<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EDL Limit in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1231245#M5967</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222359"&gt;@Mitesh_Nandu&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I don't have an answer to your question regarding how PAN-OS handles reaching the object limit for an EDL, but I have to question if a 50,000 object EDL is actually being used efficiently. Do you actually utilize an EDL that&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;needs&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;to be 50,000 objects that couldn't be condensed into ranges to help cut back on the object count (IE: do you aggregate and dedupe them?) Do you just keep every single address you've identified ever in the EDL without aging anything out?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you detail what these are actually being used for a bit more maybe collectively we would have some ideas to help you live within the limitation, or as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;pointed out your business requirements may just simply mandate that the 3420 wasn't a good fit and maybe your EDL usage needed a 5420 where you could have 150,000.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;150,000 addresses really is the max regardless of platform as far as I'm aware however and I'm slightly concerned that you may essentially have 150,000 entries based off of your questioning. That is a big reason why I would maybe work on either trimming that down or putting something simple like an IP blocklist on your router(s) upstream from your actual firewall.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 07 Jun 2025 04:52:11 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2025-06-07T04:52:11Z</dc:date>
    <item>
      <title>EDL Limit</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1230472#M5945</link>
      <description>&lt;P&gt;How we can increase the External Dynamic List (EDL) max IP limit ?&lt;/P&gt;
&lt;P&gt;For example: PA 3420 has 50,000 IP limit, how we can increase this limit in EDL ?&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 03:03:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1230472#M5945</guid>
      <dc:creator>Mitesh_Nandu</dc:creator>
      <dc:date>2025-05-30T03:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: EDL Limit</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1230475#M5947</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222359"&gt;@Mitesh_Nandu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDL limits are platform based so you can't increase the limit however&amp;nbsp; you can review your eld list and optimise it as per your requirement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/products/product-selection" target="_blank"&gt;https://www.paloaltonetworks.com/products/product-selection&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 04:01:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1230475#M5947</guid>
      <dc:creator>mshekh</dc:creator>
      <dc:date>2025-05-30T04:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: EDL Limit</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1230702#M5950</link>
      <description>&lt;P&gt;since these linits ar edetermined by the hardware, the only solution is "buy a bigger box' &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 14:10:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1230702#M5950</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-06-02T14:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: EDL Limit</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1231131#M5962</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195187"&gt;@mshekh&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp; for reply....&lt;/P&gt;
&lt;P&gt;Want to understand EDL working.&lt;/P&gt;
&lt;P&gt;In our environment we are having 3 custom edl url IP list, in each url IP list having 50000 IP entries. In this scenario what will happens ?&lt;/P&gt;
&lt;P&gt;Will PA only read custom list 1 &amp;amp; block all the IPs in that list or PA will read all the custom list &amp;amp; block any 50000 IPs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2025 00:41:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1231131#M5962</guid>
      <dc:creator>Mitesh_Nandu</dc:creator>
      <dc:date>2025-06-06T00:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: EDL Limit</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1231132#M5963</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195187"&gt;@mshekh&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp; for reply....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Want to understand EDL working.&lt;/P&gt;
&lt;P&gt;In our environment we are having 3 custom edl url IP list, in each url IP list having 50000 IP entries. In this scenario what will happens ?&lt;/P&gt;
&lt;P&gt;Will PA only read custom list 1 &amp;amp; block all the IPs in that list or PA will read all the custom list &amp;amp; block any 50000 IPs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2025 00:41:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1231132#M5963</guid>
      <dc:creator>Mitesh_Nandu</dc:creator>
      <dc:date>2025-06-06T00:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: EDL Limit</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1231232#M5965</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;That is a lot of entries. What are you attempting to achieve? Use the Regions in the security policies to allow/block certain countries. However playing IP whack a mole is futile.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2025 18:19:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1231232#M5965</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-06-06T18:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: EDL Limit</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1231245#M5967</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222359"&gt;@Mitesh_Nandu&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I don't have an answer to your question regarding how PAN-OS handles reaching the object limit for an EDL, but I have to question if a 50,000 object EDL is actually being used efficiently. Do you actually utilize an EDL that&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;needs&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;to be 50,000 objects that couldn't be condensed into ranges to help cut back on the object count (IE: do you aggregate and dedupe them?) Do you just keep every single address you've identified ever in the EDL without aging anything out?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you detail what these are actually being used for a bit more maybe collectively we would have some ideas to help you live within the limitation, or as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;pointed out your business requirements may just simply mandate that the 3420 wasn't a good fit and maybe your EDL usage needed a 5420 where you could have 150,000.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;150,000 addresses really is the max regardless of platform as far as I'm aware however and I'm slightly concerned that you may essentially have 150,000 entries based off of your questioning. That is a big reason why I would maybe work on either trimming that down or putting something simple like an IP blocklist on your router(s) upstream from your actual firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jun 2025 04:52:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1231245#M5967</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-06-07T04:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: EDL Limit</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1232276#M6005</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the valuable input.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDL limit for 3420 has been increased from 50000 to 150000.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we run the below command in appliance output was showing 150000, Palo Alto document is not updated.&lt;/P&gt;
&lt;PRE class="ckeditor_codeblock"&gt;show system state | match max-edl&lt;/PRE&gt;</description>
      <pubDate>Sun, 22 Jun 2025 15:51:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-limit/m-p/1232276#M6005</guid>
      <dc:creator>Mitesh_Nandu</dc:creator>
      <dc:date>2025-06-22T15:51:12Z</dc:date>
    </item>
  </channel>
</rss>

