Create template stacks and device groups to manage the configuration of your
VM-Series firewalls on NSX.
| Where Can I Use
This? | What Do I Need? |
To manage the VM-Series firewalls on NSX-T using Panorama, the firewalls must belong
to a device group and a template stack. Device groups allow you to assemble
firewalls that need similar policies and objects as a logical unit; the
configuration is defined using the Objects and
Policies tabs on Panorama. Use template stacks to
configure the settings that are required for the VM-Series firewalls to operate on
the network; the configuration is defined using the Device
and Network tabs on Panorama. Each template stack used in
your NSX-T configuration must be associated with a service definition.
Firewalls deployed in NSX-T have two default zones and two interfaces configured in
virtual wire mode. Ethernet1/1 is part of zone south and
ethernet1/2 is part of zone north. To push policy rules from
Panorama to managed firewalls, you must configure zones and interfaces matching
those on the firewall in the corresponding template stack on Panorama.