<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Group limits on firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-limits-on-firewall/m-p/510548#M106216</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;A relatively old post perhaps. But I'm having a bit of a challenge understanding the limitations properly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So we have a firewall (and a panorma). We'd like to configure our firewall to use (A)AD and user groups in policies and autorisations like portals and gateways.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First the firewall needs to understand where it can get AD group information? So it will query AD for groups? It will receive more groups back than 1000 (which is not a lot) and fail enumeration?&lt;BR /&gt;What happens if we narrow down the location in active directory by specifying a location to enumerate? And this contains &amp;lt;1000 groups by itself. However these groups here are filled with groups themselves (nesting). How does that count toward this limit?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a difference in PAN-OS version that may have increased the limits? Or do we really need to work with multiple locations (which is also limited) to create a situation where the firewall is actually capable of obtaining everything it needs to, to be able to do its work ?&lt;/P&gt;</description>
    <pubDate>Tue, 02 Aug 2022 10:11:19 GMT</pubDate>
    <dc:creator>Klaverblad</dc:creator>
    <dc:date>2022-08-02T10:11:19Z</dc:date>
    <item>
      <title>User Group limits on firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-limits-on-firewall/m-p/395919#M91317</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently I got error below on PA 850 device(8.1.13)&lt;/P&gt;&lt;P&gt;-User Group count of 1098 exceeds threshold of 1000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The log is straight forward, number of group is exceeding the limit, but I have some question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I have one more device,PA-3220, which look same LDAP for group mapping(same configuration).&lt;/P&gt;&lt;P&gt;I found article about this and it says FW has limitation for user group above 8.x and it's on all FW.&lt;/P&gt;&lt;P&gt;But there is no same log on 3220, even it has same number of group,1098.&lt;/P&gt;&lt;P&gt;Is the limit different via devices?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The log says number of group exceeding the limit, but FW still holds over 1000 user group.&lt;/P&gt;&lt;P&gt;active)&amp;gt; show user group list | match Total&lt;BR /&gt;Total: 1098&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this log just alert? I don't know how FW can hold more than 1000 group if there is limit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 04:25:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-limits-on-firewall/m-p/395919#M91317</guid>
      <dc:creator>yhlee1</dc:creator>
      <dc:date>2021-04-06T04:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: User Group limits on firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-limits-on-firewall/m-p/395961#M91324</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/103730"&gt;@yhlee1&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, each platform has its own limits.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can make the comparison on this page:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/products/product-comparison?chosen=pa-3220,pa-850" target="_blank"&gt;https://www.paloaltonetworks.com/products/product-comparison?chosen=pa-3220,pa-850&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this particular example you'll notice that the PA-850 can have 1000 active and unique groups in policy, compared to the PA-3220 which can have 10,000 (aggregate of LDAP groups, dynamic user groups and XML API groups).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Apr 2021 08:32:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-limits-on-firewall/m-p/395961#M91324</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-04-06T08:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: User Group limits on firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-limits-on-firewall/m-p/510548#M106216</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;A relatively old post perhaps. But I'm having a bit of a challenge understanding the limitations properly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So we have a firewall (and a panorma). We'd like to configure our firewall to use (A)AD and user groups in policies and autorisations like portals and gateways.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First the firewall needs to understand where it can get AD group information? So it will query AD for groups? It will receive more groups back than 1000 (which is not a lot) and fail enumeration?&lt;BR /&gt;What happens if we narrow down the location in active directory by specifying a location to enumerate? And this contains &amp;lt;1000 groups by itself. However these groups here are filled with groups themselves (nesting). How does that count toward this limit?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a difference in PAN-OS version that may have increased the limits? Or do we really need to work with multiple locations (which is also limited) to create a situation where the firewall is actually capable of obtaining everything it needs to, to be able to do its work ?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2022 10:11:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-limits-on-firewall/m-p/510548#M106216</guid>
      <dc:creator>Klaverblad</dc:creator>
      <dc:date>2022-08-02T10:11:19Z</dc:date>
    </item>
  </channel>
</rss>

