Managing policy with Panorama - what is best practice?

L3 Networker

We are looking at deploying multiple firewall instances managed centrally by Panorama, and would like to maintain a global baseline policy across all of them.

We recognize that regional instances will have specific local policy requirements not shared globally, so we have the option of either implementing them directly on the firewall, or instead doing it on Panorama and targeting the specific firewall.

Is there some guidance on how to approach this? What considerations should influence the decision?

