I have several PAN firewalls that I now manage individually and have recently purchased a Panorama appliance in the hopes of making it easier to manage common policies. We have two sites that will need identical rules but with different IP's referenced in the rules. I come from a background of using McAfee CommandCenter and in their terminology what I am looking for is an "Adaptive Object". Where I can define an object that has a different IP depending on which firewall it is installed on. How can I do this same functionality with Panorama? I was told that if you name the objects/groups the same that the local object will have precedence, but then you still have to manage local object and Panorama objects, it's not centralized management. Any feedback in figuring this out is greatly appreciated.
... View more