Multiple Portals Same Template Panorama Multiple Vsys

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Multiple Portals Same Template Panorama Multiple Vsys

L4 Transporter

I'm trying to see if there is a good way to use templates to create 2 different global protect portals using panorama.   This would be used as a failover scenario, and ease changes, allowing us to use 1 template to configure both firewalls.    Name and fqdn would be the same, just failover to the other IP.   


Problem is that I can't seem to find out how to capitalize on using a template when it comes down to using the same setup, but on different firewalls on a specific vsys (not vsys1).  I know variables solve the problem of ip's, but I think certificates may be a problem too.   Multiple vsys and one template config across 2 different firewalls. Solution?


Hi @Sec101 

Panorama actually doesn't care about the internal firewall-vsys-names (vsys1, vsys2, vsys3, ...). In panorama you create a template with a name like "VPN". If you then apply this template to a firewall, the configuration will be applied to the vsys with the name "VPN". There it does not matter if this vsys "VPN"  is vsys2 on firewall 1 ond vsys4 for example on firewall 2. So with this theoretically your requirement should be configurable but there probably stilm are some stones in the way aka dependent configurations. So if there are other configurations in the same vsys on the two firewalls you might need to change some of these into the template for the vsys "VPN".

@SteveCantwell are you talking about the device groups? As these are applied to 0070003242649/VSYSNAME. The templates need to be added to template stacks to which actual firewalls (without vsys) are attached.

Maybe I don't understand what you mean, but in a new template by default vsys1 is created. But then you can add the vsys with the name you like:


After that you could even delete vsys1 from this template so that it only contains the configuration for this one specific vsys you need. When you then add this template to a template stack the configuration from the VPN vsys is applied there where you need it.

That is exactly what I meant.  Thank you @vsys_remo !   So now, my only question is, I'm guessing I can have two templates managing the same vsys, as long as there are no overlaps in the configuration correct?   I know the top down precedence order in stacking, but when it comes to multiple templates managing the same vsys, does it work the same way?

@Sec101 yes, it works the same way. As long as you have no overlaps all the configurations will be applied.

(If there are overlaps then, the configuration from the template with the higher priority (higher in the list of templates in the template stack) will be used)

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!