Hey @ronan , from the brief description of your network, panos native SDWAN in Panorama will work well without knowing your full checklist of needs. To handle the device-group parent-child relationships for pre and post rules, I recommend this document - Manage Your Device Group Configurations on Panorama (paloaltonetworks.com) and make sure you configure a Master Device, & Reference Template. You can store objects in a Parent DG instead of shared to keep from overloading smaller firewalls but there is a checkbox in Panorama to only download objects used by the firewall. Since your zone name characters/case are identical, you should be able to share much of your policy via parent DG.
For Templates/Template-Stacks, you will use variables to identify different IP addresses & FQDNs for different firewalls using the same Template-Stacks.
... View more