<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EDL Capacity Reached but Lists Show Empty / Default Entry (0.0.0.0/32) – Panorama Multi-VSYS Setup  Post: in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/edl-capacity-reached-but-lists-show-empty-default-entry-0-0-0-0/m-p/1253066#M126344</link>
    <description>&lt;P data-end="230" data-start="222"&gt;Hi Everyone,&lt;/P&gt;
&lt;P data-end="389" data-start="232"&gt;I am currently facing an issue with &lt;STRONG data-end="301" data-start="268"&gt;External Dynamic Lists (EDLs)&lt;/STRONG&gt; in a &lt;STRONG data-end="347" data-start="307"&gt;Panorama-managed multi-vsys firewall&lt;/STRONG&gt; setup and would appreciate your guidance.&lt;/P&gt;
&lt;P data-end="404" data-start="391"&gt;&lt;STRONG data-end="404" data-start="391"&gt;Scenario:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-end="625" data-start="405"&gt;
&lt;LI data-end="483" data-start="405" data-section-id="lux7xe"&gt;EDLs are configured on Panorama and pushed to a multi-vsys managed firewall.&lt;/LI&gt;
&lt;LI data-end="567" data-start="484" data-section-id="1ti46yu"&gt;The EDL source URLs are reachable, and the &lt;CODE data-end="535" data-start="529"&gt;.txt&lt;/CODE&gt; files contain valid IP entries.&lt;/LI&gt;
&lt;LI data-end="625" data-start="568" data-section-id="1x2ukro"&gt;The EDLs are correctly referenced in security policies.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="637" data-start="627"&gt;&lt;STRONG data-end="637" data-start="627"&gt;Issue:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-end="881" data-start="638"&gt;
&lt;LI data-end="718" data-start="638" data-section-id="ymijdz"&gt;When attempting to add a new EDL, it is &lt;STRONG data-end="701" data-start="680"&gt;not being fetched&lt;/STRONG&gt; on the firewall.&lt;/LI&gt;
&lt;LI data-end="881" data-start="719" data-section-id="12dutup"&gt;
&lt;P data-end="758" data-start="721"&gt;Upon checking the EDL capacity using:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;request system external-list list-capacities&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="881" data-start="820"&gt;it shows that the &lt;STRONG data-end="880" data-start="838"&gt;IP EDL capacity limit has been reached&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="907" data-start="883"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL data-end="1176" data-start="908"&gt;
&lt;LI data-end="1039" data-start="908" data-section-id="37fca5"&gt;
&lt;P data-end="1014" data-start="910"&gt;When verifying the individual EDL entries, the lists appear &lt;STRONG&gt;to&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;only contain the default entry:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;0.0.0.0/32&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI data-end="1091" data-start="1040" data-section-id="vka67b"&gt;This behavior is consistent across multiple EDLs.&lt;/LI&gt;
&lt;LI data-end="1176" data-start="1092" data-section-id="11jls2k"&gt;Despite this, the firewall still reports that the &lt;STRONG data-end="1175" data-start="1144"&gt;EDL limit is fully utilized&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1205" data-start="1178"&gt;&lt;STRONG data-end="1205" data-start="1178"&gt;What has been verified:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-end="1406" data-start="1206"&gt;
&lt;LI data-end="1250" data-start="1206" data-section-id="1beq075"&gt;EDL URLs are reachable from the firewall.&lt;/LI&gt;
&lt;LI data-end="1354" data-start="1301" data-section-id="v34ha7"&gt;EDLs are actively referenced in security policies.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-end="1422" data-start="1408"&gt;&lt;STRONG data-end="1422" data-start="1408"&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-end="1852" data-start="1423"&gt;
&lt;LI data-end="1552" data-start="1423" data-section-id="1s5gkuv"&gt;Has anyone encountered a situation where EDL capacity is fully consumed, but the lists appear empty or only show &lt;CODE data-end="1551" data-start="1539"&gt;0.0.0.0/32&lt;/CODE&gt;?&lt;/LI&gt;
&lt;LI data-end="1852" data-start="1757" data-section-id="1liixsv"&gt;What would be the best way to accurately validate &lt;STRONG data-end="1851" data-start="1810"&gt;actual EDL usage vs reported capacity&lt;/STRONG&gt;?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-end="1932" data-start="1854"&gt;Any insights or recommended troubleshooting steps would be highly appreciated.&lt;/P&gt;
&lt;P data-end="1955" data-start="1934"&gt;Thank you in advance!&lt;/P&gt;</description>
    <pubDate>Mon, 27 Apr 2026 06:32:16 GMT</pubDate>
    <dc:creator>A.AlHafi</dc:creator>
    <dc:date>2026-04-27T06:32:16Z</dc:date>
    <item>
      <title>EDL Capacity Reached but Lists Show Empty / Default Entry (0.0.0.0/32) – Panorama Multi-VSYS Setup  Post:</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-capacity-reached-but-lists-show-empty-default-entry-0-0-0-0/m-p/1253066#M126344</link>
      <description>&lt;P data-end="230" data-start="222"&gt;Hi Everyone,&lt;/P&gt;
&lt;P data-end="389" data-start="232"&gt;I am currently facing an issue with &lt;STRONG data-end="301" data-start="268"&gt;External Dynamic Lists (EDLs)&lt;/STRONG&gt; in a &lt;STRONG data-end="347" data-start="307"&gt;Panorama-managed multi-vsys firewall&lt;/STRONG&gt; setup and would appreciate your guidance.&lt;/P&gt;
&lt;P data-end="404" data-start="391"&gt;&lt;STRONG data-end="404" data-start="391"&gt;Scenario:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-end="625" data-start="405"&gt;
&lt;LI data-end="483" data-start="405" data-section-id="lux7xe"&gt;EDLs are configured on Panorama and pushed to a multi-vsys managed firewall.&lt;/LI&gt;
&lt;LI data-end="567" data-start="484" data-section-id="1ti46yu"&gt;The EDL source URLs are reachable, and the &lt;CODE data-end="535" data-start="529"&gt;.txt&lt;/CODE&gt; files contain valid IP entries.&lt;/LI&gt;
&lt;LI data-end="625" data-start="568" data-section-id="1x2ukro"&gt;The EDLs are correctly referenced in security policies.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="637" data-start="627"&gt;&lt;STRONG data-end="637" data-start="627"&gt;Issue:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-end="881" data-start="638"&gt;
&lt;LI data-end="718" data-start="638" data-section-id="ymijdz"&gt;When attempting to add a new EDL, it is &lt;STRONG data-end="701" data-start="680"&gt;not being fetched&lt;/STRONG&gt; on the firewall.&lt;/LI&gt;
&lt;LI data-end="881" data-start="719" data-section-id="12dutup"&gt;
&lt;P data-end="758" data-start="721"&gt;Upon checking the EDL capacity using:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;request system external-list list-capacities&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="881" data-start="820"&gt;it shows that the &lt;STRONG data-end="880" data-start="838"&gt;IP EDL capacity limit has been reached&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="907" data-start="883"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL data-end="1176" data-start="908"&gt;
&lt;LI data-end="1039" data-start="908" data-section-id="37fca5"&gt;
&lt;P data-end="1014" data-start="910"&gt;When verifying the individual EDL entries, the lists appear &lt;STRONG&gt;to&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;only contain the default entry:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;0.0.0.0/32&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI data-end="1091" data-start="1040" data-section-id="vka67b"&gt;This behavior is consistent across multiple EDLs.&lt;/LI&gt;
&lt;LI data-end="1176" data-start="1092" data-section-id="11jls2k"&gt;Despite this, the firewall still reports that the &lt;STRONG data-end="1175" data-start="1144"&gt;EDL limit is fully utilized&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1205" data-start="1178"&gt;&lt;STRONG data-end="1205" data-start="1178"&gt;What has been verified:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-end="1406" data-start="1206"&gt;
&lt;LI data-end="1250" data-start="1206" data-section-id="1beq075"&gt;EDL URLs are reachable from the firewall.&lt;/LI&gt;
&lt;LI data-end="1354" data-start="1301" data-section-id="v34ha7"&gt;EDLs are actively referenced in security policies.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-end="1422" data-start="1408"&gt;&lt;STRONG data-end="1422" data-start="1408"&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-end="1852" data-start="1423"&gt;
&lt;LI data-end="1552" data-start="1423" data-section-id="1s5gkuv"&gt;Has anyone encountered a situation where EDL capacity is fully consumed, but the lists appear empty or only show &lt;CODE data-end="1551" data-start="1539"&gt;0.0.0.0/32&lt;/CODE&gt;?&lt;/LI&gt;
&lt;LI data-end="1852" data-start="1757" data-section-id="1liixsv"&gt;What would be the best way to accurately validate &lt;STRONG data-end="1851" data-start="1810"&gt;actual EDL usage vs reported capacity&lt;/STRONG&gt;?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-end="1932" data-start="1854"&gt;Any insights or recommended troubleshooting steps would be highly appreciated.&lt;/P&gt;
&lt;P data-end="1955" data-start="1934"&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 06:32:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-capacity-reached-but-lists-show-empty-default-entry-0-0-0-0/m-p/1253066#M126344</guid>
      <dc:creator>A.AlHafi</dc:creator>
      <dc:date>2026-04-27T06:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: EDL Capacity Reached but Lists Show Empty / Default Entry (0.0.0.0/32) – Panorama Multi-VSYS Setup  Post:</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-capacity-reached-but-lists-show-empty-default-entry-0-0-0-0/m-p/1253119#M126347</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/471036973"&gt;@A.AlHafi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have run into this issue.&amp;nbsp; What I have found is that there is one or more EDLs that reach the max, e.g. 50K IP entries, and then all the other EDLs are blank.&amp;nbsp; In my case the NGFW seemed to populate the EDLs from top to bottom in the configuration.&amp;nbsp; When you commit, you should see the EDL warning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In your case, you don't seem to be able to find the EDLs that consume all the entries.&amp;nbsp; Have you checked all vsys?&amp;nbsp; The EDL limit is per system and not per vsys.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The best way to validate EDL usage is with the command you mentioned, "request system external-list list-capacities".&amp;nbsp; The "Currently used in policy" column has proved accurate for me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 18:26:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-capacity-reached-but-lists-show-empty-default-entry-0-0-0-0/m-p/1253119#M126347</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2026-04-27T18:26:00Z</dc:date>
    </item>
  </channel>
</rss>

