Panorama - Object

Reply
Highlighted
L2 Linker

Panorama - Object

Hello

 

I start the Panorama configuration and I created Device Group. My device group are based on our site location :

 

FR

  - Paris

  - Toulouse

 

I would like to know the best way for the configuration. If I create objects in Paris DG (object to define Paris's local networks and servers) and I create also objects in Toulouse DG (object to define Toulouse's local network and servers), I can create a rule in Toulouse for exemple to allow LAN network to request server in Paris. In destination, I can't select the objet define in Paris to define a network located in Paris's site.

 

What is the best way to manage this type of configuration ? Create all objects in share DG ? 

BR

Jerome

Highlighted
Cyber Elite


@CARRIERJerome wrote:

Create all objects in share DG ? 


Yes, that's what I would recomment to you (and what I personally already do). At least adress-, addressgroup-, service- and servicegroupobjects I would configure in shared DG, because ob panorama you have the option to only push the used objects to the firewalls. This way you don't run into problems when you have many thousand objects in panorama but use it also for PA-200 which have limited capacity for objects.

 

 

Highlighted
L2 Linker

Hello

 

Thank's for your anwser. To be sure to understand, if I have the following hiearchy on the Device Group :

 

Company

   FR

     - Paris

     - Toulouse

   DE

     - Munich

 

Your recommandation is to create object with the "shared" option validated and the location of the objet is "Shared" or to create object in "Company" DG without "shared" option validated and in this case, the object is created with "Company" location, and as it's the top of the DG hiearchy, this object will be avalaible in the other DG (FR, Paris, Toulouse, .. ) ?

 

BR

Highlighted
Cyber Elite

Hi @CARRIERJerome

 

My personal recommendation is "shared" but this now depends on your preferences and maybe details like if you also use this panorama for other companies (if you - for example - work for a service provider) and if there are other admins that are not allowed to view everything but need to be able to change policies.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!