it depands.... because panorama will also manage PA device through VPN S2S and that will make my the connection between the panorama and the device rely on the VPN conneciton, so i cannot really move all the functionality from the device to the panorama i would like to see that ability that Panorama will push the configuration to the active one and then the policy will be synced to the other one... this is already done when i change for example the Interface of one PA device and push commit, the changed will also be done on the other device because most of the configuration are global to the HA Cluster, then the configuration can be done on a shared template for both of the device and specific configuration will be done on the device. (in all cases i am talking on active passive cluster)
... View more