In Panorama, Device Groups serve as the primary containers for managing configurations that define *what* traffic is allowed or denied and *how* it should be inspected. Unlike Templates (which handle Network/Device settings), Device Groups focus on:
Device Groups enable administrators to apply consistent policies and related objects to logical groupings of firewalls (e.g., based on location, function, risk level) and leverage hierarchies for efficient policy inheritance.
When configuring a Device Group in Panorama (or the Shared scope), you primarily manage settings corresponding to the Policies and Objects tabs of a firewall's configuration.
This is where you define the rules governing traffic flow and security actions:
Remember the Pre/Post rule structure within each policy type allows for control over evaluation order relative to inherited rules and local firewall rules.
This is where you define the reusable building blocks referenced by your policy rules:
It's essential to remember the division of responsibilities:
Think of Device Groups for "what traffic to allow/inspect and how" (Policies & Objects) and Templates for "how the firewall connects to the network and operates" (Network & Device).
For the PCNSE exam, be able to identify:
1. Which two main configuration tabs from a firewall's perspective are primarily managed within Panorama Device Groups? (Select TWO)
2. Which of the following is configured within a Panorama Device Group?
3. Which of the following is configured within a Panorama Template, NOT a Device Group?
4. Where would you define an Antivirus Security Profile in Panorama?
5. Policy Based Forwarding (PBF) rules are configured under which Panorama component?
6. Where are Address Objects (defining specific IP addresses or networks) typically created in Panorama?
7. Which setting would you configure in a Template?
8. Decryption Policy rules are managed within:
9. Which item IS typically configured within a Device Group?
10. The definition of the QoS Classes (1-8) and their associated bandwidth limits (Guaranteed/Max) for an interface is configured where?