Disable/Enable Panorama Policy and Objects | This option displays only when you edit
the Panorama Settings on a firewall (not
in a template on Panorama). Disable Panorama Policy
and Objects to disable the propagation of device group
policies and objects to the firewall. By default, this action also
removes those policies and objects from the firewall. To keep a
local copy of the device group policies and objects on the firewall,
in the dialog that opens when you click this option, select Import
Panorama Policy and Objects before disabling. After
you perform a commit, these policies and objects become part of the
firewall configuration and Panorama no longer manages them.
For
multi-vsys firewalls, you must first import the the template configuration
and then import the device group configuration to successfully disable
the Panorama pushed configuration.
Under normal operating
conditions, disabling Panorama management is unnecessary and could
complicate the maintenance and configuration of firewalls. This
option generally applies to situations where firewalls require rules and
object values that differ from those defined in the device group.
An example is when you move a firewall out of production and into
a laboratory environment for testing. To revert firewall policy
and object management to Panorama, click Enable Panorama
Policy and Objects. |