- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-01-2026 11:48 AM
Hi everyone,
I'm looking for some guidance on Panorama commit workflows in larger environments.
For those managing multiple device groups and templates, what has worked best for reducing commit times and avoiding unnecessary changes?
Do you typically use selective commits whenever possible, or do you have another workflow that has proven reliable? Also, are there any best practices for minimizing the impact of policy updates across a large number of managed firewalls?
I'd appreciate hearing how others handle this in production. Thanks!
08-03-2026 08:58 PM
Hello @kosarbnu
thanks for post!
Below are a few points I can think of based on my experience.
In the past I was using managed device tag: Managed Firewall Administration in the Panorama under: Panorama > Managed Devices > Summary to have 3 tier hierarchy to push policies to managed Firewalls based on tags. If you have many Firewalls with large number of policies, I found tags effective way to filter and deploy policies.
If you have huge number of objects, I would recommend to look into disabling: "Share Unused Address and Service Objects with Device". Reference: How to Limit the Number of Shared Objects Panorama Pushes to the Managed Device , Address object limit exceeded on Panorama Managed Low End platforms even if "Share Unused Address an....
If you have an environment where some of the configuration is managed locally directly in Firewall by different admins, then I would recommend to deselect: “Merge with Candidate Config” to prevent your Panorama pushed configuration is also committing someone else configuration: How Configuration Change is Being Applied Depending on “Merge with Candidate Config” Commit Option.
If you have large organization with multiple admins in different regions managing configuration through Panorama it might be worth looking into: Access Domains.
Lastly, I recommend to have pre-policy on the top that explicitly allows managed Firewalls to communicate with Panorama. In the case there is a misconfiguration by pushing a policy that cuts off manage Firewalls, you can still maintain access to rollback change. This applies when Firewall policy can break path between managed Firewalls and Panorama. This is handy in the case Automated Commit Recovery does not take an effect.
Kind Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

