<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PA-4000 Security and NAT &amp;quot;add rule&amp;quot; configuration limit in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37848#M27697</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there information on Security and NAT "add rule" configuration limitations for the PA-4000 series?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Feb 2010 20:58:36 GMT</pubDate>
    <dc:creator>twhite</dc:creator>
    <dc:date>2010-02-25T20:58:36Z</dc:date>
    <item>
      <title>PA-4000 Security and NAT "add rule" configuration limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37848#M27697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there information on Security and NAT "add rule" configuration limitations for the PA-4000 series?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Feb 2010 20:58:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37848#M27697</guid>
      <dc:creator>twhite</dc:creator>
      <dc:date>2010-02-25T20:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: PA-4000 Security and NAT "add rule" configuration limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37849#M27698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;4020&lt;/P&gt;&lt;P&gt;Total NAT rules: 1000 (max of 200 dynamic IP/port rules)&lt;/P&gt;&lt;P&gt;Security rules: 10000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4050/4060&lt;/P&gt;&lt;P&gt;Total NAT rules: 4000 (max of 200 dynamic IP/port rules and 2000 dynamic IP rules)&lt;/P&gt;&lt;P&gt;Security rules: 20000&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Feb 2010 21:45:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37849#M27698</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-02-25T21:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: PA-4000 Security and NAT "add rule" configuration limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37850#M27699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do you know the max rules on the rest of the Policy categories i.e. SSL decryption, App Override, QOS, and Captive Portal?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 13:52:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37850#M27699</guid>
      <dc:creator>twhite</dc:creator>
      <dc:date>2010-02-26T13:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: PA-4000 Security and NAT "add rule" configuration limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37851#M27700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a CLI command you can run on a device to print out the system limits:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show system state filter cfg.general.max*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some of the output is cryptic but hopefully the common ones are easily identifiable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 16:45:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37851#M27700</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-02-26T16:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: PA-4000 Security and NAT "add rule" configuration limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37852#M27701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some questions.&lt;/P&gt;&lt;P&gt;1/ Is the number of dynamic ip/port rules limited to 200 on 2.1.x too?&lt;/P&gt;&lt;P&gt;2/ Why is the limit defined?&lt;/P&gt;&lt;P&gt;3/ Will does the number of dynamic-ip/port rules increase?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;&amp;gt;4020&lt;/P&gt;&lt;P&gt;&amp;gt;Total NAT rules: 1000 (max of 200 dynamic IP/port rules)&lt;/P&gt;&lt;P&gt;&amp;gt;Security rules: 10000&lt;/P&gt;&lt;P style="padding: 0px; min-height: 8pt; height: 8pt;"&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;gt;4050/4060&lt;/P&gt;&lt;P&gt;&amp;gt;Total NAT rules: 4000 (max of 200 dynamic IP/port rules and 2000 dynamic IP rules)&lt;/P&gt;&lt;P&gt;&amp;gt;Security rules: 20000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tomoyuki Komure&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Mar 2010 04:32:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37852#M27701</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-03-02T04:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: PA-4000 Security and NAT "add rule" configuration limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37853#M27702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. Not sure. The same command mentioned earlier should allow you to check that.&lt;/P&gt;&lt;P&gt;2. Each rule consumes resources.&lt;/P&gt;&lt;P&gt;3. We are considering increasing this limit in future releases.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Mar 2010 06:51:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37853#M27702</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-03-02T06:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: PA-4000 Security and NAT "add rule" configuration limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37854#M27703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a same scenario with the 5000 platform.&lt;/P&gt;&lt;P&gt;Can you please give me the details for the limitations:&lt;/P&gt;&lt;P&gt;Error: Number of dynamic-ip-and-port rules (401) exceeds vsys capacity (400)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the command above gives us a general perception of max limitations on box.&lt;/P&gt;&lt;P&gt;For NAT this is what I see,&lt;/P&gt;&lt;P&gt;cfg.general.max-nat-policy-rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Samshodh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2012 13:03:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-4000-security-and-nat-quot-add-rule-quot-configuration-limit/m-p/37854#M27703</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2012-04-16T13:03:52Z</dc:date>
    </item>
  </channel>
</rss>

