Configure an on-premises or VM-Series Firewall as a Master Device
Focus
Focus

Configure an on-premises or VM-Series Firewall as a Master Device

Table of Contents

Configure an on-premises or VM-Series Firewall as a Master Device

Use the following procedure to configure an on-premises or VM-series firewall as a Master Device.
  1. Create device groups for mobile users, remote networks, and service connection device groups as required, and specify the on-premises device as the
    Master Device
    .
    1. Select
      Panorama
      Managed Devices
      Device Groups
      .
    2. Add
      a new device group.
    3. Enter a
      Name
      for the device group.
    4. Leave the
      Parent Device Group
      as
      Shared
      .
    5. In the
      Devices
      area, select the
      Name
      of the on-premises or VM-Series device that you want to set as the
      Master Device
      .
    6. Select
      Store user and groups from Master Device if Reporting and Filtering on Groups is enabled in Panorama Settings
      .
      This option allows Panorama to locally store usernames, user group names, and group mapping information that it receives from the Master Device.
    7. Click
      OK
      .
      The following screenshot creates a Master Device to be used for the service connection.
  2. Associate the device groups you created for your Prisma Access mobile user, remote network, or service connection deployment.
    • To associate the device group with a mobile user deployment, select
      Panorama
      Cloud Services
      Configuration
      Mobile Users
      and edit the settings by clicking the gear icon in the
      Settings
      area and associate the device group you created for the service connection with the
      Parent Device Group
      .
    • To associate the device group with a remote network connection, select
      Panorama
      Cloud Services
      Configuration
      Remote Networks
      and edit the settings by clicking the gear icon in the
      Settings
      area and associate the device group you created for the remote network connection with the
      Parent Device Group
      .
    • To associate the device group with a service connection, select
      Panorama
      Cloud Services
      Configuration
      Service Setup
      and edit the settings by clicking the gear icon in the
      Settings
      area and associate the device group you created for the service connection with the
      Parent Device Group
      .
    After you create a parent device group, Prisma Access automatically populates group mapping for the device group that is associated with the master device only. For the previous examples, the auto-population would occur only in the
    User-ID DG Mobile Users
    ,
    User-ID DG Remote Connection
    , and
    User-ID DG Service Connection
    device groups, and would not populate to the Mobile_User_Device_Group, Remote_Network_Device_Group, or Service_Conn_Device_Group device groups, respectively.
  3. Click
    OK
    .

Recommended For You