Hello, good afternoon, I'm new to the administration of Panorama, thank you very much for your support and collaboration.
I have the following question:
Stage detail:
Panorama- Device Group "INT-PA" : Members: PA-INT01 and INT02 ( HA )
Device Group "NEW-INT-PA": Members: NEW-INT-PA-01 AND NEW-INT-PA-02 (HA ).
-In the first Device Group INT-PA, I have configured a lot of policies and objects.
-Now the topic is as follows, I want to move members NEW-INT-PA-01 and NEW-INT-PA-02 from Device-Group: from NEW-INT-PA to Device Group "INT-PA". I am not interested in keeping absolutely nothing of the Device Group NEW-INT-PA configurations, since this Device Group is only transitional, it has nothing of interest configured.
Therefore what I need is that the members of NEW-INT-PA-01 and NEW-INT-PA-02 receive all the policies and objects from Device Group "INT-PA" . Therefore, after explaining the details of the scenario, the question is, just remove the firewalls NEW-INT-PA-01 and NEW-INT-PA-02 as members of the Device Group "NEW-INT-PA" and then add them to the Device Group INT-PA, so that the Palo Alto NEW-INT-PA-01 and NEW-INT-PA-02 inherit all the policies and objects, also eliminating all possible traces of configurations (some other device policy transition group ) from the other DG, and getting without problems, all the config from the DG:"INT-PA".
Thank you very much for your support, collaboration and for your time.
I remain attentive, cordial greetings and very attentive to your comments
Routing and interfaces are all part of the same configuration, and introducing overrides there leaves you open to a lot of "unexpected behavior". In my experience it is best to move all configuration to panorama and then force the template so all the local overrides are removed
I usually create a template stack for each firewall, and then add the templates as needed. In that case you would not need to touch the template stack (rename it if you ant) and move all the required templates into the stack, and remove any templates that are no longer being used.
That is correct. If you don't care about the configuration in NEW-INT-PA, simply move your firewalls over to INT-PA