When looking at Dynamic Address Groups along with Panorama, it almost looks like this can't be done unless you are using NSX. I setup the VM Source on one of my firewalls and I can do a DAG, but it doesn't transfer back to Panorama inorder to use it in a policy. If you are managing Policies and Address groups from Panorama this becomes almost a useless feature. All the docs and knowledgebase articles I have seen talk about doing this with NSX. Not sure if I missed a place to configure this on Panorama, besides in the template, but the template pushes out to the firewall devices. If I did miss sometihng please point me in the right direction so I can get this useful feature into my setup.
... View more