Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsMedium

A large enterprise uses Panorama to manage hundreds of Palo Alto Networks firewalls across various geographical locations. The security team needs to apply a consistent set of URL filtering policies to all firewalls in the 'Branch-Office' device group, but allow specific regional exceptions for certain URL categories. How should this be configured in Panorama?

  1. ACreate a URL Filtering profile at the Panorama 'Template' level and link it to the firewalls.
  2. BCreate a shared URL Filtering profile at the Panorama 'Shared' location, then override it locally on firewalls.
  3. CCreate a URL Filtering profile within the 'Branch-Office' device group, and allow overrides at a lower device group or firewall level.
  4. DCreate a URL Filtering profile directly on each firewall and push it from Panorama.
Show answer & explanation

Correct answer: C. Create a URL Filtering profile within the 'Branch-Office' device group, and allow overrides at a lower device group or firewall level.

To apply a consistent policy to a group of firewalls while allowing exceptions, the best practice is to configure the base policy at the appropriate device group level (e.g., 'Branch-Office'). Policies defined at a device group level can then be overridden or supplemented by policies defined at lower device group levels or directly on individual firewalls, providing the desired flexibility and hierarchy.

Why the other options are wrong

  • A. Templates are primarily for network and device settings (e.g., interfaces, zones, virtual routers), not for security policies like URL filtering profiles, which are managed within device groups.
  • B. While 'Shared' policies can be overridden, creating it directly within the relevant device group ('Branch-Office') is more granular and aligns with the organizational structure, allowing overrides at a lower level if necessary.
  • D. Configuring on each firewall directly defeats the purpose of centralized management with Panorama and consistency.

Panorama Device Group Hierarchy

Panorama's device group hierarchy allows administrators to apply consistent configurations and policies to groups of firewalls, with the flexibility to define more specific policies or overrides at lower levels of the hierarchy.

  • Policies inherit from higher device groups.
  • Lower device groups or individual firewalls can override or add to inherited policies.
  • Enables centralized management with localized flexibility.

Memory trick: Policies flow down the family tree, but local branches can add their own leaves.

More Core Concepts questions