set deviceconfig system hostname PA-CORP-FW01 set deviceconfig system domain corp.local set deviceconfig system timezone US/Eastern set deviceconfig system ntp-servers primary-ntp-server ntp-server-address pool.ntp.org set deviceconfig system service disable-telnet no set deviceconfig system service disable-http no set deviceconfig system service disable-https no set deviceconfig system permitted-ip 0.0.0.0/0 set mgt-config users admin permissions role-based superuser yes set mgt-config users admin password admin123 set mgt-config users svc-backup permissions role-based superuser yes set mgt-config users svc-backup password Welcome1! set network interface ethernet ethernet1/1 layer3 ip 203.0.113.10/29 set network interface ethernet ethernet1/2 layer3 ip 10.10.0.1/24 set network interface ethernet ethernet1/3 layer3 ip 10.20.0.1/24 set zone untrust network layer3 ethernet1/1 set zone trust network layer3 ethernet1/2 set zone dmz network layer3 ethernet1/3 set rulebase security rules Allow-Outbound from trust to untrust source any destination any application any service any action allow log-end no set rulebase security rules Allow-Inbound-Web from untrust to dmz source any destination 10.20.0.5 application web-browsing service service-https action allow set rulebase security rules DMZ-to-Trust from dmz to trust source any destination any application any service any action allow set rulebase security rules Default-Deny from any to any source any destination any application any service any action deny log-end yes set rulebase security rules Allow-Outbound profile-setting group none set rulebase security rules Allow-Inbound-Web profile-setting group none set zone untrust network layer3 ethernet1/1 zone-protection-profile none set deviceconfig system update-schedule statistics-service application-reports yes set deviceconfig system update-schedule threats recurring weekly day-of-week sunday at 02:00 action download-and-install set shared log-settings syslog disabled set deviceconfig system snmp-setting access-setting version v2c community public set shared certificate webui-cert ca no set deviceconfig system ssl-tls-service-profile mgmt-tls min-version tls1-0 set shared application-group risky-apps members bittorrent set rulebase security rules Allow-Outbound application any # WildFire and threat prevention not configured # DNS sinkhole not configured # No URL filtering profile applied # SAML/MFA not configured for admin login