Hi @chens ,
This is something that is not explained very well in the documentation.
Step 5 in the URL below, Export or push device config bundle, deletes the local Policies and Objects (device group configuration) and adds the Panorama pushed Policies and Objects. Your template values are not changed.
Step 6 in the URL below, Commit to Panorama then Commit > Push to Devices, will override the local Network and Device configuration (template values) IF the Force Template Values box is checked. This should be done with care because you could override IP addresses, routes, etc. The NGFW is smart enough not to change the management interface configuration or host name. Generally this should be done only once on the first push after the export/push.
https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-to-panorama-management
Thanks,
Tom
... View more