Adding zones in Panorama

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Adding zones in Panorama

L4 Transporter

Hello everyone,


I have question.  I inherited a few firewalls that are partially managed by Panorama, meaning I have objects and other items pushed to the firewall from Panorama but mostly everything else is local.  On the local firewall, contains all firewall rules, zones, interfaces are configured with ip addresses.  The other firewalls are fully managed by Panorama.  Not ideal but the real problem is I cannot create shared security rules in Panorama for all my firewalls since no zones exist for these few firewalls.


My question is, can I safely create the zones with the same names in Panorama for these device groups and push it out to the firewalls without impacting the interfaces on the local firewall


Once I can get the zones in Panorama, I can slowly create matching firewall rules and get rid of the local rules



L4 Transporter

If you have a zone configured on panorama and on the firewall node, then the one on the firewall will take precedence. Once you are sure the zone configurations are equal on panorama and the firewall node, then you can remove the config from the firewall itself.

@JoergSchuetter I do not yet have a zone configured for these particular firewalls in Panorama.  I wasn't sure if the commit would fail or if it would cause other issues.   Based on your response, it sounds like it would push to the firewall successfully but would be overridden by local config (which is fine).  Right now, I'm more concerned with having the ability to create shared security policy rules across all firewalls, so that they are consistent.  I believe this will solve that issue

  • 2 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!