I am planning to delete unused objects (Address, AddressGroups, Service) in PaloAlto, Is it possible to extract only the objects that are not set in the policy?
I know that if they are set in the policy, an error will be output when deleting them, but out of thousands of configurations, I would like to find the objects that do not generate an error, However, it is difficult to find an object that does not generate an error among thousands of settings.
Therefore, we would like to extract only the objects that are not set in the policy and delete them all at once.
For reference, the following video shows how to extract "Unused objects" from CheckPoint's "Objects Explorer". We would like to implement this kind of method in PaloAlto.
https://www.youtube.com/watch?v=EHkeOc9Zkr4
If you have any suggestions or advice, I would be happy to hear from you.
... View more