Corporate · onsite · online training worldwide
contact@DevOpsSchool.com· +91 99057 40781·
> Network Security · DevOpsSchool Trainer

Palo Alto Networks Trainer

Private corporate batches, live online cohorts and 1-on-1 mentoring in PAN-OS next-generation firewalls, App-ID and User-ID policy, decryption, GlobalProtect and Panorama — taught by a practitioner who runs it in production.

20 years across DevOps, SRE and Security · 10,000+ engineers trained · Trained teams at JPMorgan Chase, Verizon, Nokia and the World Bank

DeliveryOnline · Onsite · Hybrid
FormatsCorporate · 1-on-1 · Cohort
AgendaCustomisable
Batch size8–30 engineers
Engineers we've trained work at
JPMorgan ChaseBank of AmericaWells FargoVerizonNokiaWorld BankGE HealthcareVMwareOracleQualcommMercedes-BenzAirbusDatadogSplunkDeloitteInfosysWiproCapgemini
# who teaches it

Your Palo Alto Networks trainer

Rajesh Kumar

Principal DevOps Engineer & Architect

DevSecOpsSecurity engineeringPipeline hardening20 years in productionPrincipal / architect roles10,000+ engineers trainedM.Tech BITS Pilani25+ certifications

Rajesh teaches Palo Alto Networks around policy and evidence rather than menu navigation: the PAN-OS packet flow that explains why a rule did not match, how App-ID and User-ID change what a rule actually means, and how to migrate port-based rules to application-based ones without an outage. Sessions cover decryption decisions and their privacy and compliance exemptions, security profile tuning that reduces false positives instead of muting alerts, and Panorama device groups and template stacks for keeping a multi-site estate consistent — with every concept demonstrated against a lab firewall and its logs. The framing is defensive throughout: designing, operating and auditing controls, and reconstructing what happened from traffic, threat and URL logs.

Twenty years across DevOps, SRE and Security, in principal and architect roles at PayPay, SoftwareAG, ServiceNow, JDA Software, Intuit, Adobe and others. He has trained engineers at JPMorgan Chase, Verizon, Nokia, the World Bank, VMware, Oracle, Mercedes-Benz and Airbus — more than 10,000 people personally. He teaches what he runs, not what he reads.

One practitioner, not a bench

You are booked with a named engineer, and that is who turns up. Marketplaces and larger providers rotate whoever is free, so the person who sold you the agenda is rarely the person teaching it.

The same trainer is available for the next engagement, which matters when a team builds on what it learned last time.

18,000+certified learners
500+corporate batches delivered
50+countries served
100+certification programmes
# faculty

Who delivers Palo Alto Networks engagements

Your batch is assigned a named trainer before it starts, and that is who teaches it. See the full faculty.

How your Palo Alto Networks trainer is chosen

Engagements are matched on the tool, not the calendar. For Palo Alto Networks that means a trainer who has run it in production — PAN-OS next-generation firewalls, App-ID and User-ID policy, decryption, GlobalProtect and Panorama — rather than whoever is free that week. You are told who is teaching before you commit, and that person is on the discovery call that shapes the agenda.

Where a batch is large enough to need a second trainer, the pairing is declared up front. The lead trainer stays accountable for the syllabus and the assessment either way.

Rajesh Kumar

Principal DevOps Engineer & Architect

India20 yrsLead trainer

Twenty years across DevOps, SRE and Security in principal and architect roles at PayPay, SoftwareAG, ServiceNow, JDA Software, Intuit, Adobe, IBM/Emptoris, Ness, MindTree and Accenture. He has trained more than 10,000 engineers personally, at organisations including JPMorgan Chase, Verizon, Nokia, the World Bank, VMware, Oracle, Mercedes-Benz and Airbus. He teaches what he runs, not what he reads.

Nikhil Gupta

IndiaInstructorCoach

Pranab Kumar

IndiaInstructorCoach

Rohit Ghatol

IndiaInstructorCoach

Amit Agarwal

IndiaInstructorCoach

Anil Kumar

IndiaInstructorCoach

Balachandran Anbalagan

IndiaInstructorCoach

Durga Prasad

IndiaInstructorCoach

Gaurav Aggarwal

IndiaInstructorCoach

Harsh Mehta

IndiaInstructorCoach

Kapil Gupta

IndiaInstructorCoach

Kunal Jain

IndiaInstructorCoach

# how to engage

Four ways to work with this trainer

Private corporate batch

Teams of 8–30

Custom agenda, your timezone, onsite or online, NDA-friendly.

Request a quote

1-on-1 mentoring

Individual engineers

A private instructor and a curriculum built around your goal.

₹99,999

Live & Interactive cohort

Individuals who want peers

Scheduled batch, max 8 to 10 hours of live instruction.

₹34,999

Self-paced video

Self-starters

Full LMS access — 20+ courses and 50+ tools included.

₹833/mo
# private batches

Private Palo Alto Networks training for your team

A private batch starts with a discovery call. We look at the stack you actually run — the CI system, the cloud, the constraints — and map the agenda onto it, so examples use your topology rather than a generic one.

Delivery is onsite at your premises, live online, or hybrid, scheduled around your release calendar rather than ours. Batches run 8 to 30 engineers.

Every attendee leaves with recordings, slides, lab repositories and a completion certificate. You receive an attendance and assessment report. Invoicing supports PO and GST.

Talk to us about a private Palo Alto Networks batch

What you provide vs what we bring

  • You: the room or the call, and the engineers
  • Us: trainer, agenda, labs, assessment, certificates
  • Labs: we guide your team through provisioning their own free-tier cloud environment — the skill goes with them
# the technology

What is Palo Alto Networks?

Palo Alto Networks builds next-generation firewalls and the security platform around them. The core product is PAN-OS, the operating system that runs on the hardware appliances, on the VM-Series in public and private cloud, and on the CN-Series for container environments. What distinguishes it from a port-and-protocol firewall is that traffic is classified by application, user and content rather than by port number: App-ID identifies the application regardless of port or encryption, User-ID maps sessions to directory identities, and Content-ID inspects the payload for threats, exploits, malicious URLs and data patterns — all in a single pass over the packet.

A production deployment is more than one box. Security zones and interfaces define where traffic may travel; security policy rules written against applications and user groups decide what is allowed; security profiles attached to those rules decide what is inspected. Decryption policy determines which TLS sessions are opened for inspection and which are deliberately left alone for privacy or compliance reasons. GlobalProtect extends the same policy to remote users, and IPSec tunnels extend it between sites.

At scale, Panorama becomes the control plane: device groups push shared and per-site policy, template stacks push network and device configuration, and log collectors centralise the traffic, threat, URL and WildFire logs that make investigation possible. This course is defensive throughout — it is about designing, operating and auditing controls, reading logs to explain what happened, and tuning policy so that legitimate work is not blocked and malicious activity is.

Why this skill matters now

Firewall policy has become identity and application policy. Flat allow-any rules between internal zones are precisely how an initial foothold turns into a breach, and every serious framework — from segmentation requirements in payment standards to zero-trust guidance — now expects rules expressed in terms of who and what, not which port.

At the same time the estate has spread. The same policy has to hold across a data centre, several cloud VPCs, branch sites and a fully remote workforce, which is why Panorama-managed device groups and template stacks matter more than the CLI syntax of any one device. Getting that consistency wrong produces silent gaps that nobody notices until an incident review.

Demand is for engineers who can do the harder half: convert legacy port-based rules to App-ID safely without an outage, decide what to decrypt and what to exempt, tune threat profiles so they block real attacks instead of generating noise, and reconstruct an incident from traffic and threat logs. Certification tracks such as PCNSA and PCNSE exist because organisations need that competence demonstrated, not asserted.

Palo Alto Networks training
# outcomes

What your team can do afterwards

Explain the PAN-OS packet flow well enough to debug why a session matched the wrong rule or no rule at all
Design zones, interfaces and virtual routers for a segmented network, including Layer 3, Layer 2, virtual wire and tap deployments
Write security policy against applications and user groups rather than ports, and migrate legacy port-based rules safely
Configure and tune security profiles — antivirus, anti-spyware, vulnerability protection, URL filtering, file blocking, WildFire and DNS security
Build source and destination NAT that behaves predictably alongside security policy
Make and document decryption decisions, including forward proxy, inbound inspection and deliberate exemptions
Deliver secure remote access with GlobalProtect and site-to-site IPSec tunnels
Manage a multi-site estate from Panorama using device groups, templates and template stacks, with centralised log collection
Reconstruct an incident from traffic, threat, URL and WildFire logs and produce a defensible written finding
# curriculum

10 modules. Live demos in a real lab, not slides.

01Platform architecture and the PAN-OS packet flowLive & Interactive5 hrs · 2 assignments · 1 capstone

Where the products fit and how a packet is actually processed. The hardware appliances, VM-Series and CN-Series; the management plane versus the data plane; and the single-pass packet flow — ingress, session lookup, policy lookup, App-ID, Content-ID, egress — which is the mental model that explains almost every confusing rule-match behaviour later in the course.

Topics: Product family: hardware, VM-Series, CN-Series · Management plane and data plane separation · Single-pass architecture and the packet flow diagram · Session setup versus session fast path · Management access, admin roles and authentication · Configuration model: candidate, running and commit · Content and software update lifecycle

  • Assignments: (1) Walk a sample session through the packet flow and identify every decision point; (2) Configure role-based admin access with separate read-only and change roles
  • Capstone: Produce a packet-flow explainer your own team can use to triage rule-match problems
02Interfaces, zones and routingLive & Interactive5 hrs · 2 assignments · 1 capstone

The network foundation everything else sits on. Deployment modes and when each applies, security zones as the unit of policy, virtual routers and route redistribution, and the interface management profiles that decide what can be reached on each leg. Then high availability, because a firewall that is a single point of failure is a design flaw.

Topics: Layer 3, Layer 2, virtual wire and tap deployments · Security zones and intra-zone versus inter-zone traffic · Sub-interfaces, VLANs and aggregate links · Virtual routers, static routes and dynamic routing · Interface management profiles · HA active/passive and active/active · Link and path monitoring

  • Assignments: (1) Build a segmented lab with at least four zones and prove traffic only flows where intended; (2) Configure an HA pair and fail it over without dropping established sessions
  • Capstone: Design a zone and routing model for a real network with a written segmentation rationale
03Security policy and NATLive & Interactive5 hrs · 2 assignments · 1 capstone

Rules as the organisation's stated intent. Rule structure and evaluation order, the implicit and intrazone-default rules people forget about, address and service objects, tags and rule hygiene. Then NAT — source, destination, U-turn and the ordering relationship with security policy that causes the classic 'my rule looks right but nothing passes' problem.

Topics: Rule structure, order and first-match evaluation · Implicit rules and interzone/intrazone defaults · Address, service and tag objects · Source NAT: dynamic IP and port, static · Destination NAT and port forwarding · NAT and security policy ordering · Rule hygiene: shadowed, unused and overly permissive rules

  • Assignments: (1) Publish an internal service through destination NAT with a correctly scoped security rule; (2) Audit a supplied ruleset and produce a list of shadowed and redundant rules
  • Capstone: Rewrite a legacy port-based ruleset into a clean, ordered, documented policy
04App-ID, User-ID and Content-IDLive & Interactive5 hrs · 2 assignments · 1 capstone

The three classifications that make the firewall next-generation. How App-ID identifies applications regardless of port, what application dependencies and implicit-use mean in practice, and how to migrate to application-based rules using the traffic log and Policy Optimizer rather than guesswork. Then User-ID — the agents, mapping sources and group mapping that make identity-based rules possible.

Topics: How App-ID classifies traffic and handles dependencies · Application groups, filters and custom applications · App-ID content updates and handling classification shifts · Policy Optimizer and port-to-App-ID migration · User-ID mapping sources: agent, agentless, syslog, captive portal · Group mapping from LDAP and identity providers · Content-ID and where inspection occurs in the flow

  • Assignments: (1) Convert five port-based rules to App-ID rules using traffic-log evidence; (2) Wire User-ID group mapping and write a rule that applies to a directory group
  • Capstone: Deliver a migration plan that moves a production ruleset to App-ID with a staged, reversible rollout
05Threat prevention and security profilesLive & Interactive5 hrs · 2 assignments · 1 capstone

What actually gets inspected once a rule permits traffic. Each profile type, what it detects, and how to tune it so real detections are visible instead of buried. Profile groups for consistency, exception handling that is documented rather than ad hoc, and zone and DoS protection for volumetric and reconnaissance activity.

Topics: Antivirus and anti-spyware profiles · Vulnerability protection and signature severity · URL filtering categories, overrides and credential-submission control · File blocking and data filtering patterns · WildFire analysis and verdict handling · DNS security and sinkholing · Security profile groups and consistent application · Zone protection and DoS protection profiles · Tuning exceptions without disabling detection

  • Assignments: (1) Attach a tuned profile group to a rule and demonstrate a blocked test threat; (2) Take a noisy detection and reduce false positives without losing true coverage
  • Capstone: Produce a documented baseline profile group with a written exception register
06DecryptionLive & Interactive5 hrs · 2 assignments · 1 capstone

The most consequential and most sensitive control on the platform. What you can and cannot inspect without decryption, how forward proxy and inbound inspection differ, certificate handling and trust distribution, and — equally important — the exemptions you must make for privacy, regulated categories and pinned applications. Covered as a governance decision as much as a configuration one.

Topics: SSL forward proxy · SSL inbound inspection · Certificate management and trust distribution · Decryption policy and exclusion rules · Certificate pinning and applications that must be exempted · Privacy, legal and works-council considerations · Decryption logs and troubleshooting broken sessions · Performance impact and sizing

  • Assignments: (1) Configure forward proxy for one zone and prove inspection works on a test session; (2) Build a documented exemption list for regulated and pinned traffic
  • Capstone: Write a decryption policy document an internal governance or privacy reviewer would accept
07Remote access and site-to-site connectivityLive & Interactive5 hrs · 2 assignments · 1 capstone

Extending the same policy beyond the perimeter. GlobalProtect portal and gateway configuration, authentication including multi-factor, host information profiles for posture checks, and split-tunnel decisions. Then IPSec site-to-site tunnels, IKE profiles, and troubleshooting the phase-one and phase-two failures that account for most tunnel incidents.

Topics: GlobalProtect portal, gateway and agent configuration · Authentication profiles, certificates and multi-factor · HIP checks and posture-based policy · Split tunnel versus full tunnel decisions · IPSec site-to-site tunnels and IKE crypto profiles · Route-based tunnels and monitoring · Troubleshooting phase 1 and phase 2 negotiation failures

  • Assignments: (1) Stand up GlobalProtect with certificate-based authentication and a HIP check; (2) Build an IPSec tunnel to a second site and diagnose a deliberately mismatched proposal
  • Capstone: Design remote-access architecture for a distributed workforce with policy parity to the office
08Panorama and multi-site managementLive & Interactive5 hrs · 2 assignments · 1 capstone

Managing an estate instead of a device. Panorama deployment modes, device groups with shared and site-specific rules, pre-rules and post-rules and how they sandwich local policy, templates and template stacks for network and device settings, and log collectors for centralised, searchable logging. Then configuration management: commit scope, config audit, rollback and change control.

Topics: Panorama modes and deployment sizing · Device groups, hierarchy and shared objects · Pre-rules, post-rules and local rule interaction · Templates and template stacks · Log collectors and log forwarding · Commit scope, partial commits and push behaviour · Config audit, versioning and rollback · Onboarding a new site consistently

  • Assignments: (1) Build a device-group hierarchy where a shared rule and a site rule coexist correctly; (2) Push a template stack change to two firewalls and audit the resulting diff
  • Capstone: Deliver a Panorama design that lets a new site be onboarded to standard policy in a day
09Monitoring, investigation and incident responseLive & Interactive5 hrs · 2 assignments · 1 capstone

Turning logs into answers. Reading traffic, threat, URL, WildFire and system logs and knowing which one answers which question. The ACC for pattern-finding, custom reports, log forwarding to SIEM, and a structured method for reconstructing what happened during an incident and writing it up defensibly.

Topics: Traffic, threat, URL, WildFire and system logs · Session browser and live session inspection · The Application Command Center for pattern discovery · Custom reports and scheduled reporting · Log forwarding profiles and SIEM integration · Correlation objects and automated correlation · Reconstructing an incident timeline from logs · Writing a defensible incident finding

  • Assignments: (1) Given a set of logs, determine which rule allowed a session and why; (2) Produce an incident timeline from traffic and threat logs for a simulated event
  • Capstone: Deliver a written incident report with evidence, timeline, root cause and remediation actions
10Operations, automation and the wider platformLive & Interactive5 hrs · 2 assignments · 1 capstone

Keeping it healthy over time and knowing what sits alongside it. PAN-OS upgrade paths and content update discipline, backup and restore, certificate expiry, capacity monitoring. Then the XML API and automation with Terraform and Ansible so policy changes become reviewable code, and an honest map of the wider portfolio — Prisma Access, Prisma Cloud, Cortex XDR and XSOAR — and where each is and is not relevant.

Topics: PAN-OS upgrade paths and pre-upgrade checks · Content and threat update discipline · Configuration backup, restore and disaster recovery · Certificate lifecycle and expiry monitoring · Capacity, throughput and session-table monitoring · The XML and REST APIs · Automating policy with Terraform and Ansible · Where Prisma Access, Prisma Cloud, Cortex XDR and XSOAR fit · Preparing for PCNSA and PCNSE

  • Assignments: (1) Plan and rehearse a PAN-OS upgrade including rollback criteria; (2) Create an address object and a rule entirely through the API and review the diff
  • Capstone: Produce an operational runbook covering upgrades, backups, monitoring and change control

Need this mapped to your stack?

We rebuild the agenda around the tools you actually run.

Request a custom agenda
# hands-on

Labs and capstones your engineers actually build

LAB · SEGMENTATION

Zones, routing and a segmented network

Build a multi-zone lab with Layer 3 interfaces, virtual routers and an HA pair, then prove with logs that traffic only flows where policy permits.

zonesroutinghigh availability
LAB · POLICY

Port-based to App-ID migration

Take a legacy port-based ruleset, use traffic logs and Policy Optimizer to identify the real applications, and migrate to application-based rules without breaking a service.

app-idpolicy optimizermigration
LAB · IDENTITY

User-ID and identity-based rules

Configure User-ID mapping and LDAP group mapping, write rules that apply to directory groups, and prove attribution in the traffic log.

user-idldapidentity
LAB · THREAT

Profile tuning against a noisy detection

Attach a full security profile group, generate benign traffic that trips a signature, and tune the exception properly instead of disabling the profile.

threat preventionwildfiretuning
LAB · DECRYPTION

Forward proxy with documented exemptions

Enable SSL forward proxy for one zone, distribute trust, then build and justify an exemption list covering pinned applications and regulated categories.

decryptioncertificatesprivacy
CAPSTONE · INVESTIGATION

Reconstruct an incident from logs

Given traffic, threat, URL and WildFire logs from a simulated event, establish what was allowed, by which rule, and produce a written finding with remediation actions.

logsincident responsereporting
# ecosystem

The tools Palo Alto Networks sits next to

Panorama
GlobalProtect
WildFire
Prisma Access
Prisma Cloud
Cortex XDR
Cortex XSOAR
Splunk
Active Directory
LDAP
Terraform
Ansible

Who this is for

  • Network and firewall engineers moving from port-based to application-based policy
  • Security operations analysts who investigate alerts and need to read firewall logs properly
  • Infrastructure engineers deploying VM-Series firewalls in cloud environments
  • Security architects designing segmentation and zero-trust network controls
  • Engineers preparing for the PCNSA or PCNSE certifications
  • Compliance and audit teams who must evidence network controls and change management

Pre-requisites

  • Solid TCP/IP fundamentals — addressing, subnetting, routing, NAT and TLS basics
  • Experience administering any firewall or router, even a port-based one
  • Familiarity with directory services such as Active Directory or LDAP
  • Comfortable reading logs and correlating events across sources
  • Access to a lab firewall, VM-Series instance or evaluation environment
# pricing

Straightforward pricing

Every plan includes 1 year of full LMS access — not just this course, the entire DevOpsSchool LMS: 20+ courses, 50+ tools, videos, quizzes, assignments and projects.

Self-paced video

₹833/mo

Billed yearly at ₹9,996

Enroll now

1-on-1 mentorship

₹99,999

Full program, private instructor

Enroll 1-on-1

Corporate / private batch

8–30 engineers · custom agenda · onsite or online · PO and GST invoicing

Get a custom quote

Refunds. If we cancel or postpone a cohort, you get a full refund within 15 days. There is no money-back guarantee otherwise.

Terms. Course material remains licensed to the attendee. Read the terms.

Your data. We don't share it with third parties. Privacy policy.

Every attendee gets a verifiable certificate

  • Issued per attendee on completion
  • Verifiable at devopsschool.com/certificates
  • Hard copy available on request
  • Corporate batches receive an attendance and assessment report
DevOpsSchool

Palo Alto Networks Training

Certificate of completion

# feedback

What engineers say

4.4 / 5 from 26 reviews on Trustpilot.

★★★★★
My experience with the AIOps training was positive. The course covered important topics in a structured way, and Rajesh Kumar explained the concepts patiently. I found the practical aspects particularly helpful because they made the technical content easier to understand.
AARTI KUMARI · Trustpilot
★★★★★
I was looking to improve my understanding of AIOps, and this training helped me achieve that goal. Rajesh Kumar explained the subject in a structured and practical manner. The sessions on different AIOps concepts were informative.
Sonali Tiwari · Trustpilot
★★★★★
I recently did a SRE Session with Rajesh Kumar from DevOps School and the session was great. Right from 1st day till day 15, we had a very interactive session. Rajesh clarified our doubts and the tool demos were excellent without any hiccups. He simplified the concepts while sticking to the content with a fine balance between theory and practice. Am convinced he is one of the best trainers for SRE & DevOps concepts.
chandrasekaran j · Trustpilot
★★★★★
The Rundeck developer session was excellent and highly engaging. I appreciated how well the session was structured, with the theoretical concepts explained clearly and in simple terms. What stood out most to me was the demo — it was both informative and enjoyable. I especially liked how Rajesh walked us through not only the happy path but also the sad path, showcasing common issues and sharing practical troubleshooting tips.
Raimy Roy · Trustpilot
★★★★★
Rajesh's experience and knowledge are exceptional and we learnt invaluable practical knowledge which we can apply in our production environment. Incredibly friendly and gave us a fantastic insight both in-depth and at a high level of the Rundeck product.
Fire Titan · Trustpilot
★★★★★
Great learning experience from a very knowledgeable instructor with well-prepared course notes. The lab exercises on AWS instance work well to learn the hands-on side of the course.
Ando Gg · Trustpilot
# comparison

Why a named practitioner beats a marketplace listing

What mattersYouTube + blogsGeneric online courseFreelance marketplaceDevOpsSchool
Named practitionerNoRarelyVaries per bookingYes — same trainer each time
Production experienceUnknownUnknownUnverified20 years, named employers
Custom agendaNoNoSometimesBuilt from your stack
Onsite deliveryNoNoSometimesYes
Lab environmentNoneSandbox that expiresVariesYour own cloud — skill goes with you
AssessmentNoneQuizRarelyAssignments + capstone per module
Per-attendee certificatesNoSometimesRarelyYes
Corporate invoicingNoLimitedVariesPO and GST
Post-training supportNoneForum, time-limitedNoneLifetime forum access
# questions

Frequently asked

Can the agenda be customised for our stack?
Yes — that is the normal case for a private batch. We start with a discovery call, look at your PAN-OS versions, Panorama topology, identity source and cloud footprint, and rebuild the module list around them. Examples then use your topology rather than a generic one.
Do you deliver onsite?
Yes. Private batches run onsite at your premises, live online, or hybrid. You provide the room and the engineers; we bring the trainer, agenda, labs, assessment and certificates.
What lab environment do we need?
Attendees provision their own environment — typically a VM-Series instance on a free-tier or evaluation cloud account, or an existing lab appliance — and we walk them through it. We deliberately do not hand out shared sandboxes, because the environment they build is the one they keep.
Is this an offensive security course?
No. The course is entirely defensive: designing segmentation, writing and auditing policy, tuning detection, and reconstructing incidents from logs. Attack techniques are discussed only to the extent needed to explain what a control detects and why.
Does it prepare us for PCNSA or PCNSE?
It maps closely to both blueprints and covers the operational depth the PCNSE expects — packet flow, Panorama, decryption, HA and troubleshooting. We are not an authorised exam provider; we prepare the competence and point you at the official exam.
Can you cover Prisma or Cortex as well?
We can add awareness-level sessions on Prisma Access, Prisma Cloud, Cortex XDR and XSOAR to a private batch. Full depth on those products is a separate engagement — combining everything into one week produces a shallow course.
How long does a private Palo Alto Networks batch take?
Typically four to five days. Zones, policy, NAT, App-ID and threat profiles fill three days; adding decryption, GlobalProtect, Panorama and incident investigation takes it to five.
What size are batches?
Private corporate batches run 8 to 30 engineers. Public Live & Interactive cohorts are capped at 10 so everyone gets time with the trainer.
Do attendees get a certificate?
Yes — every attendee receives a completion certificate, verifiable at devopsschool.com/certificates. Corporate batches also receive an attendance and assessment report.
What happens if someone misses a session?
Sessions are recorded and available in the LMS, and attendees keep LMS access for a year. For public cohorts, a missed session can be picked up in a later batch.
How do you handle invoicing and tax?
We support purchase orders and issue GST invoices where applicable. Corporate quotes are issued in your currency; INR remains the source price.
What is your refund position?
If we cancel or postpone a cohort, you receive a full refund within 15 days. There is no general money-back guarantee, and GST and gateway fees are not refunded.

Still deciding?

Tell us the team, the stack and the timeline. You'll get a straight answer, not a sales sequence.

Talk to an advisor
# ready when you are

Book a Palo Alto Networks trainer — or ask a question first.

  • No spam, no drip sequence
  • Syllabus in 60 seconds
  • A human reply within one business day

Prefer to call or email?

More ways to reach us on the contact page.

Talk to an advisorRequest a quote