Nested Device Group in Panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Nested Device Group in Panorama

L3 Networker

How to create nested device group in panorama, is the same device group can be part of multiple nested device group.

 

If yes, how the policy priorities would be.

Please suggest here.

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Thank you for reply @Sujanya

 

unfortunately, I never came across what you are referring to and have not found anything related in documentation. I do not see such option while creating a device group. A firewall as well as vsys can be assigned to only one device group: https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/manage-device-groups...

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

Hello @Sujanya

 

thanks for the post!

 

You can configure nested device group in the tree of up to 4 device group levels. The policies, objects,... are inhereted from upper device group in the hierarchy. Further details are in documentation: https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/panorama-overview/centralized-firewal...

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi Pavel,

 

Thanks for the information. We do have single device group which needs to be part of two separate device group( which is for different purposes). What we heard is while creating the device group in Panorama , we can call the same device group by bifurcating via vsys. Please let us know if you have any suggestion on the same or any documentation which can help us in implementing it in our network.

 

 

Cyber Elite
Cyber Elite

Thank you for reply @Sujanya

 

unfortunately, I never came across what you are referring to and have not found anything related in documentation. I do not see such option while creating a device group. A firewall as well as vsys can be assigned to only one device group: https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/manage-device-groups...

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi @PavelK ,

 

Thanks for the details. This solved my queries.

  • 1 accepted solution
  • 3007 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!