Panorama sharing security policy across device groups?

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Panorama sharing security policy across device groups?

L0 Member

Is there a way in panorama 4.0.2 to create and either copy the policy to a new device group or have a shared policy that can have a target of all devices?  We currently have 12 device groups (due to muliple vert systems.) and i would like an easy way of putting security policy on all of the devices. I don't see any "Shared" device group when I am in panorama. Is what i'm asking possible?


L4 Transporter

There is no "global" or "shared" device group that exists in Panorama so you will not be able to accompish sharing of security policy across device groups.

You could use shared objects for anything used in the security rules across multiple device groups and create a scripted (CLI or XML API) solution to copy/duplicate the rules.

You could also create one DG and use "Targets" for rules which are specific to the 12 individual groups you have today. You could use tags on rules which are either "Global" or should be targeted to todays device groups. This will allow for easy filtering to thin the rulebase to "tag eq Global or tag eq <DG_name>" if you want to do "DG" specific rulebase editing. The disadvantage to this approach is that any admin will have to have access to the entire rulebase and you wont be able to create DG specific admins.

Thanks this answers my question. Is the single DG a supported option, i have looked at the setup and didn't know that we could do that.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!