After linking your Cloud NGFW resource to the Panorama virtual appliance you can
start using the integration for policy management tasks, such as adding device
groups and applying policy rules to the device group.
With Panorama, you group firewalls in your network into logical units called
device groups. A device group enables grouping based on
network segmentation, geographic location, organizational function, or any other
common aspect of firewalls requiring similar policy configurations.
Using device groups, you can configure policy rules and the objects they
reference. Organize device groups hierarchically, with shared rules and objects
at the top, and device group-specific rules and objects at subsequent levels.
This enables you to create a hierarchy of rules that enforce how firewalls
handle traffic.
To add a cloud device group using the Panorama console: