©
Palo
Alto
Networks,
Inc.
Panorama
6.1
Administrator’s
Guide
•
93
Manage
Firewalls
Manage
Templates
Manage
Templates
Panorama
Templates
allow
you
manage
the
configuration
options
on
the
Device
and
Network
tabs
on
the
managed
firewalls.
Using
templates
you
can
define
a
base
configuration
for
centrally
staging
new
firewalls
and
then
make
device
‐
specific
exceptions
in
configuration,
if
required.
For
example,
you
can
use
templates
to
define
administrative
access
to
the
device,
set
up
User
‐
ID,
manage
certificates,
set
up
the
firewalls
in
a
high
availability
pair,
define
log
settings,
and
define
server
profiles
on
the
managed
firewalls.
When
creating
templates,
make
sure
to
assign
similar
devices
to
a
template.
For
example,
group
devices
with
a
single
virtual
system
in
a
one
template
and
devices
enabled
for
multiple
virtual
systems
in
another
template,
or
group
devices
that
require
very
similar
network
interface
and
zone
configuration
in
a
template.
The
following
topics
provide
more
information
on
working
with
templates:
Template
Capabilities
and
Exceptions
Panorama
templates
have
the
following
capabilities
and
exceptions,
depending
on
the
PAN
‐
OS
release
running
on
the
managed
firewalls:
To
delete/remove
a
template,
you
must
first
on
the
managed
firewall
locally.
Firewall
PAN
‐
OS
Release Template
Capabilities
and
Exceptions
PAN
‐
OS
4.x
You
can
use
Panorama
templates
only
for
the
following
tasks:
•
Create
response
pages
•
Define
authentication
profiles
and
sequences
•
Create
self
‐
signed
certificates
on
Panorama
or
import
certificates
•
Create
client
authentication
certificates
(known
as
Certificate
Profiles
in
Panorama
5.0
and
later)
•
Create
server
profiles:
SNMP
Trap,
Syslog,
Email,
NetFlow,
RADIUS,
LDAP,
and
Kerberos