PCNSE · Question #724
A company has recently migrated their branch office's PA-220s to a centralized Panorama. This Panorama manages a number of PA-7000 Series and PA-5200 Series devices. All device group and template…
The correct answer is A. Disable "Share Unused Address and Service Objects with Devices" in Panorama Settings. When Panorama manages a mix of large (PA-7000, PA-5200) and small (PA-220) devices in the same device group, the 'Share Unused Address and Service Objects with Devices' setting causes Panorama to push ALL address and service objects defined in the device group to EVERY managed…
Question
A company has recently migrated their branch office's PA-220s to a centralized Panorama. This Panorama manages a number of PA-7000 Series and PA-5200 Series devices. All device group and template configuration is managed solely within Panorama. They notice that commit times have drastically increased for the PA-220s after the migration. What can they do to reduce commit times?
Options
- ADisable "Share Unused Address and Service Objects with Devices" in Panorama Settings.
- BPerform a device group push using the "merge with device candidate config" option.
- CUpdate the apps and threat version using device-deployment.
- DUse "export or push device config bundle" to ensure that the firewall is integrated with the
How the community answered
(48 responses)- A75% (36)
- B6% (3)
- C4% (2)
- D15% (7)
Explanation
When Panorama manages a mix of large (PA-7000, PA-5200) and small (PA-220) devices in the same device group, the 'Share Unused Address and Service Objects with Devices' setting causes Panorama to push ALL address and service objects defined in the device group to EVERY managed device - including the PA-220 - regardless of whether those objects are actually referenced in any policy on that device. The PA-7000 and PA-5200 deployments may have thousands of objects, and pushing all of them to the PA-220 dramatically increases commit time and memory usage. Disabling this setting ensures only objects actually used in policies on a given device are pushed to it, significantly reducing commit overhead on the smaller PA-220 branch firewalls.
Topics
Community Discussion
No community discussion yet for this question.