28
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Plan
Your
Deployment
Panorama
Overview
group
is
one
that
contains
all
the
firewalls
that
a
Research
and
Development
team
uses.
You
might
also
group
firewalls
by
the
function
they
perform,
such
as
gateway
firewalls,
branch
office
firewalls
or
datacenter
firewalls.
Plan
a
layering
strategy
for
administering
policies.
Think
through
how
policies
must
be
inherited
and
evaluated
and
how
to
best
implement
shared
rules,
device
‐
group
rules,
and
device
‐
specific
rules
to
meet
your
network
needs.
–
For
visibility
and
centralized
policy
management,
consider
using
Panorama
for
administering
policies,
even
if
you
would
like
to
create
device
‐
specific
exceptions
to
shared/device
‐
group
policies.
To
apply
a
rule
to
a
subset
of
devices
in
a
device
group,
you
can
target
the
rule(s)
to
the
specific
device(s),
see
–
Consider
whether
to
create
smaller
device
groups
based
on
commonality
or
to
create
larger
device
groups
to
scale
more
easily.
See
.
Plan
your
device
organization
for
how
configuration
settings
(using
templates)
are
inherited
and
enforced.
For
example,
think
through
how
to
assign
devices
to
templates
based
on
hardware
platforms,
geographic
proximity
and
similar
network
set
up
needs
for
time
zones,
DNS
server,
and
interface
settings.
See
.