Hello all, we are running into an issue where we are unable to change static address object groups to dynamic address object groups We have an M500 and several PA7050 and the objects are managed under the "shared" device group for all the PA7050's. We have added tags etc. to the address objects and on the panorama they show up with their dynamic members, all looks fine here. But when we push the configuration to the firewalls, the address object group will be switched from type static to type dynamic without any members, therefore the policy for these addresses will no longer match --> Global Deny. Is this a known behavior or general limitation that a switch from static to dynamic is not possible? Since the support from the distributor had no clue either I thought to ask you guys 🙂 Best regards, Thomas
... View more