<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Determine configuration size on Palo Devices in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/223700#M64311</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34190"&gt;@dwmaas&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;mentioned the size of the configuration only effects the performance of the management process, as there is more information for it to process when doing certain actions such as the validate process. If the device is crashing when you do a commit, it sounds like the validate process is simply failing to process that large of a configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;mentioned this would be a really good time to go through and look for unused objects, object groups, firewall rules, old admin accounts, and all the like to attempt to actually give the validation process a chance to breath.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you say 100m what exactly are you referencing here? I'm assuming megabytes and not millions of lines?&amp;nbsp;Either way I have to assume that you have large amounts of rules or objects that aren't being utilized. I mean, we're talking about an XML file, it's not like those take up a lot of space. Regardless if your talking about megabytes or millions of lines of configuration you'd still have&amp;nbsp;&lt;EM&gt;millions&lt;/EM&gt; of lines of configuration to get a file that large, which to avoid crossing platform limitations I would have to imagine you have a large part of that disabled or unused.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jul 2018 16:57:42 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-07-26T16:57:42Z</dc:date>
    <item>
      <title>Determine configuration size on Palo Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/223685#M64305</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;How can we determine the configuraiton file size on Palo Alto PA devices.&lt;/P&gt;&lt;P&gt;We wish to determine were our configuraiton size is compared to the recommened size for each PA type 5K 7k etc.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 15:53:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/223685#M64305</guid>
      <dc:creator>dwmaas</dc:creator>
      <dc:date>2018-07-26T15:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Determine configuration size on Palo Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/223693#M64306</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34190"&gt;@dwmaas&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Where did you read something about a "recommended configuration file size"?&lt;/P&gt;&lt;P&gt;I don't think there is such a value. There are maximum values for objects and rules where if you reach such a max you should keep an eye on the cpu. If you have 65000 security policy rules on a PA-7050 your configuration file probably is pretty big, but the platform is theoretically made for that and (for whatever reason) 55000 rules could be disabled then the configuration is still big but this shouldn't have any impact on anything as the firewall only has to check 10000 rules for new connections. The same with objects. If you have configured 160000 objects on a 7050 but you use only a small part this does not mean a lot.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 16:22:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/223693#M64306</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-26T16:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Determine configuration size on Palo Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/223695#M64307</link>
      <description>&lt;P&gt;We were told my our Palo Alto Team that there are recommended config file size, and we have proven that going over that to much has performance impacts. We were told 35m for 5060, and 40m for 7050.&lt;/P&gt;&lt;P&gt;We had one that was almost 100m, and we experience management performance issues, with the mgmt service would crash anytime a push was done, and even on its own. Were were forced to move vsys off and increase our footprint of devices.&lt;/P&gt;&lt;P&gt;We are back to needed to know were we stand now, to make any further recommendations to leadership, or to move to another solution. I prefer we stick with Palo I am an advocate and love them myself.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 16:28:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/223695#M64307</guid>
      <dc:creator>dwmaas</dc:creator>
      <dc:date>2018-07-26T16:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Determine configuration size on Palo Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/223697#M64309</link>
      <description>&lt;P&gt;Ok, yes from a management process/cpu perspective, this could have impacts. But if the process crashes this sounds more like a bug to me.&lt;/P&gt;&lt;P&gt;Anyway, do you have a lot of unused objects or disaabled firewallrules that you no longer need?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 16:36:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/223697#M64309</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-26T16:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Determine configuration size on Palo Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/223700#M64311</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34190"&gt;@dwmaas&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;mentioned the size of the configuration only effects the performance of the management process, as there is more information for it to process when doing certain actions such as the validate process. If the device is crashing when you do a commit, it sounds like the validate process is simply failing to process that large of a configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;mentioned this would be a really good time to go through and look for unused objects, object groups, firewall rules, old admin accounts, and all the like to attempt to actually give the validation process a chance to breath.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you say 100m what exactly are you referencing here? I'm assuming megabytes and not millions of lines?&amp;nbsp;Either way I have to assume that you have large amounts of rules or objects that aren't being utilized. I mean, we're talking about an XML file, it's not like those take up a lot of space. Regardless if your talking about megabytes or millions of lines of configuration you'd still have&amp;nbsp;&lt;EM&gt;millions&lt;/EM&gt; of lines of configuration to get a file that large, which to avoid crossing platform limitations I would have to imagine you have a large part of that disabled or unused.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 16:57:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/223700#M64311</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-26T16:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Determine configuration size on Palo Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/224563#M64465</link>
      <description>&lt;P&gt;yes, megabytes, and found the way to get the apprx size&lt;/P&gt;&lt;P&gt;download and expand techsupport file and go to&amp;nbsp;&lt;STRONG&gt;opt\pancfg\mgmt\saved-configs and look for the merged file.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 12:28:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/224563#M64465</guid>
      <dc:creator>dwmaas</dc:creator>
      <dc:date>2018-08-02T12:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Determine configuration size on Palo Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/556344#M112949</link>
      <description>&lt;P&gt;You can check the current size by following this KB:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlF4CAI&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlF4CAI&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2023 06:55:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/determine-configuration-size-on-palo-devices/m-p/556344#M112949</guid>
      <dc:creator>begilmore</dc:creator>
      <dc:date>2023-09-04T06:55:05Z</dc:date>
    </item>
  </channel>
</rss>

