- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-25-2011 08:44 AM
Is there a way in panorama 4.0.2 to create and either copy the policy to a new device group or have a shared policy that can have a target of all devices? We currently have 12 device groups (due to muliple vert systems.) and i would like an easy way of putting security policy on all of the devices. I don't see any "Shared" device group when I am in panorama. Is what i'm asking possible?
07-28-2011 10:46 AM
There is no "global" or "shared" device group that exists in Panorama so you will not be able to accompish sharing of security policy across device groups.
You could use shared objects for anything used in the security rules across multiple device groups and create a scripted (CLI or XML API) solution to copy/duplicate the rules.
You could also create one DG and use "Targets" for rules which are specific to the 12 individual groups you have today. You could use tags on rules which are either "Global" or should be targeted to todays device groups. This will allow for easy filtering to thin the rulebase to "tag eq Global or tag eq <DG_name>" if you want to do "DG" specific rulebase editing. The disadvantage to this approach is that any admin will have to have access to the entire rulebase and you wont be able to create DG specific admins.
07-28-2011 10:55 AM
Thanks this answers my question. Is the single DG a supported option, i have looked at the setup and didn't know that we could do that.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!