88
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Manage
Device
Groups
Manage
Firewalls
Disabling
this
option
may,
however,
increase
the
commit
time
on
Panorama.
This
is
because
Panorama
has
to
dynamically
check
whether
a
particular
object
is
referenced
in
policy.
Perform
the
following
steps
to
disable
the
sharing
of
unused
address
and
service
objects
to
devices.
Would
like
to
ensure
that
a
shared
object
takes
precedence
over
an
object
that
has
the
same
name
as
a
device
group
object.
By
default,
shared
objects
do
not
override
any
device
group
object
with
the
same
name
as
a
shared
object.
If
you
would
like
to
prevent
overrides
to
objects
that
have
been
defined
as
shared
objects
on
Panorama,
you
can
enable
the
option
for
Shared Objects Take Precedence
.
When
enabled,
all
device
group
objects
with
the
same
name
will
be
discarded
and
the
shared
object
settings
will
be
pushed
to
the
managed
devices.
Perform
the
following
steps
to
ensure
that
shared
objects
always
take
priority
over
device
group
objects.
Select
a
URL
Filtering
Vendor
on
Panorama
URL
Filtering
enables
you
to
configure
firewalls
to
monitor
and
control
web
access
for
your
users.
The
policies
(security,
QoS,
Captive
Portal,
and
decryption)
that
enforce
web
access
rules
reference
URL
categories.
The
URL
filtering
vendor
you
select
on
Panorama
determines
which
URL
categories
are
referenced
in
the
policies
that
you
add
to
device
groups
and
push
to
firewalls.
any
single
device,
Panorama
or
a
firewall,
only
one
URL
Filtering
vendor
can
be
active:
PAN
‐
DB
or
BrightCloud.
To
determine
which
vendor
best
suits
your
needs,
consult
Palo
Alto
Networks
Customer
Service.
When
selecting
a
vendor
for
Panorama,
you
must
consider
the
vendor
and
PAN
‐
OS
version
of
the
managed
firewalls:
PAN
‐
OS
5.0.x
and
earlier
versions—Panorama
and
the
firewalls
require
matching
URL
Filtering
vendors.
PAN
‐
OS
6.0
or
later
versions—Panorama
and
the
firewalls
do
not
require
matching
URL
Filtering
vendors.
If
a
vendor
mismatch
is
detected,
the
firewall
maps
the
URL
categories
in
the
URL
Filtering
profiles
and
policies
that
it
received
from
Panorama
to
categories
that
align
with
those
of
the
vendor
enabled
on
the
firewall.
For
details,
refer
to
the
article
.
Therefore,
for
a
deployment
in
which
some
firewalls
run
PAN
‐
OS
6.0
and
some
firewalls
run
earlier
PAN
‐
OS
versions,
Panorama
must
use
the
same
URL
Filtering
vendor
as
the
firewalls
that
run
earlier
PAN
‐
OS
versions.
For
example,
if
firewalls
that
run
PAN
‐
OS
5.0
use
BrightCloud,
and
firewalls
that
run
PAN
‐
OS
6.0
use
PAN
‐
DB
(or
BrightCloud),
Panorama
must
use
BrightCloud.
Manage
Unused
Shared
Objects
1.
Select
Panorama > Setup > Management
,
and
edit
the
Panorama
Settings.
2.
Clear
the
Share Unused Address and Service Objects with Devices
check
box.
Manage
Precedence
of
Shared
Objects
1.
Select
Panorama > Setup > Management
and
edit
the
Panorama
Settings.
2.
Select
the
Shared Objects Take Precedence
check
box.