<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change device group tree in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/change-device-group-tree/m-p/501067#M105219</link>
    <description>&lt;P&gt;any advice?&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jun 2022 07:36:50 GMT</pubDate>
    <dc:creator>ChristianBolelli</dc:creator>
    <dc:date>2022-06-07T07:36:50Z</dc:date>
    <item>
      <title>Change device group tree</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-device-group-tree/m-p/499042#M105168</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Now my Panorama managing 4 cluster, 3 in Emea and 1 in US.&lt;/P&gt;&lt;P&gt;This the Device Group organization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shared&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cluster 1&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cluster 2&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cluster 3&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cluster 4&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we want to modify the organization to split the Emea Cluster and US Cluster:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shared&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Emea:&lt;OL&gt;&lt;LI&gt;Cluster1&lt;/LI&gt;&lt;LI&gt;cluster2&lt;/LI&gt;&lt;LI&gt;cluster3&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;US:&lt;OL&gt;&lt;LI&gt;Cluster1&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Should be easy like that:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create 2&amp;nbsp; new empty Device Gruop "Emea" and "US" (parent device group will be Shared)&lt;/LI&gt;&lt;LI&gt;For each cluster change the "Parent Device Gruop" from "shared" to the dedicated Region DG.&lt;/LI&gt;&lt;LI&gt;Commit&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's only a Panorama organizations or there are an consequences on the fws that can create an outage and I have to consider?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 08:20:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-device-group-tree/m-p/499042#M105168</guid>
      <dc:creator>ChristianBolelli</dc:creator>
      <dc:date>2022-06-03T08:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Change device group tree</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-device-group-tree/m-p/501067#M105219</link>
      <description>&lt;P&gt;any advice?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 07:36:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-device-group-tree/m-p/501067#M105219</guid>
      <dc:creator>ChristianBolelli</dc:creator>
      <dc:date>2022-06-07T07:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: Change device group tree</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-device-group-tree/m-p/501224#M105229</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110051"&gt;@ChristianBolelli&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;As long as "Emea" and "US" device-groups are completely empty it shouldn't have any difference for the actuall firewall configuration or any traffic interruption.&lt;/P&gt;
&lt;P&gt;You may still need to "push" config to devices if Panorama show firewall config out of sync. But you could confirm that nothing will change for the firewall, by "preview changes" (Push to Devices -&amp;gt; Edit Selections -&amp;gt; Device Groups -&amp;gt; Preview Changes")&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 14:28:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-device-group-tree/m-p/501224#M105229</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-06-07T14:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Change device group tree</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-device-group-tree/m-p/501246#M105232</link>
      <description>&lt;P&gt;Ah yes, now "Emea"and "US" are two DG where I can put a regional rules.&lt;BR /&gt;For example on my scenario I can put under the Emea policy a rule that will be pushed on all 3 cluster but If the Emea and US still empty the firewall rule will be the same.&lt;/P&gt;&lt;P&gt;Right?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 14:41:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-device-group-tree/m-p/501246#M105232</guid>
      <dc:creator>ChristianBolelli</dc:creator>
      <dc:date>2022-06-07T14:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Change device group tree</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-device-group-tree/m-p/501301#M105236</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110051"&gt;@ChristianBolelli&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;That is correct. Each device groups will inherint the rules from it parent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to think for device groups as of onion layers as the parent device groups are the outter layers and the child are the inner layers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1654613734494.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41641i638E03DEB42F05CD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1654613734494.png" alt="Astardzhiev_0-1654613734494.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Above image represent the final rule order pushed to the device. Sorry I couldn't found image with multiple device group, but the principle is the same. In your case it should look like &lt;BR /&gt;Share Pre-prolicies&lt;/P&gt;
&lt;P&gt;Emea Pre-policies&lt;/P&gt;
&lt;P&gt;Cluster1 Pre-policies&lt;/P&gt;
&lt;P&gt;Local policies&lt;/P&gt;
&lt;P&gt;Cluster1 Post-policies&lt;/P&gt;
&lt;P&gt;Emea Post-policies&lt;/P&gt;
&lt;P&gt;Shared Post policies&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your Emea device group is empty...Nothing will really change for the firewall policy and rule order.&lt;/P&gt;
&lt;P&gt;If you add Pre-rule in Emea device group it will be inherited by all emea clusters and that rule will be placed above any pre-rules defined in the clusterX device groups&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this make sense, not sure if I manage to explaint it in a good way.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 15:02:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-device-group-tree/m-p/501301#M105236</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-06-07T15:02:39Z</dc:date>
    </item>
  </channel>
</rss>

