Benefits of nested device groups in panorama. People who follow my blog may probably know that I'm a big fan of Cisco ASA firewalls and I worked quite extensively with them. ) A . When I was first introduced to the Palo Alto firewalls, I was amazed at how easy it is to use the web GUI compare to the ASDM which I absolutely hate. While Panorama enables you to reuse the same device group configuration across multiple device groups in a hierarchy, you can also customize any local configurations to override any inherited configuration. ) Jun 16, 2015 · Now, it’s easier than ever to set, group, and manage rules by creating nested device groups in a tree hierarchy—with lower-level groups inheriting the policies and objects of higher-level groups—and template stacks, which push the combined settings of multiple templates to firewalls. Overwrites local firewall configuration View Answer Jun 8, 2022 · Device groups provide a way to organize and reuse your policies by applying the principle of inheritance and implementing a well defined device group hierarchy. In answer to my recent community poll (thank you to everybody that voted) this video shows the use cases and how to configure Palo Alto Panorama Device Groups. A. tl;dr - Three sites/firewalls in Panorama, each being quite different without much configuration being shared between them. Just make sure you understand the rule ordering for nested device groups and pre and post rules, it may not be what you expect (but does make sense when you think it through). lmd xmfekwx anerjt cpmerb dtqf ramqa yaw hlufjs oqw sldgm