Hello @egarantiva The zones are defined in "Templates", and used in "Device Groups". The config push is not a one-shot (if I see it right), meaning panorama is pushing in part after the other. We had a similar need, followed the following procedure: - create new zones, but don't assign it to interfaces - push the templates - append new zones to policies (you might need to clone NAT policies) -- I did this using a script, making use of the API - push the device groups - adjust the interfaces (use the new zones) - push the templates - remove the no longer required zones I would not expect the historic logs will change if you change the zones. Best Regards Joerg
... View more