Panorama configuration management is based on:
- Device Groups — Organize firewalls into hierarchical groups for security policy
management (security rules, NAT policies, application filters).
- Templates and Template Stacks — Define network and device settings (interfaces,
zones, routing, system settings).
- Inheritance — Device Groups inherit policies from parent groups; Template Stacks
layer multiple templates with override capabilities.
Strata Cloud Manager configuration management is based on:
- Folders — Hierarchical containers that hold both security policies AND network
configurations.
- Snippets — Reusable configuration blocks that can be attached to folders at any
level.
- Containers — Device-specific configuration holders for unique firewall requirements
.
During migration, Strata Cloud Manager converts your Panorama-based
configuration and builds it into folders and snippets:
| Panorama | Strata Cloud Manager |
| Device Groups | Folders |
| Templates & Template Stacks | Snippets |
| Policies and Profiles | Snippets |
| Shared Objects | Global folder as an attached Snippet |
| Policies in Device Groups | Policies under mapped Folder(s) |
| Objects (addresses, EDLs, etc.) | Objects under mapped Folder(s) |
Key difference between Panorama and Strata Cloud Manager to keep in mind:
Strata Cloud Manager Folders contain both network and security
configurations, while Panorama separates these between Templates and Device Groups
Strata Cloud Manager Folders provide more flexible inheritance with
Snippet-based overrides versus the lower-level group overrides seen in Panorama
Strata Cloud Manager Snippets provide a more plug-and-play approach to configurations
compared to Panorama's Templates and Template stacks that are inherited down the
stack.
After migration, you manage configurations through the folder and snippet
model. Snippet attachment order determines configuration precedence, providing granular
control over how multiple configuration sources combine. You can also create
device-specific containers for NGFWs requiring unique configurations outside the folder
inheritance model.