Engineering reference

What the model represents

42 stages, 77 directed branches, 38 scenarios and 58 representative packet checkpoints. Every displayed edge is exercised by at least one included trace.

Five logical columns

ColumnResponsibilities
IngressParsing, inspection eligibility, tunnel decapsulation, IP reassembly, early discard and local/held handling.
Session setupZone Protection, initial TCP checks, forwarding and NAT lookups, User-ID, DoS policy, firewall Security policy lookup, session installation.
Fast pathSession lookup, L2–L4/TCP state, stored NAT, TCP reassembly, SSL proxy gate, application-state decision and content eligibility.
App / contentOverride/signature lookup, app-based Security policy, profiles/QoS classification, decryption/proxy setup, inspection, app changes, profile actions and re-encryption.
EgressForwarding, QoS shaping, MTU/DF decisions, IPv4 fragmentation, tunnel encapsulation, outer route lookup and transmission.

After DoS policy, permitted setup proceeds to firewall Security policy lookup. After SSL proxy processing, an unresolved application with payload enters App-ID; a known application proceeds to content eligibility. Pure handshake packets can bypass payload inspection. Decoder-discovered application changes return to application-aware Security policy. These branches preserve the distinction between first-packet setup and established-session processing.

Included scenario families

Assumptions and boundaries

Reference material

The model was developed from the supplied “Day in the Life of a Packet” diagram and packet-flow document, and checked against these vendor references:

This is an independent educational project. Palo Alto Networks and PAN-OS are trademarks of their respective owner. No vendor artwork, executable firewall software or source PDF is redistributed in this package.

Validation

The supplied model tests check all 58 traces, every stage and edge, ordering invariants, terminal block/hold/transmit outcomes, reverse NAT and selected application/decryption behaviors. They validate consistency of the implemented model; they are not a certification against every PAN-OS version or platform.