Configure an on-premises or VM-Series Firewall as a Master Device
Focus
Focus

Configure an on-premises or VM-Series Firewall as a Master Device

Table of Contents

Configure an on-premises or VM-Series Firewall as a Master Device

Use the following procedure to configure an on-premises or VM-series firewall as a Master Device.
  1. Create device groups for mobile users, remote networks, and service connection device groups as required, and specify the on-premises device as the Master Device.
    1. Select PanoramaManaged DevicesDevice Groups.
    2. Add a new device group.
    3. Enter a Name for the device group.
    4. Leave the Parent Device Group as Shared.
    5. In the Devices area, select the Name of the on-premises or VM-Series device that you want to set as the Master Device.
    6. Select Store user and groups from Master Device if Reporting and Filtering on Groups is enabled in Panorama Settings.
      This option allows Panorama to locally store usernames, user group names, and group mapping information that it receives from the Master Device.
    7. Click OK.
      The following screenshot creates a Master Device to be used for the service connection.
  2. Associate the device groups you created for your Prisma Access mobile user, remote network, or service connection deployment.
    • To associate the device group with a mobile user deployment, select PanoramaCloud ServicesConfigurationMobile Users and edit the settings by clicking the gear icon in the Settings area and associate the device group you created for the service connection with the Parent Device Group.
    • To associate the device group with a remote network connection, select PanoramaCloud ServicesConfigurationRemote Networks and edit the settings by clicking the gear icon in the Settings area and associate the device group you created for the remote network connection with the Parent Device Group.
    • To associate the device group with a service connection, select PanoramaCloud ServicesConfigurationService Setup and edit the settings by clicking the gear icon in the Settings area and associate the device group you created for the service connection with the Parent Device Group.
    After you create a parent device group, Prisma Access automatically populates group mapping for the device group that is associated with the master device only. For the previous examples, the auto-population would occur only in the User-ID DG Mobile Users, User-ID DG Remote Connection, and User-ID DG Service Connection device groups, and would not populate to the Mobile_User_Device_Group, Remote_Network_Device_Group, or Service_Conn_Device_Group device groups, respectively.
  3. Click OK.