©
Palo
Alto
Networks,
Inc.
Panorama
6.1
Administrator’s
Guide
•
87
Manage
Firewalls
Manage
Device
Groups
Manage
Shared
Objects
You
can
configure
how
Panorama
handles
shared
objects.
Consider
whether
you:
Would
like
to
configure
Panorama
to
push only
shared
objects
that
are
referenced
either
in
shared
policies
or
device
group
policies
to
the
managed
device.
For
example,
say
all
objects
in
your
deployment
are
defined
as
shared
objects,
but
you
would
like
to
push
only
the
relevant
objects
for
each
device
group.
The
Share Unused Address and Service Objects
check
box
enables
you
to
limit
the
objects
that
Panorama
pushes
to
the
managed
devices.
By
default,
Panorama
pushes
all
shared
objects
(used
and
unused)
to
the
managed
devices.
On
lower
‐
end
platforms,
such
as
the
PA
‐
200,
consider
pushing
only
the
relevant
shared
objects
to
the
managed
devices.
This
is
because
the
number
of
objects
that
can
be
stored
on
the
lower
‐
end
platforms
is
considerably
lower
than
that
of
the
mid
‐
to
high
‐
end
platforms.
Also,
if
you
have
many
address
and
service
objects
that
are
unused,
clearing
the
Share Unused Address and Service Objects
check
box
reduces
the
commit
times
significantly
on
the
devices
because
the
configuration
pushed
to
each
device
is
smaller.
•
Create
a
device
group
object.
In
this
example,
we
will
add
a
device
group
object
for
specific
web
servers
on
your
network.
1.
Select
the
Device
Group
for
which
you
plan
to
use
this
object
in
the
Device Group
drop
‐
down.
2.
Select
the
Objects > Addresses
tab
.
3.
Select
Address
and
click
Add
.
4.
Verify
that
the
Shared
check
box
is
not
selected.
5.
Enter
a
Name
,
a
Description
,
and
select
the
Type
of
address
object
from
the
drop
‐
down.
For
example,
select
IP Range
and
include
the
IP
address
range
for
the
web
servers
for
which
you
would
like
to
create
an
address
object.
6.
Click
OK
.
7.
Commit
your
changes.
a.
Click
Commit
,
and
select
Panorama
as
the
Commit Type
.
This
saves
the
changes
to
the
running
configuration
on
Panorama.
b.
Click
Commit
,
and
select
Device Group
as
the
Commit
Type
.
This
pushes
the
changes
to
the
devices
included
in
the
Device
Group.
•
View
shared
objects
and
device
group
objects
in
Panorama.
To
demonstrate
the
difference
between
a
shared
object
and
a
device
group
object,
the
following
screenshot
includes
a
shared
address
object
that
was
created
on
Panorama.
The
Location
column
in
the
Objects
tab
displays
whether
an
object
is
shared
or
is
specific
to
a
device
group.
1.
Select
the
device
group,
for
which
you
just
created
a
device
group
object,
in
the
Device Group
drop
‐
down.
2.
Select
the
Objects > Addresses
tab
and
verify
that
the
device
group
object
displays;
note
that
the
device
group
name
in
the
Location
column
matches
the
selection
in
the
Device Group
drop
‐
down.
If
a
different
device
group
is
selected
in
the
Device
Group
drop
‐
down,
only
the
device
group
objects
(and
shared
objects)
created
for
the
selected
device
group
will
display.
Create
Objects
for
Use
in
Shared
or
Device
Group
Policy
(Continued)