<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About address and EBL limitation for maximum in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/about-address-and-ebl-limitation-for-maximum/m-p/67969#M39749</link>
    <description>&lt;P&gt;Hi there...This is extracted from the 7.0 admin guide. &amp;nbsp;You can have 10 DBL lists.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1134iE849D815652BCBF6/image-size/medium?v=mpbl-1&amp;amp;px=-1" border="0" alt="DBL.JPG" title="DBL.JPG" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Yes, the maximum number of entries (in your case 25,000) is for the entire device, and is shared across the allow list, block list, and custom URL categories.&lt;/P&gt;
&lt;P&gt;3) The DBL is separate from the max address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Nov 2015 21:23:37 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2015-11-11T21:23:37Z</dc:date>
    <item>
      <title>About address and EBL limitation for maximum</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-address-and-ebl-limitation-for-maximum/m-p/67834#M39686</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to know my question what address and EBL maximum from you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Using-IP-Address-Lists-on-Palo-Alto-Networks-Policies/ta-p/57411" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Using-IP-Address-Lists-on-Palo-Alto-Networks-Policies/ta-p/57411&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The above documnet describes&amp;nbsp;"&lt;SPAN&gt; Each imported &lt;/SPAN&gt;&lt;SPAN class="lia-search-match-lithium"&gt;list&lt;/SPAN&gt;&lt;SPAN&gt; can contain up to 5,000 IP addresses (IPv4 and/or IPv6), IP ranges, or subnets."&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How many can FW creat&amp;nbsp;lists? What are Miximum?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I checked the result of the following CLI output,&lt;/P&gt;
&lt;P&gt;show system state filter cfg.general.max*&lt;/P&gt;
&lt;P&gt;-&amp;gt;&lt;SPAN&gt;cfg.general.max-blacklist : 25000&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the above black list about URL Filtering?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found a below discussiton&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Size-limit-for-URL-block-list/m-p/27631/highlight/true#M20144" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Size-limit-for-URL-block-list/m-p/27631/highlight/true#M20144&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This question is important.&lt;/P&gt;
&lt;P&gt;PA-3020 can have miximum 5000 address.&lt;/P&gt;
&lt;P&gt;"&lt;SPAN class="s1"&gt;cfg.general.max-address: 5000"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I want to know whether this vaule inculde EBL list or exclude it.&lt;/P&gt;
&lt;P&gt;And&lt;/P&gt;
&lt;P&gt;PA can make security rules without address objects.&lt;/P&gt;
&lt;P&gt;When FW can create to write IP on security rules, How many can I make IPs without address object?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What are maximum? Are this maximum &amp;nbsp;included "max-address : 5000"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;KC Lee&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 10:17:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-address-and-ebl-limitation-for-maximum/m-p/67834#M39686</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2015-11-09T10:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: About address and EBL limitation for maximum</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-address-and-ebl-limitation-for-maximum/m-p/67969#M39749</link>
      <description>&lt;P&gt;Hi there...This is extracted from the 7.0 admin guide. &amp;nbsp;You can have 10 DBL lists.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1134iE849D815652BCBF6/image-size/medium?v=mpbl-1&amp;amp;px=-1" border="0" alt="DBL.JPG" title="DBL.JPG" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Yes, the maximum number of entries (in your case 25,000) is for the entire device, and is shared across the allow list, block list, and custom URL categories.&lt;/P&gt;
&lt;P&gt;3) The DBL is separate from the max address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 21:23:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-address-and-ebl-limitation-for-maximum/m-p/67969#M39749</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2015-11-11T21:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: About address and EBL limitation for maximum</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-address-and-ebl-limitation-for-maximum/m-p/67991#M39762</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your anwer.&lt;/P&gt;
&lt;P&gt;May I ask you question more further?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;About No.3 question I asked.&lt;/P&gt;
&lt;P&gt;I heard from someone what one DBL list place in one of &amp;nbsp;all address object.&lt;/P&gt;
&lt;P&gt;You meaned one DBL list does not equal one address object. Right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And a new question.&lt;/P&gt;
&lt;P&gt;Please look at the following document.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Using-IP-Address-Lists-on-Palo-Alto-Networks-Policies/ta-p/57411" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Using-IP-Address-Lists-on-Palo-Alto-Networks-Policies/ta-p/57411&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This doc describes "&lt;SPAN&gt; Each imported &lt;/SPAN&gt;&lt;SPAN class="lia-search-match-lithium"&gt;list&lt;/SPAN&gt;&lt;SPAN&gt; can contain up to &lt;/SPAN&gt;&lt;SPAN class="lia-search-match-lithium"&gt;5,000&lt;/SPAN&gt;&lt;SPAN&gt; IP addresses (IPv4 and/or IPv6), IP ranges, or subnets."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But It is different between the above sentence and a result I tested.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PA-200 can have 2200 lines of one DBL list [2500(max addresses) - 300(system register IPs)]&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PA-3020 can have 4700 lines of one DBL list&amp;nbsp;&lt;SPAN&gt;[5000(max addresses) - 300(system register IPs)]&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;What is the truth between all platform can have 5,000 or each models can have each other mas address without 300?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope let me know it.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 01:12:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-address-and-ebl-limitation-for-maximum/m-p/67991#M39762</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2015-11-12T01:12:04Z</dc:date>
    </item>
  </channel>
</rss>

