Charles,
Refuse the siren call of the MDS, unless it is truly warranted
It often adds unneeded complexity to the operations and is mostly called for in multi-tenant environments with sufficient administrative personnel.
In R80.XX you have other options of managing distributed environments.
1. A single unified policy across your entire organization:
You can have shared inline layers to impose "Global" rules on the organization's policies:
across all gateways in organization and non-shared layers with installation targets being gateways at each location.
2. Separate policies for each location using shared layers when necessary.
3. Delegate administration of individual policies and/or layers to admins responsible for either each location or subset of layers across organization.
MDS is also called for in the composite organizations running multiple lines of businesses with each mandating the use of independent security domain (CSRC - Glossary - Security Domain ).
In this case, the person or organization managing MDS is NOT the same entity as the one responsible for the management of the DMS' (Domain Management Server(s)) it is running.
Cheers,
Vladimir