Thanks for your reply. i do not use the template from panorama to create the vsys. is it possible ? my template only have some sylog server setting and authentication setting. For network part( like interface , routing ,.. ) , i will configure on the firewall ( not panorama ) . For panorama, i use the device group to deploy the security policy ,NAT, object,...) when i add new vsys on firewall ( not panorama ), how Panorama work for this newly created vsys ?
... View more