<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create device group to use it on panorama target field in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/create-device-group-to-use-it-on-panorama-target-field/m-p/175588#M55013</link>
    <description>&lt;P&gt;I don't know if I explain my problem:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example I have these 2 pre-rules in panorama and deployed to about 40 firewalls (last column on the screenshot).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11184iFC017406B74E036C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I created only a shared device group with all my firewalls, but however when I want to target a pre-rule to all the firewalls I have to check all:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11185iE6CC9A8FC182DE3D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And if I add a new Firewall to the shared device group, I have to go to all pre-rules and check the new FW on the target windows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the end I can't create different device groups with shared firewalls:&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;In the share device group XX, I have FW1 and FW2.&lt;/P&gt;&lt;P&gt;If I create the shared device group YY, the FW1 and FW2 are hidden.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope to be clearer.&lt;/P&gt;</description>
    <pubDate>Fri, 08 Sep 2017 07:51:52 GMT</pubDate>
    <dc:creator>FassaSRL</dc:creator>
    <dc:date>2017-09-08T07:51:52Z</dc:date>
    <item>
      <title>Create device group to use it on panorama target field</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-device-group-to-use-it-on-panorama-target-field/m-p/175329#M54957</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I use Panorama to deploy some policy rules to my 40 firewalls.&lt;/P&gt;&lt;P&gt;Obviously some rules are the same for all firewalls, others are specific to a some of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to create different groups of firewalls and deploy the rules to the groups. So if I have to add/change a FW to a panorama rule, will be sufficient to modify the group and not all rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yesterday I changed a broken firewall, and I had to remove the old one from more of 50 rules and the add the new one. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example I'd like to be able to:&lt;/P&gt;&lt;P&gt;Rule A --&amp;gt; deployed to FW1, FW2&lt;/P&gt;&lt;P&gt;Rule B --&amp;gt; deployed to FW1, FW2&lt;/P&gt;&lt;P&gt;Rule C --&amp;gt; deployed to FW1, FW3&lt;/P&gt;&lt;P&gt;Rule D --&amp;gt; deployed to FW1, FW3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I have to add the FW4, and add it to all rules, it would be faster to have:&lt;/P&gt;&lt;P&gt;Device Group X: FW1, FW2&lt;/P&gt;&lt;P&gt;Device Group Y: FW1, FW3&lt;/P&gt;&lt;P&gt;Rule A --&amp;gt; deployed to Group X&lt;/P&gt;&lt;P&gt;Rule B --&amp;gt; deployed to &lt;SPAN&gt;Group X&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Rule C --&amp;gt; deployed to &lt;SPAN&gt;Group Y&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Rule D --&amp;gt; deployed to &lt;SPAN&gt;Group Y&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and add FW to the groups.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Massimiliano&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 08:17:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-device-group-to-use-it-on-panorama-target-field/m-p/175329#M54957</guid>
      <dc:creator>FassaSRL</dc:creator>
      <dc:date>2017-09-07T08:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Create device group to use it on panorama target field</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-device-group-to-use-it-on-panorama-target-field/m-p/175390#M54964</link>
      <description>&lt;P&gt;You can in Panorama&amp;nbsp;you have a shared device group section that will apply to all firewall groups. In this you can specify "Pre rules" and "Post Rules"&lt;/P&gt;&lt;P&gt;you also can select the individual groups and set up pre and post rules.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I dont believe&amp;nbsp;you can have a single firewall as a memeber of more then one group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any rules you want assigned to only one firewall (or HA pair) the rules would fall between the Pre and Post rules.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 11:47:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-device-group-to-use-it-on-panorama-target-field/m-p/175390#M54964</guid>
      <dc:creator>Kaje</dc:creator>
      <dc:date>2017-09-07T11:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Create device group to use it on panorama target field</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-device-group-to-use-it-on-panorama-target-field/m-p/175467#M54980</link>
      <description>&lt;P&gt;We create a device group for each FW. Why do we do this... Well so we don't have to worry about specifying a "target"&amp;nbsp;FW each rule goes to. Once the rule is created in Panorama you can "Clone" it to another FW. You will not however be able to "Clone" to another FW if you originally wrote the rule specifying a "target" fw.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 16:14:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-device-group-to-use-it-on-panorama-target-field/m-p/175467#M54980</guid>
      <dc:creator>Wald</dc:creator>
      <dc:date>2017-09-07T16:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Create device group to use it on panorama target field</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-device-group-to-use-it-on-panorama-target-field/m-p/175588#M55013</link>
      <description>&lt;P&gt;I don't know if I explain my problem:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example I have these 2 pre-rules in panorama and deployed to about 40 firewalls (last column on the screenshot).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11184iFC017406B74E036C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I created only a shared device group with all my firewalls, but however when I want to target a pre-rule to all the firewalls I have to check all:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11185iE6CC9A8FC182DE3D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And if I add a new Firewall to the shared device group, I have to go to all pre-rules and check the new FW on the target windows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the end I can't create different device groups with shared firewalls:&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;In the share device group XX, I have FW1 and FW2.&lt;/P&gt;&lt;P&gt;If I create the shared device group YY, the FW1 and FW2 are hidden.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope to be clearer.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:51:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-device-group-to-use-it-on-panorama-target-field/m-p/175588#M55013</guid>
      <dc:creator>FassaSRL</dc:creator>
      <dc:date>2017-09-08T07:51:52Z</dc:date>
    </item>
  </channel>
</rss>

