When looking at Dynamic Address Groups along with Panorama, it almost looks like this can't be done unless you are using NSX. I setup the VM Source on one of my firewalls and I can do a DAG, but it doesn't transfer back to Panorama inorder to use it in a policy. If you are managing Policies and Address groups from Panorama this becomes almost a useless feature.
All the docs and knowledgebase articles I have seen talk about doing this with NSX.
Not sure if I missed a place to configure this on Panorama, besides in the template, but the template pushes out to the firewall devices. If I did miss sometihng please point me in the right direction so I can get this useful feature into my setup.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!