<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama Commit Best Practices for Large Environments in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-commit-best-practices-for-large-environments/m-p/1260835#M3136</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1696229647"&gt;@kosarbnu&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for post!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below are a few points I can think of based on my experience.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the past I was using managed device tag:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/ngfw/help/12-2/panorama-web-interface/panorama-managed-devices-summary/managed-firewall-administration#idfb2fd59b-4789-4ae1-888f-2f43eb4d3167" target="_self"&gt;Managed Firewall Administration&lt;/A&gt;&amp;nbsp;in the Panorama under: Panorama &amp;gt; Managed Devices &amp;gt; Summary to have 3 tier hierarchy to push policies to managed Firewalls based on tags. If you have many Firewalls with large number of policies, I found tags effective way to filter and deploy policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have huge number of objects, I would recommend to look into disabling:&amp;nbsp;"Share Unused Address and Service Objects with Device". Reference:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm1tCAC" target="_self"&gt;How to Limit the Number of Shared Objects Panorama Pushes to the Managed Device&lt;/A&gt;&amp;nbsp;,&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLZUCA4&amp;amp;lang=en_US%E2%80%A9" target="_self"&gt;Address object limit exceeded on Panorama Managed Low End platforms even if "Share Unused Address and Service Objects with Device" is unchecked&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If you have an environment where some of the configuration is managed locally directly in Firewall by different admins, then I would recommend to deselect:&amp;nbsp;“Merge with Candidate Config” to prevent your Panorama pushed configuration is also committing someone else configuration:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClQqCAK" target="_self"&gt;How Configuration Change is Being Applied Depending on “Merge with Candidate Config” Commit Option&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have large organization with multiple admins in different regions managing configuration through Panorama it might be worth looking into:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/getting-started/panorama-overview/role-based-access-control/access-domains" target="_self"&gt;Access Domains&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lastly, I recommend to have pre-policy on the top that explicitly allows managed Firewalls to communicate with Panorama. In the case there is a misconfiguration by pushing a policy that cuts off manage Firewalls, you can still maintain access to rollback change.&amp;nbsp; This applies when Firewall policy can break path between managed Firewalls and Panorama. This is handy in the case Automated Commit Recovery does not take an effect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2026 03:58:00 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2026-08-04T03:58:00Z</dc:date>
    <item>
      <title>Panorama Commit Best Practices for Large Environments</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-commit-best-practices-for-large-environments/m-p/1260673#M3133</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;I'm looking for some guidance on Panorama commit workflows in larger environments.&lt;/P&gt;
&lt;P&gt;For those managing multiple device groups and templates, what has worked best for reducing commit times and avoiding unnecessary changes?&lt;/P&gt;
&lt;P&gt;Do you typically use selective commits whenever possible, or do you have another workflow that has proven reliable? Also, are there any best practices for minimizing the impact of policy updates across a large number of managed firewalls?&lt;/P&gt;
&lt;P&gt;I'd appreciate hearing how others handle this in production. Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 01 Aug 2026 18:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-commit-best-practices-for-large-environments/m-p/1260673#M3133</guid>
      <dc:creator>kosarbnu</dc:creator>
      <dc:date>2026-08-01T18:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama Commit Best Practices for Large Environments</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-commit-best-practices-for-large-environments/m-p/1260835#M3136</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1696229647"&gt;@kosarbnu&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for post!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below are a few points I can think of based on my experience.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the past I was using managed device tag:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/ngfw/help/12-2/panorama-web-interface/panorama-managed-devices-summary/managed-firewall-administration#idfb2fd59b-4789-4ae1-888f-2f43eb4d3167" target="_self"&gt;Managed Firewall Administration&lt;/A&gt;&amp;nbsp;in the Panorama under: Panorama &amp;gt; Managed Devices &amp;gt; Summary to have 3 tier hierarchy to push policies to managed Firewalls based on tags. If you have many Firewalls with large number of policies, I found tags effective way to filter and deploy policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have huge number of objects, I would recommend to look into disabling:&amp;nbsp;"Share Unused Address and Service Objects with Device". Reference:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm1tCAC" target="_self"&gt;How to Limit the Number of Shared Objects Panorama Pushes to the Managed Device&lt;/A&gt;&amp;nbsp;,&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLZUCA4&amp;amp;lang=en_US%E2%80%A9" target="_self"&gt;Address object limit exceeded on Panorama Managed Low End platforms even if "Share Unused Address and Service Objects with Device" is unchecked&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If you have an environment where some of the configuration is managed locally directly in Firewall by different admins, then I would recommend to deselect:&amp;nbsp;“Merge with Candidate Config” to prevent your Panorama pushed configuration is also committing someone else configuration:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClQqCAK" target="_self"&gt;How Configuration Change is Being Applied Depending on “Merge with Candidate Config” Commit Option&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have large organization with multiple admins in different regions managing configuration through Panorama it might be worth looking into:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/getting-started/panorama-overview/role-based-access-control/access-domains" target="_self"&gt;Access Domains&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lastly, I recommend to have pre-policy on the top that explicitly allows managed Firewalls to communicate with Panorama. In the case there is a misconfiguration by pushing a policy that cuts off manage Firewalls, you can still maintain access to rollback change.&amp;nbsp; This applies when Firewall policy can break path between managed Firewalls and Panorama. This is handy in the case Automated Commit Recovery does not take an effect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2026 03:58:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-commit-best-practices-for-large-environments/m-p/1260835#M3136</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2026-08-04T03:58:00Z</dc:date>
    </item>
  </channel>
</rss>

