When you commit Device Groups, by default Panorama pushes all shared objects to firewalls whether or not any shared or device group policy rules reference the objects. However, you can configure Panorama to push only the shared objects that rules reference in the device groups you commit. The Share Unused Address and Service Objects with Devices check box enables you to limit the objects that Panorama pushes to the managed firewalls.
On smaller firewalls, such as the PA-200, consider pushing only the relevant shared objects to the managed firewalls. This is because the number of objects that can be stored on a smaller firewall is considerably lower than that of the mid-size and larger models. Also, if you have many address and service objects that are unused, clearing the Share Unused Address and Service Objects with Devices check box reduces the commit times significantly on the firewalls because the configuration pushed to each firewall is smaller. Disabling this option may, however, increase the commit time on Panorama. This is because Panorama has to dynamically check whether policy rules reference a particular object.
Manage Unused Shared Objects
Select Panorama > Setup > Management, and edit the Panorama Settings.
Clear the Share Unused Address and Service Objects with Devices check box to push only the shared objects that rules reference, or select the check box to re-enable pushing all shared objects.
Click OK and Commit, for the Commit Type select Panorama, and click Commit again.

Related Documentation