<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: pn do not use tempalte ,only use device group in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/pn-do-not-use-tempalte-only-use-device-group/m-p/524077#M1271</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76688"&gt;@Felixcao&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for the post!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can think of a few issues and limitations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some of the Device Group configuration has dependency on Templates. For example Log Forwarding profile is being pushed by Device Group, but Syslog, SNMP, Email is coming from Template. If you do not use Template, you will not be able to push this configuration. The same applies to security policy, QoS, Policy Based Forwarding, Decryption. Each of these configuration is leveraging Zones and moving this from Template to local Firewall configuration will result in not being able to reference it in Device Group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are still some configuration under Device Group that have no dependency on Template, however not being able to use configuration from Template because it has moved from Panorama to local configuration will limit customer to only several configuration sections.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Personally, I think by this move there are more limitations than benefits.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Wed, 14 Dec 2022 10:07:48 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2022-12-14T10:07:48Z</dc:date>
    <item>
      <title>pn do not use tempalte ,only use device group</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/pn-do-not-use-tempalte-only-use-device-group/m-p/524043#M1269</link>
      <description>&lt;P&gt;The customer manages multiple sets of firewalls through panorama. Considering that the configuration of the template is not changed much in the future, the customer considers porting the configuration of the template to the local wall. If the parameters are changed, it will not be pushed through panorama.&lt;/P&gt;
&lt;P&gt;Panorama is only responsible for pushing policies and objects. Does this bring new problems to the later operation and maintenance, or are there any special precautions?&lt;/P&gt;
&lt;P&gt;Please put forward more suggestions or discuss, thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 04:31:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/pn-do-not-use-tempalte-only-use-device-group/m-p/524043#M1269</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2022-12-14T04:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: pn do not use tempalte ,only use device group</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/pn-do-not-use-tempalte-only-use-device-group/m-p/524077#M1271</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76688"&gt;@Felixcao&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for the post!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can think of a few issues and limitations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some of the Device Group configuration has dependency on Templates. For example Log Forwarding profile is being pushed by Device Group, but Syslog, SNMP, Email is coming from Template. If you do not use Template, you will not be able to push this configuration. The same applies to security policy, QoS, Policy Based Forwarding, Decryption. Each of these configuration is leveraging Zones and moving this from Template to local Firewall configuration will result in not being able to reference it in Device Group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are still some configuration under Device Group that have no dependency on Template, however not being able to use configuration from Template because it has moved from Panorama to local configuration will limit customer to only several configuration sections.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Personally, I think by this move there are more limitations than benefits.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 10:07:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/pn-do-not-use-tempalte-only-use-device-group/m-p/524077#M1271</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-12-14T10:07:48Z</dc:date>
    </item>
  </channel>
</rss>

