Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Panos

ASecurity

Expert coverage of Palo Alto Networks PAN-OS across all versions: SP3 architecture, App-ID, Content-ID, User-ID, security policy design, Panorama management, WildFire, decryption, zone design, HA, and CLI troubleshooting. Use for \"PAN-OS\", \"Palo Alto\", \"App-ID\", \"Panorama\", \"WildFire\", \"Content-ID\", \"User-ID\", \"GlobalProtect\", \"PA-\", \"security profile\", \"IronSkillet\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `fi...

4 stars
0 votes
0 copies
0 views
Added 9/24/2026
devopsrustgoazureterraformapisecurity

Works with

cliapi

Security Analysis

A100/100

Pro scans all 9 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill panos --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Panos?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Panos
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-panos/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-panos)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: panos
description: "Expert coverage of Palo Alto Networks PAN-OS across all versions: SP3 architecture, App-ID, Content-ID, User-ID, security policy design, Panorama management, WildFire, decryption, zone design, HA, and CLI troubleshooting. Use for \"PAN-OS\", \"Palo Alto\", \"App-ID\", \"Panorama\", \"WildFire\", \"Content-ID\", \"User-ID\", \"GlobalProtect\", \"PA-\", \"security profile\", \"IronSkillet\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `firewall` skill."
license: MIT
---

# PAN-OS

This skill covers Palo Alto Networks PAN-OS across all supported versions (10.2 through 12.1). Areas of expertise include:

- Single-Pass Parallel Processing (SP3) architecture
- App-ID application identification and continuous reclassification
- Content-ID threat prevention (AV, Anti-Spyware, Vulnerability Protection, URL Filtering, WildFire)
- User-ID IP-to-user mapping and group-based policy
- Security policy design (zone-based, application-based, top-down first-match)
- NAT architecture (pre-NAT IP matching, post-NAT zone matching)
- Panorama centralized management (device groups, templates, template stacks)
- SSL/TLS decryption (forward proxy, inbound, SSH proxy)
- High availability (active/passive, active/active)
- CLI troubleshooting and operational commands
- Automation (XML API, REST API, Terraform, Ansible, Skillets)

When a question is version-specific, consult the matching `references/versions/` file. When the version is unknown, provide general guidance and note where behavior differs.

## How to Approach Tasks

1. **Classify** the request:
   - **Troubleshooting** -- Load `references/diagnostics.md` for CLI commands and debug workflows
   - **Policy design** -- Load `references/best-practices.md` for rule ordering and profile attachment
   - **Architecture** -- Load `references/architecture.md` for SP3, packet flow, zones, vsys, HA
   - **Administration** -- Follow Panorama and commit model guidance below
   - **Automation** -- Apply XML API, REST API, Terraform, or Ansible guidance

2. **Identify version** -- Determine which PAN-OS version. If unclear, ask. Version matters for feature availability (Advanced Threat Prevention requires 10.2+, App-ID Cloud Engine requires 11.1+, PQC requires 11.1+).

3. **Load context** -- Read the relevant reference file for deep knowledge.

4. **Analyze** -- Apply PAN-OS-specific reasoning, not generic firewall advice.

5. **Recommend** -- Provide actionable, specific guidance with CLI examples or GUI paths.

6. **Verify** -- Suggest validation steps (`test security-policy-match`, `show session`, packet captures).

## Core Architecture: SP3

PAN-OS uses Single-Pass Parallel Processing with hardware-separated planes:

- **Data Plane**: Dedicated CPU/memory for packet processing. Three processor types: Network Processor (forwarding, routing, NAT), Security Processor (SSL/TLS/IPsec), Security Matching Processor (signatures, URL lookups).
- **Management Plane**: Separate CPU/memory for GUI, CLI, API, logging, reporting, routing protocol control plane.
- **Key benefit**: Heavy admin activity (reports, log searches) does not degrade packet forwarding.

## Packet Flow

```
Ingress -> L2/L3 parse -> Session lookup
  Existing session (fast path) -> Forward with minimal processing
  New session (slow path) -> App-ID -> Content-ID -> Policy evaluation -> Session creation -> Forward
```

**Critical NAT/policy interaction**: Security policy matches **pre-NAT source/destination IPs** but **post-NAT zones**. When writing rules for inbound DNAT, use the original public IP as the destination in the security rule, not the translated private IP.

## App-ID Deep Knowledge

App-ID classifies traffic through four mechanisms applied in sequence:
1. **Protocol decoders** -- Validate protocol conformance (HTTP on port 80 actually uses HTTP)
2. **Application signatures** -- Pattern matching on payload, headers, behavior
3. **Heuristics** -- Behavioral analysis for evasive/encrypted applications
4. **Continuous reclassification** -- Mid-session updates (web-browsing -> facebook-base -> facebook-posting)

**When App-ID reclassifies a session**: PAN-OS re-evaluates security policy. If the new application matches a deny rule, the session is terminated.

**Application Override vs Custom App-ID**: Application Override skips App-ID entirely (no L7 inspection, threat prevention severely limited). Prefer creating a Custom App-ID signature that correctly identifies the application while preserving full security inspection.

**`application-default` service**: Restricts traffic to the application's documented ports. Prevents application tunneling (e.g., SSH over port 80). Best practice for most rules.

## Security Policy Design

### Rule Structure
1. Deny known-bad (EDLs, block lists) at the top
2. Specific interzone rules ordered by specificity
3. Intrazone rules where needed
4. Cleanup rule (explicit deny-all with logging)
5. Default rules (intrazone allow, interzone deny)

### Security Profiles -- Always Attach
Every allow rule should have a Security Profile Group attached:
- **Outbound (trust->untrust)**: AV + Anti-Spyware (with DNS sinkhole) + Vulnerability Protection (strict) + URL Filtering + WildFire Analysis + File Blocking
- **Inbound (untrust->DMZ)**: AV + Anti-Spyware + Vulnerability Protection (strict)
- **Intrazone (servers)**: Vulnerability Protection + Anti-Spyware

Use Security Profile Groups (not individual profiles per rule) for maintainable policy. IronSkillet provides ready-made profile groups.

### Rule Validation
```
test security-policy-match from <src-zone> to <dst-zone> source <ip> destination <ip> protocol <proto> destination-port <port> application <app>
```
This simulates policy lookup and shows which rule matches -- essential for detecting shadowed rules.

## Commit Model

PAN-OS uses a candidate/running configuration model:
- **Candidate config**: Working copy. All changes (GUI, CLI, API) modify the candidate.
- **Running config**: Active on the dataplane. Updated only on `commit`.
- **`diff`**: Always review before committing.
- **`validate full`**: Syntax and semantic check without committing.
- **Partial commit** (10.2+): Commit only changes from a specific admin.
- **Config locks**: Prevent conflicting concurrent edits.

**Panorama commit flow**:
1. Commit to Panorama (saves Panorama's running config)
2. Push to Devices (pushes policy and template config to managed firewalls)
3. Never skip step 1 -- always commit to Panorama first

## Panorama Management

### Device Groups
Contain security policies and objects. Hierarchical: Shared > Parent DG > Child DG.
- **Pre-rules**: Evaluated before device-local rules (centrally managed mandatory policy)
- **Post-rules**: Evaluated after device-local rules (centrally managed catch-all)
- Objects in a parent DG are inherited by child DGs

### Templates and Template Stacks
Templates define network/device configuration (interfaces, zones, routing, VPN, management profiles). Template stacks layer 1-8 templates in priority order.
- **Template variables**: Enable per-device value substitution ($mgmt-ip, $loopback-ip)
- Best practice: Global base template (NTP, DNS, syslog) + per-site template (interfaces, routing)

## WildFire

Cloud-based malware analysis with four verdicts: benign, grayware, malicious, phishing.
- WF-500 on-premises appliance does NOT support phishing verdict
- WildFire signatures distributed within minutes of malware discovery (vs. daily AV updates)
- Always configure WildFire Analysis profile to forward all supported file types
- Enable WildFire real-time signatures under Device > Setup > WildFire

## Decryption

### SSL Forward Proxy (Outbound)
- Firewall acts as MITM for outbound HTTPS
- Requires internal CA certificate trusted by all clients (deploy via GPO/MDM)
- Forward Trust cert (valid server certs) and Forward Untrust cert (invalid server certs)

### No-Decrypt Rules
- Place above decrypt rules (evaluated first)
- Required for: certificate-pinned apps, banking, healthcare, privacy-sensitive traffic
- Decryption policy is also top-down first-match

## User-ID

Maps IP addresses to usernames for user/group-based policy:
- **Windows User-ID Agent**: Monitors DC event logs (4768, 4624)
- **Integrated Agent (Agentless)**: Firewall monitors DCs directly via WMI
- **Cloud Identity Engine (CIE)**: Cloud-native for Azure AD, Okta, Google Workspace (10.1+, recommended for cloud IdPs)
- **Captive Portal**: Fallback for unauthenticated users
- **GlobalProtect**: VPN users mapped automatically

## Common Pitfalls

1. **Forgetting security profiles on allow rules** -- An allow rule without threat inspection provides zero defense in depth. Use the IronSkillet profile groups as a baseline.

2. **Using `application: any` with `service: specific-port`** -- This allows ALL applications on that port, not just the intended application. Use specific App-IDs instead.

3. **NAT confusion with policy matching** -- Security policy uses pre-NAT IPs but post-NAT zones. Test with `test security-policy-match` to verify.

4. **Upgrading both HA peers simultaneously** -- Always upgrade passive first, verify, fail over, then upgrade the other. Never upgrade both at once.

5. **Panorama version behind firewalls** -- Panorama must always be the same version or newer than managed firewalls. Upgrade Panorama first.

6. **Not reviewing App-ID changes before content updates** -- Each content update may change App-IDs. Review the App-ID impact report before committing content updates in production.

7. **Committing without reviewing diff** -- Always run `diff` or Preview Changes before committing to avoid unintended changes from other admins.

8. **Ignoring the BPA** -- Run the Best Practice Assessment via Expedition regularly. It catches common misconfigurations.

## Version-Specific Guidance

| Version | Reference | What's version-specific |
|---|---|---|
| 10.2 | `references/versions/10.2.md` | Advanced Threat Prevention, Advanced URL Filtering, AIOps, Advanced Routing Engine |
| 11.2 | `references/versions/11.2.md` | Quantum-Safe VPN (Phase 2/Full PQC), PA-400R rugged NGFW, App-ID Cloud Engine matured |
| 12.1 | `references/versions/12.1.md` | Comprehensive PQC platform, PA-5500 hardware, Quantum Readiness Dashboard, 48-month support |

## Reference Files

Load these when you need deep knowledge:

- `references/architecture.md` -- SP3 internals, packet flow stages, session management, zone types, vsys, HA mechanics, log forwarding. Read for "how does X work" questions.
- `references/diagnostics.md` -- CLI troubleshooting commands, packet captures, debug dataplane, session inspection, HA commands, content updates. Read when troubleshooting.
- `references/best-practices.md` -- Policy design, zone design, NAT design, HA deployment, Panorama architecture, IronSkillet, BPA, upgrade procedures. Read for design and operations questions.

## Diagnostic Scripts

Ready-made SSH operational-command bundles (read-only) in `scripts/`.

- `scripts/01-system-health.sh` -- System state, resources, HA state, session pressure
- `scripts/02-traffic-triage.sh` -- Policy-match test, live sessions, drop counters for one flow

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Terraform Module Library

Build reusable Terraform modules for AWS, Azure, and GCP infrastructure following infrastructure-as-code best practices. Use when creating infrastructure modules, standardizing cloud provisioning, or implementing reusable IaC components.

401991 votes

sematext-otel

Wire a service's OpenTelemetry output to Sematext Cloud. Walks through region, App-type, instrumentation flow (managed OTLP endpoint vs Sematext Agent), and signal selection (traces/metrics/logs), then produces the exact env-var block and points at a runnable reference example in this repo. Invoke when instrumenting a new app for Sematext.

01 votes

Deployment Patterns

Deployment workflows, CI/CD pipeline patterns, Docker containerization, health checks, rollback strategies, and production readiness checklists for web applications. Use when setting up deployment infrastructure or planning releases.

2699140 votes

Babysit

Watch a pull request or review cycle until it is ready to merge. Use when asked to babysit, monitor, or keep checking PR comments, reviews, and CI until all actionable issues are resolved.

968770 votes

V7 Roster

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

953190 votes
View all in devops →