<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy creation/management in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-creation-management/m-p/531216#M109543</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/273942"&gt;@sachin_chauhan&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using tags by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt; is the easiest solution with just a few different subnets.&amp;nbsp; If you don't want to use tags, you can also manually check the device under the Target tab in the policy rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another solution is to use nested device groups.&amp;nbsp; Put the policies that don't change in the higher device group and the policies that are different for different NGFWs in a lower device group.&amp;nbsp; You can use the Move button on the bottom of the GUI to do this.&amp;nbsp; I generally put all objects in Shared.&amp;nbsp; This method makes it easier to manage multiple NGFWs but requires planning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once done, you can clone your lower device group.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cla3CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cla3CAC&lt;/A&gt;&amp;nbsp; Or you can copy the rules as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt; suggested.&amp;nbsp; Assign the new NGFW to the new DG and make the changes needed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These are other options for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 15 Feb 2023 10:58:30 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-02-15T10:58:30Z</dc:date>
    <item>
      <title>Policy creation/management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-creation-management/m-p/531198#M109538</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a running sites where firewall running and managing through panorama. clients building a new sites and new firewall deployments however panorama will be remain same and policy will be the same just few sub-nets needs to be changed. there are many policy in exiting firewalls/panorama. Is there any way to copy existing policy into new policy group? or we have do to create them manually?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 08:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-creation-management/m-p/531198#M109538</guid>
      <dc:creator>sachin_chauhan</dc:creator>
      <dc:date>2023-02-15T08:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Policy creation/management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-creation-management/m-p/531203#M109539</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/273942"&gt;@sachin_chauhan&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for the post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you mean copying policies between different device groups, then you can do a bulk cloning of policies by selecting multiple policies and placing copy to different device group:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1676449896686.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47967i707D5E32CDCC7CA4/image-size/large?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1676449896686.png" alt="PavelK_0-1676449896686.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Slightly different approach would be leveraging device tags in policies. With device tags associated with certain sites you can manage what policies are pushed to different sites. This will however require a bit of planning.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNdxCAG" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNdxCAG&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 08:41:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-creation-management/m-p/531203#M109539</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-02-15T08:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: Policy creation/management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-creation-management/m-p/531216#M109543</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/273942"&gt;@sachin_chauhan&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using tags by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt; is the easiest solution with just a few different subnets.&amp;nbsp; If you don't want to use tags, you can also manually check the device under the Target tab in the policy rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another solution is to use nested device groups.&amp;nbsp; Put the policies that don't change in the higher device group and the policies that are different for different NGFWs in a lower device group.&amp;nbsp; You can use the Move button on the bottom of the GUI to do this.&amp;nbsp; I generally put all objects in Shared.&amp;nbsp; This method makes it easier to manage multiple NGFWs but requires planning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once done, you can clone your lower device group.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cla3CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cla3CAC&lt;/A&gt;&amp;nbsp; Or you can copy the rules as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt; suggested.&amp;nbsp; Assign the new NGFW to the new DG and make the changes needed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These are other options for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 10:58:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-creation-management/m-p/531216#M109543</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-02-15T10:58:30Z</dc:date>
    </item>
  </channel>
</rss>

