<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Commit Error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/commit-error/m-p/423995#M94222</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/40369"&gt;@Ayesha&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Are you managing this directly or through Panorama? Panorama by default will attempt to sync all shared objects to a firewall even if they aren't being utilized in policy on that device. You can modify this by clearing the&amp;nbsp;&lt;STRONG&gt;Share Unused Address and Service Objects with Devices&amp;nbsp;&lt;/STRONG&gt;option so that only shared objects that are actually referenced are being pushed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are managing this locally directly on the firewall then I would do the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Ensure that you don't have any unused objects that people have simply failed to actually cleanup with time. If you attempt to delete an object that is in use you'll receive an error and it won't be removed.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Combine objects when and where you can to cut down on object count.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163815"&gt;@laurence64&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The article that you mentioned is very specific to DAG IP addresses and not actual address objects, where the 820 can have 2,500.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 02 Aug 2021 18:19:19 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-08-02T18:19:19Z</dc:date>
    <item>
      <title>Commit Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-error/m-p/423894#M94214</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We're getting the following commit error on our PA-820 device:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Error: Number of addresses, dynamic groups, external-ip-lists, external-predefined-ip-lists and predefined ip-block-lists (2547) exceeds platform capacity (2500)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 14:24:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-error/m-p/423894#M94214</guid>
      <dc:creator>Ayesha</dc:creator>
      <dc:date>2021-08-02T14:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: Commit Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-error/m-p/423958#M94218</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The capacity for dynamic addresses on the pa-820 according to this article is 1000&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/policy/monitor-changes-in-the-virtual-environment/use-dynamic-address-groups-in-policy" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/policy/monitor-changes-in-the-virtual-environment/use-dynamic-address-groups-in-policy&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But that seems to be a little out of the 2500 that your commit error has which is the limit of the 850, hope that helps a little at least.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 16:57:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-error/m-p/423958#M94218</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2021-08-02T16:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Commit Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-error/m-p/423995#M94222</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/40369"&gt;@Ayesha&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Are you managing this directly or through Panorama? Panorama by default will attempt to sync all shared objects to a firewall even if they aren't being utilized in policy on that device. You can modify this by clearing the&amp;nbsp;&lt;STRONG&gt;Share Unused Address and Service Objects with Devices&amp;nbsp;&lt;/STRONG&gt;option so that only shared objects that are actually referenced are being pushed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are managing this locally directly on the firewall then I would do the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Ensure that you don't have any unused objects that people have simply failed to actually cleanup with time. If you attempt to delete an object that is in use you'll receive an error and it won't be removed.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Combine objects when and where you can to cut down on object count.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163815"&gt;@laurence64&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The article that you mentioned is very specific to DAG IP addresses and not actual address objects, where the 820 can have 2,500.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 18:19:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-error/m-p/423995#M94222</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-08-02T18:19:19Z</dc:date>
    </item>
  </channel>
</rss>

