Hi, We have active/passive firewalls at the perimeter and datacenter. I went a bit overboard with the templates. I created a template for each firewall, then a template for the perimeter and datacenter, and a global template. I then created a stack for each firewall. The reasons why I did that is because I didn't want to put any configuration directly on the firewalls (beside the HA configuration), in case I mistakenly override a local configuration from Panorama, and also because I didn't want to have the same configuration in two places. For example, our NTP server configuration is only in the global template, and the firewall hostname is in each individual template. Benjamin
... View more