Once you have established your Panorama management server and created your Device Group hierarchy (for managing Policies and Objects) and potentially Template Stacks (for managing Network and Device settings), the next crucial step is to assign your managed firewalls to the appropriate Device Group and Template Stack.
This assignment determines:
Proper assignment ensures firewalls receive the correct, consistent configurations based on their role, location, or function within the organization.
A firewall can belong to only one Device Group and be assigned only one Template Stack at any given time.
When initially adding a firewall to be managed by Panorama:
Panorama > Managed Devices > Summary
and click
Add
. Enter the serial number of the firewall you want to manage.
Assign Device Group and Template
button (or similar wording depending on version).
It's common practice to assign newly managed firewalls to a dedicated "staging" or "onboarding" Device Group and Template Stack initially, push a basic configuration, verify connectivity, and then move them to their final production Device Group/Stack.
You may need to move a firewall from one Device Group to another if its role or location changes.
Panorama > Managed Devices > Summary
. Select the checkbox next to the firewall you want to move.
Assign Device Group and Template
button.
Caveat: Moving a firewall between Device Groups can result in a significant configuration change being pushed, as the firewall will inherit a different set of policies, objects, and potentially template settings. This should be done during a planned maintenance window and thoroughly tested afterward.
While you can assign a stack when adding/moving a device, the primary association between a Device Group and its configuration baseline (Templates) is made by assigning a Template Stack directly to the Device Group. This ensures that all firewalls added to that Device Group will automatically inherit the settings from that specific Template Stack.
Panorama > Device Groups
and click on the name of the Device Group you want to configure.
This method ensures all firewalls within a given Device Group receive the same baseline Network and Device configuration defined by the assigned Template Stack.
For the PCNSE exam, understand:
1. What is the primary purpose of assigning a firewall to a Panorama Device Group?
2. How many Device Groups can a single firewall belong to simultaneously in Panorama?
3. When initially adding a new firewall's serial number to Panorama, where is this action typically performed?
Panorama > Managed Devices > Summary
to begin the management process.
4. After assigning a firewall to a new Device Group in Panorama, what is the essential next step to apply the new policy set to the firewall?
5. What is a recommended practice when onboarding a new firewall to Panorama before placing it into its final production Device Group?
6. What is a significant risk when moving a firewall from one Device Group to another?
7. How does assigning a Template Stack directly to a Device Group affect firewalls in that group?
8. If a firewall is assigned to Device Group "DG-Branch" and "DG-Branch" has "Stack-Branch" assigned to it, what configuration does the firewall primarily receive?
9. Which of the following is a key best practice when assigning firewalls to Device Groups?
10. What happens to most local configurations on a firewall when a configuration is pushed from Panorama after assignment to a Device Group/Template Stack?
11. True or False: A firewall can be assigned to multiple Template Stacks simultaneously to layer Network/Device settings.
12. After changing a firewall's Device Group assignment in Panorama > Managed Devices, which targets should you typically select during the "Commit and Push" operation to apply the changes?
13. If a Template Stack "Stack-A" is assigned to "DeviceGroup-A", and firewall FW1 is moved from "DeviceGroup-B" (which used "Stack-B") to "DeviceGroup-A", what happens to FW1's Network/Device settings after a successful commit and push?
14. What is the main reason for minimizing device-level Template Stack overrides and primarily assigning stacks at the Device Group level?
15. Before moving a firewall to a new Device Group with a different Template Stack, what is a crucial best practice?
16. Where in Panorama would you typically navigate to assign a specific Template Stack as the default for all firewalls that will be added to "DeviceGroup-X"?
Panorama > Device Groups
, then selecting the specific Device Group.
17. What is a primary consequence of assigning a firewall to the wrong Device Group?
18. If a firewall is in DeviceGroup-A, which is assigned Stack-A, but the firewall itself has a device-level assignment to Stack-B, which Template Stack's Network/Device settings will be applied to the firewall after a push?
19. From a PCNSE exam perspective, assigning a firewall to a Device Group primarily determines its:
20. What is the consequence of only committing to Panorama after assigning a device to a new Device Group, without performing a "Commit and Push"?