<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Template and Devcie Group Design in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/template-and-devcie-group-design/m-p/126768#M46542</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have active/passive firewalls at the perimeter and datacenter. I went a bit overboard with the templates. I created a template for each firewall, then a template for the perimeter and datacenter, and a global template. I then created a stack for each firewall. The reasons why I did that is because I didn't want to put any configuration directly on the firewalls (beside the HA configuration), in case I mistakenly override a local configuration from Panorama, and also because I didn't want to have the same configuration in two places. For example, our NTP server configuration is only in the global template, and the firewall hostname is in each individual template.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
    <pubDate>Wed, 16 Nov 2016 15:11:24 GMT</pubDate>
    <dc:creator>BenjAudy.MTL</dc:creator>
    <dc:date>2016-11-16T15:11:24Z</dc:date>
    <item>
      <title>Template and Devcie Group Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/template-and-devcie-group-design/m-p/126057#M46483</link>
      <description>&lt;P&gt;Hello Experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two firewalls cluster, managed by panorama. One cluster is for perimeter firewall and other is core/DC firewalls. I have three customers and I created three vsys (CUST1, CUST2 and CUST3) on both clusters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now what is the recommendations for creating how many templates and device groups on panorama. Should I create three device groups - one for each customer on perimter cluster and DC cluster - means total six device groups?&lt;/P&gt;&lt;P&gt;Also what about templates? Should I create two tempaltes - one template per cluster or we can create templates for customer on same cluster?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciated your input&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2016 06:56:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/template-and-devcie-group-design/m-p/126057#M46483</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-14T06:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Template and Devcie Group Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/template-and-devcie-group-design/m-p/126711#M46530</link>
      <description>&lt;P&gt;Any one there?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 10:53:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/template-and-devcie-group-design/m-p/126711#M46530</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-16T10:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: Template and Devcie Group Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/template-and-devcie-group-design/m-p/126768#M46542</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have active/passive firewalls at the perimeter and datacenter. I went a bit overboard with the templates. I created a template for each firewall, then a template for the perimeter and datacenter, and a global template. I then created a stack for each firewall. The reasons why I did that is because I didn't want to put any configuration directly on the firewalls (beside the HA configuration), in case I mistakenly override a local configuration from Panorama, and also because I didn't want to have the same configuration in two places. For example, our NTP server configuration is only in the global template, and the firewall hostname is in each individual template.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 15:11:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/template-and-devcie-group-design/m-p/126768#M46542</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2016-11-16T15:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Template and Devcie Group Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/template-and-devcie-group-design/m-p/126945#M46572</link>
      <description>&lt;P&gt;Thank you make sense. But how about if your DC firewall have multiple virtual system (each for one customer). In this case would you go for individual template for each customer? What I see, If i stick to only one template for all virtual system then I cannot reuse the same zone name and also can not use different ssl forward decryption certificate etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I can go with global template (contains HA config, hostname etc) then I can make one template per each customer and stack with global template. Is this make sense and we can do?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 07:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/template-and-devcie-group-design/m-p/126945#M46572</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-17T07:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Template and Devcie Group Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/template-and-devcie-group-design/m-p/127893#M46623</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think it would make sense to have a template per customer. It makes sense for device groups, though.&amp;nbsp;I don't understand why you cannot reuse the same zone name for different vsys. You tried it and you got an error message?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2016 18:26:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/template-and-devcie-group-design/m-p/127893#M46623</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2016-11-21T18:26:50Z</dc:date>
    </item>
  </channel>
</rss>

