The Pano DAS communicates with the Pano Manager and Pano devices over certain network ports. If there is a firewall on the DVM, it needs to be configured to allow communication over certain ports for both inbound and outbound traffic. Otherwise, the DVM fails because it cannot communicate with the Pano Manager.
Domain policies have higher precedence than local policies. Therefore, you should not expect local policies that are applied to a DVM template to always be used when new DVMs are cloned from the template. The best strategy is to always use the domain level GPOs.
Remember, GPOs can be applied to an organizational unit (OU) so it is possible to narrow the scope of this Firewall policy to just the collections of DVMs that the Pano Manager manages.