A/A vs A/P

They want Active/Active because “we paid for two boxes.” When do you refuse?

Direct answer
Default A/P. Official docs: A/P is significantly easier to troubleshoot. A/A needs session owner, session setup, HA3 forwarding, floating IPs / virtual MAC. If they only want failover, bind floating IP to Active-Primary and set owner + setup to Primary Device — that is A/A pretending to be A/P.
Weak answer / trap
Enabling A/A without HA3, then chasing flow_fwd_zonechange.

Q6 · PA scenario · Azure IPSec

IKE Phase 1 is up to Azure VPN Gateway. No Phase 2. What do you check before crypto?

Direct answer
Azure route-based = IKEv2. Proxy IDs are the traffic selectors. Empty Proxy ID on PAN-OS becomes 0.0.0.0/0 ↔ 0.0.0.0/0. If Azure advertised specific prefixes, Phase 2 does not install. Mirror the selectors, then install a route out the tunnel interface.

Q7 · PA scenario · traffic not passing

test security-policy-match hits interzone-default deny. First move?

Direct answer
Zone or service or App-ID mismatch — not “add any-any.” Re-test one field at a time. If the custom rule matches but s2c is 0, leave policy and fix return routing / Symmetric Return / server default gateway.

Q8 · CVE-2026-0300

CISA/KEV, unauthenticated root on Captive Portal. Are Cloud NGFW and Prisma Access in the blast radius?

Direct answer
No. Official advisory: Prisma Access, Cloud NGFW, and Panorama appliances are not impacted. PA-Series and VM-Series are, and only when Authentication Portal is enabled and an interface management profile with Response Pages sits on an L3 interface that untrusted traffic can reach.

Evidence to name

Device → User Identification → Authentication Portal Settings → Enable Authentication Portal. Network → Interfaces → Advanced → Management Profile → Response Pages. Temporary: Threat ID 510019 (content 9097-10022, PAN-OS 11.1+). Then patch to the listed hotfixes (example: 11.1.4-h33, 10.2.7-h34, 12.1.4-h5 / 12.1.7).

8. Traps + proof checklist

TrapWhat you seeSafer path
Disable the profileScanner works; every other exploit is allowedException one Threat ID (+ Exempt IP). Keep strict on the Allow.
Profile action AllowNo Threat log, “it disappeared”Alert while you investigate. Allow is official “exclude from enforcement.”
DNS block instead of sinkholeTraffic log names the resolverAnti-Spyware sinkhole so the client connects to the sinkhole IP.
PBF without Symmetric Returnc2s works, s2c dies, zonechange countersEnforce Symmetric Return + next-hop list. Confirm flag 0x00000800.
A/A without HA3Random drops, session on the other memberHA3 for packet forwarding, or collapse to A/P.
GP portal vs gateway mixupClient has config, no tunnel / no HIPPortal hands config. Gateway owns the tunnel and HIP report.
Empty Proxy ID to Azure / policy-based peerPhase 1 up, no useful Phase 2Set matching Proxy IDs; route into the tunnel interface.
Prisma MU before Service ConnectionUnknown user, or internet-onlySC first if LDAP/DNS/private apps live on-prem.
Auth Portal on an untrusted L3 + Response PagesCVE-2026-0300 exposed (ATTACKED)Restrict to trusted IPs; disable Response Pages on internet interfaces; patch; optional Threat ID 510019.
Commit as proofConfig matches, users still downSession Browser + Traffic session_end_reason + Threat ID / URL category / vpn ipsec-sa.
https://fw.lab.example · Device › User Identification › Authentication Portal Settings
Training mock · not live

Device → User Identification → Authentication Portal Settings

Enable Authentication Portal

checked · redirect mode
captive.lab.example
Response Pages = enabled ← exposure
203.0.113.0/24 only (trusted)
Disable portal if unusedRestrict + Commit

Source: CVE-2026-0300 advisory. Exposure = portal enabled and Response Pages on an L3 that untrusted packets can hit. Prisma Access / Cloud NGFW / Panorama: not impacted.

Pilot checklist before you close the ticket

Deep dives on the same track:

Knowledge check

Six judgment items. Pick the first fix, not the product brochure.

Q1

After last night’s Applications and Threats update, the Qualys scanner is reset. The Security rule is still Allow. What is the first safe fix?

Correct: b. Official path is profile → Exceptions → one Threat ID. Allow on a signature writes no Threat log. Disabling the profile is a hole. Re-read Side A.
Q2

No session appears for a new flow. What is the first ladder step you do not skip?

Correct: c. Path A starts with “is there a slot?” and a policy-match from the real zone. Re-read the 7-step.
Q3

Prisma Access Mobile Users reach the internet. They cannot reach a DC file server. GP tunnel to the PoP is up. What is missing?

Correct: a. Private apps and often internal LDAP ride the Service Connection. Prisma Cloud is CNAPP. Re-read interview Q1.
Q4

Leadership wants Active/Active “because both boxes should work.” The design is a simple L3 edge with one ISP. What do you recommend?

Correct: b. Official HA modes page: A/P is significantly easier to troubleshoot. A/A without HA3 creates zonechange drops. Re-read Side B HA.
Q5

CVE-2026-0300 is being exploited against User-ID Authentication Portal. Which statement is true?

Correct: b. Directly from the 2026-05-05 advisory. Threat ID 510019 is a temporary shield, not the product scope. Re-read traps + Q8.
Q6

Xpanse found an RDP listener. XDR has no alert. XSOAR is idle. What is the right first sentence in the interview?

Correct: a. Three Cortex products, three jobs. Re-read the choose table and interview Q4.

Sources

Related: PAN-OS session factory · F5 session factory (style sibling) · PA interview pack · Scenario questions