<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: address-group limitation in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/address-group-limitation/m-p/44198#M32446</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; OK thanks for your answer!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I'll try using three groups in a rule, and see whether I manage to blow the system &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cya&lt;/P&gt;&lt;P&gt;chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Feb 2012 14:44:21 GMT</pubDate>
    <dc:creator>Wirecard</dc:creator>
    <dc:date>2012-02-14T14:44:21Z</dc:date>
    <item>
      <title>address-group limitation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/address-group-limitation/m-p/44196#M32444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi @all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US" style="mso-ansi-language: EN-US"&gt;we’re using a PA-5020 active-passive Firewall-Cluster. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US" style="mso-ansi-language: EN-US"&gt;We recently noticed that the address-groups are limited to 500 items per group. As we have a list of nearly 1500 items (ip-address and network-addresses) to manage, I want to ask whether there are any performance issues known if we split the items in three or more groups.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 13:45:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/address-group-limitation/m-p/44196#M32444</guid>
      <dc:creator>Wirecard</dc:creator>
      <dc:date>2012-02-14T13:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: address-group limitation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/address-group-limitation/m-p/44197#M32445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Either performance or hardware limitations due to that the addressgroup is "compiled" into a list of actual addresses which is then loaded to the fpga/asics. However 500 as limit sounds to me more of a GUI limit than a true hardware limit (but thats just a feeling I got).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could test this easily by creating another address-group and then try to use both of them in the same security rule (like both of them as sourceip or such). However be prepared to quickly rollback your config in case things go wrong...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 14:00:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/address-group-limitation/m-p/44197#M32445</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-02-14T14:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: address-group limitation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/address-group-limitation/m-p/44198#M32446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; OK thanks for your answer!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I'll try using three groups in a rule, and see whether I manage to blow the system &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cya&lt;/P&gt;&lt;P&gt;chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 14:44:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/address-group-limitation/m-p/44198#M32446</guid>
      <dc:creator>Wirecard</dc:creator>
      <dc:date>2012-02-14T14:44:21Z</dc:date>
    </item>
  </channel>
</rss>

