Yes, I'm pretty sure. I used the API to pull the merged config directly from the firewall, and it definitely does not include the security rules from Panorama. I get the same results from the cli command 'show config merged'. However, when I log into the device's web console, I can see all the rules that came from Panorama so I'm certain they're getting pushed to the device.
Btw, I can run 'show config pushed-shared-policy' on the firewall and all of the policy objects from Panorama are displayed. They just do not appear in the merged output.
... View more