Hi
I have a Firewall currently setup in a Panorama Device Group.
I now want to to manage a new Firewall that has a similar set of rules (not a HA) so I want to put it in the same Device Group, so the rules are synced going forward.
My question is what happens to the rules on the 2nd Firewall when I add it to the Device Group and push the policy? Does the Device Group Rules (currently from the 1st Firewall import) get merged with the existing rules? Will duplicates get removed? Or will it overwrite the whole config?
Many thanks.
This depends how you join the firewall to panorama
If you import and then push config bundle, all the local config is replaced (from panorama > setup > operations)
If you simply attach it to panorama, the pre-rules will be put above the existing rules, and the post-rules will be placed below. Your local rules will remain
Conflicting rules might cause a commit error, so make sure you update any names that might become duplicate