<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama-shared objects in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-shared-objects/m-p/501859#M105267</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Take a look at this document&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/manage-device-groups/manage-unused-shared-objects" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/manage-device-groups/manage-unused-shared-objects&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Panorama has the option to disable the&amp;nbsp;&lt;STRONG&gt;Share Unused Address and Service Objects with Devices&amp;nbsp;&lt;/STRONG&gt;(which is enabled by default) so that you're only sharing objects if it's actually needed in the configuration.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jun 2022 18:20:42 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2022-06-08T18:20:42Z</dc:date>
    <item>
      <title>Panorama-shared objects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-shared-objects/m-p/501810#M105261</link>
      <description>&lt;P&gt;I am just setting up a panorama with 25 managed firewalls.&lt;/P&gt;&lt;P&gt;How can I have shared objects that are only shared between few firewalls but not all? My perimneter firewalls have huge number of objects which I would not like sharing with other remote firewalls but to some datacenter firewalls. how can I achieve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 15:16:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-shared-objects/m-p/501810#M105261</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2022-06-08T15:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama-shared objects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-shared-objects/m-p/501859#M105267</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Take a look at this document&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/manage-device-groups/manage-unused-shared-objects" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/manage-device-groups/manage-unused-shared-objects&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Panorama has the option to disable the&amp;nbsp;&lt;STRONG&gt;Share Unused Address and Service Objects with Devices&amp;nbsp;&lt;/STRONG&gt;(which is enabled by default) so that you're only sharing objects if it's actually needed in the configuration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 18:20:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-shared-objects/m-p/501859#M105267</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-06-08T18:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama-shared objects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-shared-objects/m-p/502656#M105348</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;In addition to what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; explained I would also suggest to organize your device group in hierarchical structure&lt;/P&gt;
&lt;P&gt;Something like this:&lt;/P&gt;
&lt;P&gt;Shared&lt;/P&gt;
&lt;P&gt;-- Perimeter-FWs&lt;/P&gt;
&lt;P&gt;---- Perimeter-FW-01&lt;/P&gt;
&lt;P&gt;---- Perimeter-FW-02&lt;/P&gt;
&lt;P&gt;---- Perimeter-FW-03&lt;/P&gt;
&lt;P&gt;-- DataCenter-FWs&lt;/P&gt;
&lt;P&gt;---- DataCenter-FW-01&lt;/P&gt;
&lt;P&gt;---- DataCenter-FW-02&lt;/P&gt;
&lt;P&gt;---- DataCenter-FW-03&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Everything defined in "Shared" device group will be inherited by all device groups. This is build-in device-group which always sits on top.&lt;/P&gt;
&lt;P&gt;- Everything defined in "Perimeter-FWs" will be inherited only by device groups that are children of this group&lt;/P&gt;
&lt;P&gt;- Everything defined in "DataCenter-FWs" will be inherited only by device groups that are children of this group&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Probably better explanation could be found here - &lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-hierarchy" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-hierarchy&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 14:26:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-shared-objects/m-p/502656#M105348</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-06-10T14:26:00Z</dc:date>
    </item>
  </channel>
</rss>

