Disable/Enable Panorama Policy and Objects | This option displays only when you edit the
Panorama Settings on a firewall (not in a
template on Panorama). Disable Panorama Policy and
Objects to disable the propagation of device group
policies and objects to the firewall. By default, this action also
removes those policies and objects from the firewall. To keep a
local copy of the device group policies and objects on the firewall,
in the dialog that opens when you click this option, select
Import Panorama Policy and Objects before
disabling. After you perform a commit, these
policies and objects become part of the firewall configuration and
Panorama no longer manages them.
For multi-vsys
firewalls, you must first import the the template configuration
and then import the device group configuration to successfully
disable the Panorama pushed configuration.
Under
normal operating conditions, disabling Panorama management is
unnecessary and could complicate the maintenance and configuration
of firewalls. This option generally applies to situations where
firewalls require rules and object values that differ from those
defined in the device group. An example is when you move a firewall
out of production and into a laboratory environment for
testing. To revert firewall policy and object management to
Panorama, click Enable Panorama Policy and
Objects. |