I've been working with Panorama now for just over a month, learning most its concepts slowly but surely. I am now stuck however on the following:
Before we acquired Panorama, we had several clients running PA-220s. After it was announced the 220s were reaching EoL, we replaced most with 410s and 440s. We then acquired Panorama to centralise all deployments. How I did it was to import each client's 220 configs into respective 410/440 replacements, then deploy them to client site. Then from office I would register them to our Panorama, import its config into client-respective device group and templates.
From this point on, it has been really painful getting even one client FW to be in sync with either device group or template. I am having to rename/remove every single object/policy for example for the firewall to accept push, due to conflicting objects.
I think lesson learnt here is that I should've pushed the configs into the firewall via Panorama instead of directly into firewall.
My question, is there any simpler way I can push templates and groups to already deployed firewalls more easily, without having to configure them from scratch and risk removing their running configs?
... View more