nerdexam
Palo_Alto_Networks

PCNSE · Question #724

A company has recently migrated their branch office's PA-220s to a centralized Panorama. This Panorama manages a number of PA-7000 Series and PA-5200 Series devices. All device group and template…

The correct answer is A. Disable "Share Unused Address and Service Objects with Devices" in Panorama Settings. When Panorama manages a mix of large (PA-7000, PA-5200) and small (PA-220) devices in the same device group, the 'Share Unused Address and Service Objects with Devices' setting causes Panorama to push ALL address and service objects defined in the device group to EVERY managed…

Submitted by brentm· Apr 18, 2026Configuration Troubleshooting

Question

A company has recently migrated their branch office's PA-220s to a centralized Panorama. This Panorama manages a number of PA-7000 Series and PA-5200 Series devices. All device group and template configuration is managed solely within Panorama. They notice that commit times have drastically increased for the PA-220s after the migration. What can they do to reduce commit times?

Options

  • ADisable "Share Unused Address and Service Objects with Devices" in Panorama Settings.
  • BPerform a device group push using the "merge with device candidate config" option.
  • CUpdate the apps and threat version using device-deployment.
  • DUse "export or push device config bundle" to ensure that the firewall is integrated with the

How the community answered

(48 responses)
  • A
    75% (36)
  • B
    6% (3)
  • C
    4% (2)
  • D
    15% (7)

Explanation

When Panorama manages a mix of large (PA-7000, PA-5200) and small (PA-220) devices in the same device group, the 'Share Unused Address and Service Objects with Devices' setting causes Panorama to push ALL address and service objects defined in the device group to EVERY managed device - including the PA-220 - regardless of whether those objects are actually referenced in any policy on that device. The PA-7000 and PA-5200 deployments may have thousands of objects, and pushing all of them to the PA-220 dramatically increases commit time and memory usage. Disabling this setting ensures only objects actually used in policies on a given device are pushed to it, significantly reducing commit overhead on the smaller PA-220 branch firewalls.

Topics

#Panorama Commit Optimization#Configuration Scaling#Shared Objects#Device Group Management

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice