- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-22-2018 09:04 AM
Hello
I start the Panorama configuration and I created Device Group. My device group are based on our site location :
FR
- Paris
- Toulouse
I would like to know the best way for the configuration. If I create objects in Paris DG (object to define Paris's local networks and servers) and I create also objects in Toulouse DG (object to define Toulouse's local network and servers), I can create a rule in Toulouse for exemple to allow LAN network to request server in Paris. In destination, I can't select the objet define in Paris to define a network located in Paris's site.
What is the best way to manage this type of configuration ? Create all objects in share DG ?
BR
Jerome
11-22-2018 12:07 PM
@CARRIERJerome wrote:Create all objects in share DG ?
Yes, that's what I would recomment to you (and what I personally already do). At least adress-, addressgroup-, service- and servicegroupobjects I would configure in shared DG, because ob panorama you have the option to only push the used objects to the firewalls. This way you don't run into problems when you have many thousand objects in panorama but use it also for PA-200 which have limited capacity for objects.
11-23-2018 12:00 AM
Hello
Thank's for your anwser. To be sure to understand, if I have the following hiearchy on the Device Group :
Company
FR
- Paris
- Toulouse
DE
- Munich
Your recommandation is to create object with the "shared" option validated and the location of the objet is "Shared" or to create object in "Company" DG without "shared" option validated and in this case, the object is created with "Company" location, and as it's the top of the DG hiearchy, this object will be avalaible in the other DG (FR, Paris, Toulouse, .. ) ?
BR
11-23-2018 09:45 AM
My personal recommendation is "shared" but this now depends on your preferences and maybe details like if you also use this panorama for other companies (if you - for example - work for a service provider) and if there are other admins that are not allowed to view everything but need to be able to change policies.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!