Palo Alto Networks, PAN-OS® Administrator’s Guide 10.2.
Section: Networking > Packet Flow Sequence in PAN-OS
Details: The documentation provides a detailed diagram and explanation of the "Life of a Packet." It explicitly shows Zone Protection occurring in the initial ingress stage (Stage 1). It then details the slow path (session setup), where policy lookup triggers decryption (Stage 6), followed by application identification (App-ID) (Stage 8), and finally, content inspection/security profile enforcement (Stage 9).
Palo Alto Networks Live Community, "The Life of a Packet."
Document: This resource provides a simplified and graphical representation of the packet flow. It confirms that ingress processing, including zone protection, happens first. It is followed by session setup, which involves policy evaluation that can trigger decryption, then App-ID, and subsequently content scanning via security profiles.