<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Group Count exceeds threshold - PANORAMA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/381874#M89782</link>
    <description>&lt;P&gt;Did you set a master device in the Device Group?&lt;/P&gt;&lt;P&gt;a device group has a master device from which the user-id information is collected&lt;/P&gt;&lt;P&gt;if you set it to none it might be grabbing the info from all members or i you've set all firewalls in different groups, then they're all polled for 'their group's information)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jan 2021 08:16:55 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2021-01-25T08:16:55Z</dc:date>
    <item>
      <title>User Group Count exceeds threshold - PANORAMA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/381536#M89756</link>
      <description>&lt;P&gt;Hi Folks, looking for advice on an alert which is bugging me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our Panorama instance regularly (2 per hour) reports that:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Panorama - SYSTEM ALERT : high : User Group count of 12080 exceeds threshold of 10000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now this is correct - as it comes from two (soon to be four) firewalls plumbed into LDAP/AD:&lt;BR /&gt;&lt;STRONG&gt;admin@Panorama&amp;gt; show user group list device-group FW1a | match Total&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Total: 6040&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;admin@Panorama&amp;gt; show user group list device-group FW1b | match Total&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Total: 6040&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each firewall is an A-A HA pair - so both really need to know the groups -&lt;/P&gt;&lt;P&gt;We are about to deploy a second HA A-A pair which would also have the same number of groups (&lt;U&gt;&lt;STRONG&gt;4 x 6040&lt;/STRONG&gt;&lt;/U&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i believe that the solution to this is to have Panorama import from one firewall (or have it import and share to the firewalls)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am unsure how to do this in a resilient manner - i.e. if Panorama or the identified firewall is off the air for any period of time, can the remaining firewalls keep the group list populated and up to date?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any pointers would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 14:01:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/381536#M89756</guid>
      <dc:creator>GN_ROS</dc:creator>
      <dc:date>2021-01-22T14:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: User Group Count exceeds threshold - PANORAMA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/381855#M89779</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132903"&gt;@GN_ROS&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So the groups would be cached so if something happened they would just work off the cached information, but they wouldn't update if the source was unavailable. The part that is kind of confusing in your post though is that this appears to be pulling the same information from both firewalls, as the number of groups is exactly the same. In that sense, you shouldn't actually be exceeding your group count since the group would just be 6040 if the membership and domain information is the same anyways.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 04:30:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/381855#M89779</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-01-25T04:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: User Group Count exceeds threshold - PANORAMA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/381874#M89782</link>
      <description>&lt;P&gt;Did you set a master device in the Device Group?&lt;/P&gt;&lt;P&gt;a device group has a master device from which the user-id information is collected&lt;/P&gt;&lt;P&gt;if you set it to none it might be grabbing the info from all members or i you've set all firewalls in different groups, then they're all polled for 'their group's information)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 08:16:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/381874#M89782</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-01-25T08:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: User Group Count exceeds threshold - PANORAMA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/381886#M89785</link>
      <description>&lt;P&gt;Hi folks,&lt;BR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;, thanks for the reply.&lt;/P&gt;&lt;P&gt;Yes master device is set, however this may be the root of the issue.&lt;/P&gt;&lt;P&gt;We use a device group structure like so&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Prod_Firewalls&lt;/P&gt;&lt;P&gt;&amp;nbsp; -&amp;gt; ActiveFW1_group&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; FW1a&lt;/P&gt;&lt;P&gt;&amp;nbsp; -&amp;gt;ActiveFW2_group&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;FW1b&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In ActiveFW1_group - FW1a is the master&lt;/P&gt;&lt;P&gt;In ActiveFW2_group - FW1b is master&lt;/P&gt;&lt;P&gt;In Prod_Firewalls - None is selected, as there is no option for the lower groups or FW's to be selected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, Panorama therefore sees the two as Master i suppose.&lt;/P&gt;&lt;P&gt;We have 2 groups like this such that 2 sets of admins can operate the permissions model.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any advice on how to overcome the dual mastership for identity info?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 10:29:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/381886#M89785</guid>
      <dc:creator>GN_ROS</dc:creator>
      <dc:date>2021-01-25T10:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: User Group Count exceeds threshold - PANORAMA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/381888#M89786</link>
      <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132903"&gt;@GN_ROS&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, put both members of the cluster in the same device group &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; that's how it's supposed to be done (this is what the 'master' is for etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you elaborate on why you are splitting up your admins over 2 different devices in the same cluster?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 11:03:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/381888#M89786</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-01-25T11:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: User Group Count exceeds threshold - PANORAMA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/382585#M89862</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Sorry for the late response.&amp;nbsp;&lt;BR /&gt;The initial reasons are historic... and probably not valid now if designed fresh.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While it is an active-active pair, each has its own virtual router and needed specific rules per side.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think most of what we wish to achieve can be accomplished with targets.&lt;BR /&gt;&lt;BR /&gt;i will accept your solution as the best.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 14:01:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/382585#M89862</guid>
      <dc:creator>GN_ROS</dc:creator>
      <dc:date>2021-01-28T14:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: User Group Count exceeds threshold - PANORAMA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/382649#M89872</link>
      <description>&lt;P&gt;Allow me to add more solution &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Templates and device groups are two different sections of configuration that live independent of eachother&lt;/P&gt;&lt;P&gt;You can accomplish the separate config through templates: assign each firewall its own template stack, create a shared template of device config that both firewalls will get and then create a unique template per firewall that contains the things that need to be applied to that firewall only (routing, HA config, dynamic updates, hostname,...)&lt;/P&gt;&lt;P&gt;While keeping both firewalls in the same device group so they get all the same policies and objects&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 17:30:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/382649#M89872</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-01-28T17:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: User Group Count exceeds threshold - PANORAMA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/383397#M89955</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;- Thanks for the info (and sorry for the late reply - i didn't get a notification)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Allow me to clarify the position we have :&lt;/P&gt;&lt;P&gt;We essentially have 3 rulebases :&lt;BR /&gt;RED - controlled by Admin group 1&amp;nbsp; &amp;nbsp;&lt;BR /&gt;BLUE - controlled by Admin group 2&lt;BR /&gt;PURPLE - shared control by both admin groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The firewalls are active-active for the PURPLE ruleset and then there is a distinct virtual router (with unique routing) on each firewall to suit the RED ruleset (on HA device 0) and the BLUE ruleset (on HA device 1)&lt;/P&gt;&lt;P&gt;The device tree at the moment is&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;PURPLE&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; /&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; \&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;RED&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; BLUE&lt;/P&gt;&lt;P&gt;&amp;nbsp; FW0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FW1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the text diagram above - FW0 is master for red device group and FW1 is master for blue - there is no option to set the purple master device (option is none).&lt;BR /&gt;I am happy with using template stacks to achieve the differences needed for Network and Device settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So while i can move rules from RED and BLUE to PURPLE (with appropriate rule targets) - with the goal of removing RED and BLUE, this then creates one flat rulebase with shared control, we lose the RBAC control.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;am i missing any other way to organise things?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as an aside - how does this scale well, as with 4 tiers available for device groups, there could be a significant number of devices all receiving user groups at the leafs, but if they are not merged up each branch to the core (i.e panorama) then there is always going to be crazy high numbers of duplicate entries. Why does panorama not also have the ability to set a master at each branch of the device tree? (as there are no devices attached to the branch level - the option is none rather than any child device names)&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 11:47:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/383397#M89955</guid>
      <dc:creator>GN_ROS</dc:creator>
      <dc:date>2021-02-02T11:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: User Group Count exceeds threshold - PANORAMA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/383400#M89956</link>
      <description>&lt;P&gt;I think the disconnect happens in the way that this is set up&amp;nbsp;&lt;/P&gt;&lt;P&gt;The usual approach in your scenario would be to set up vsys on the chassis so each admin has their own virtual firewall in the device groups. you would then have 2 device groups with each 2 members (vsys1FWA+vsys1FWB and vsys2FWA+vsys2FWB) and then have member A set to master in both device groups&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is highly unusual to have one admin to manage only FWA and the other only FWB and still have a cluster (because panorama will push only to the one device, causing massive config discrepancy across the cluster). A cluster is supposed to have fully synced config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To your aside:&lt;/P&gt;&lt;P&gt;By design, a single member in a device group becomes the master for that device group. If you have multiple devices you can choose which one is master for that group as all the devices in that group are 'the same' (so cluster members should always be in the same device group)&lt;/P&gt;&lt;P&gt;Vsys are employed to make them 'different'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 12:11:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold-panorama/m-p/383400#M89956</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-02-02T12:11:00Z</dc:date>
    </item>
  </channel>
</rss>

