Hello, Are both the PAN firewalls in the same Device group on the Panorama? If so, since you're looking for creating identical rules but with different IP/address objects, create separate security policies with respective address-objects/IP's and target them only to the specific device in question.(Target is the last tab while creating a Security policy). This way when pushing the config to the Device group, policies will be pushed based on the target specified to the selected device. You can also add the devices in different device groups, so that way you can create address-objects and policies specific to each group. In this case, as you said you define the object with a different IP depending upon the device group. Hope that helps! Aditi
... View more