<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configure existing Production Panorama template used for Policies/Objects, but not Interfaces/Zones for SD WAN in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/configure-existing-production-panorama-template-used-for/m-p/538268#M1470</link>
    <description>&lt;P&gt;When we started using the Panorama many years ago, we did so using the templates as an after thought of manually configuring each firewall. We are a small company so it wasn't difficult, but now we want to entertain SD WAN and my understanding is it is best to do this from the Panorama and not individually from each firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since the Interfaces/Zones are set up individually, but identically (other than IP address differences) what would happen if I introduced the Interface/Zone configurations to the Panorama and then pushed this down to the firewall(s)? Scared to do so and cause issues. What is the best way forward? Maybe set up a new template with this configured and then move each firewall to the new template.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I should add I have 11 firewalls. The majority of these are in one template (9 firewalls) with 1 other in its own template and the last firewall is manually maintained and is different from all the rest.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Apr 2023 16:40:37 GMT</pubDate>
    <dc:creator>ronan</dc:creator>
    <dc:date>2023-04-11T16:40:37Z</dc:date>
    <item>
      <title>Configure existing Production Panorama template used for Policies/Objects, but not Interfaces/Zones for SD WAN</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/configure-existing-production-panorama-template-used-for/m-p/538268#M1470</link>
      <description>&lt;P&gt;When we started using the Panorama many years ago, we did so using the templates as an after thought of manually configuring each firewall. We are a small company so it wasn't difficult, but now we want to entertain SD WAN and my understanding is it is best to do this from the Panorama and not individually from each firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since the Interfaces/Zones are set up individually, but identically (other than IP address differences) what would happen if I introduced the Interface/Zone configurations to the Panorama and then pushed this down to the firewall(s)? Scared to do so and cause issues. What is the best way forward? Maybe set up a new template with this configured and then move each firewall to the new template.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I should add I have 11 firewalls. The majority of these are in one template (9 firewalls) with 1 other in its own template and the last firewall is manually maintained and is different from all the rest.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 16:40:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/configure-existing-production-panorama-template-used-for/m-p/538268#M1470</guid>
      <dc:creator>ronan</dc:creator>
      <dc:date>2023-04-11T16:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Configure existing Production Panorama template used for Policies/Objects, but not Interfaces/Zones for SD WAN</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/configure-existing-production-panorama-template-used-for/m-p/538284#M1471</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52408"&gt;@ronan&lt;/a&gt;&amp;nbsp;, from the brief description of your network, panos native SDWAN in Panorama will work well without knowing your full checklist of needs. To handle the device-group parent-child relationships for pre and post rules, I recommend this document -&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/best-practices/10-1/best-practices-for-managing-firewalls-with-panorama/configuration-management/device-group-management" target="_blank"&gt;Manage Your Device Group Configurations on Panorama (paloaltonetworks.com)&lt;/A&gt;&amp;nbsp;and make sure you configure a Master Device, &amp;amp; Reference Template.&amp;nbsp; You can store objects in a Parent DG instead of &lt;EM&gt;shared&lt;/EM&gt;&amp;nbsp;to keep from overloading smaller firewalls but there is a checkbox in Panorama to only download objects used by the firewall.&amp;nbsp; Since your zone name characters/case are identical, you should be able to share much of your policy via parent DG.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For Templates/Template-Stacks, you will use &lt;EM&gt;variables&lt;/EM&gt;&amp;nbsp;to identify different IP addresses &amp;amp; FQDNs for different firewalls using the same Template-Stacks.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 18:49:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/configure-existing-production-panorama-template-used-for/m-p/538284#M1471</guid>
      <dc:creator>delliott_6784</dc:creator>
      <dc:date>2023-04-11T18:49:24Z</dc:date>
    </item>
  </channel>
</rss>

