After adding firewalls (see
Add a Firewall as a Managed Device), you can group them into
(up to 256), as follows. Be sure to assign both firewalls in an active-passive high availability (HA) configuration to the same device group so that Panorama will push the same policy rules and objects to those firewalls. PAN-OS doesn’t synchronize pushed rules across HA peers. To manage rules and objects at different administrative levels in your organization,
Create a Device Group Hierarchy.