<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Confused over EBL size limit in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/129628#M98718</link>
    <description>&lt;P&gt;If the list is larger than the firewall can support, it will download its max allowed (starting at the top and working down) and then drop anything longer than it can accomdate. At this point it will also throw a warning that the max limit has been hit. I'm trying to dig up the exact message, but I believe it was posted in the forums before.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Nov 2016 15:57:15 GMT</pubDate>
    <dc:creator>Greg_R</dc:creator>
    <dc:date>2016-11-29T15:57:15Z</dc:date>
    <item>
      <title>Confused over EBL size limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/104038#M98712</link>
      <description>&lt;P&gt;We have a 3020 running 7.0.8 and are experimenting with MineMeld.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As soon as we get close to 5k IPs on the combined EBLs we get an error on a EBL refresh that it's been truncated as it's over the limit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto's own KB suggests that on an entry level PA-&lt;STRONG&gt;&lt;EM&gt;200&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp;there is a limit of 50k items on all EBLs combined.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Working-with-External-Block-List-EBL-Formats-and-Limitations/ta-p/58795" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Working-with-External-Block-List-EBL-Formats-and-Limitations/ta-p/58795&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Support are telling me that the limit on 3020 is 5k which doesn't seem to make sense as a) why would a 200 support more than a 3020 and b) what's the point of something like minmeld if you can only have 5000 IPs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any clarification would be great.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 18:07:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/104038#M98712</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2016-08-17T18:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: Confused over EBL size limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/104039#M98713</link>
      <description>&lt;P&gt;For 7.0.x and earlier read this article. Specifically the 3rd entry down.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Dynamic-Block-List-Limit-on-number-of-entries/m-p/100757/thread-id/44278" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Dynamic-Block-List-Limit-on-number-of-entries/m-p/100757/thread-id/44278&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For 7.1 see this link.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Dynamic-Block-List-Limit-on-number-of-entries/m-p/100757/thread-id/44278" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Dynamic-Block-List-Limit-on-number-of-entries/m-p/100757/thread-id/44278&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Either way PanOS sets aside 300 entries so the number will always be 300 lower than the maximum. The limit on your 3020 running 7.0.8 will be 4700.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 18:17:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/104039#M98713</guid>
      <dc:creator>Greg_R</dc:creator>
      <dc:date>2016-08-17T18:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Confused over EBL size limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/104086#M98714</link>
      <description>&lt;P&gt;In addition to Greg answer about enanchements in 7.1, note that:&lt;/P&gt;
&lt;P&gt;- you can limit the number of entries of MineMeld output feeds retrieved by PAN-OS using the 'n' URL parameter. Example: https://&amp;lt;minemeld&amp;gt;/feeds/inboundhcfeed?n=1000 will retrieve only the top 1000 entries of the feed&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- output feeds by default in MineMeld are sorted by recency. This means that when you retrieve the 1000 topmost entries, the 1000 most recent entries are retrieved&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 21:32:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/104086#M98714</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-17T21:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Confused over EBL size limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/129524#M98715</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a Pa-500 version 6.1.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show system state | match cfg.general.max-address&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cfg.general.max-address: 0x9c4 --&amp;gt; 2500 IP&lt;BR /&gt;cfg.general.max-address-group: 0xfa --&amp;gt; 250&lt;BR /&gt;cfg.general.max-address-per-group: 0x1f4 --&amp;gt; 500&lt;BR /&gt;peer.cfg.general.max-address: 0x9c4&lt;BR /&gt;peer.cfg.general.max-address-group: 0xfa&lt;BR /&gt;peer.cfg.general.max-address-per-group: 0x1f4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;I am confused with the limits of the lists.&lt;/SPAN&gt; &lt;SPAN&gt;I can not predict how big the feed can become.&lt;/SPAN&gt; If it's bigger than the limits, does the Palo Alto read the list as much as I can or can not read it?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;With these values, how many lists can I have?&lt;BR /&gt;How many values can this list have?&lt;BR /&gt;In global, how many ip can I have?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 10:55:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/129524#M98715</guid>
      <dc:creator>Sistemas_SanLucar</dc:creator>
      <dc:date>2016-11-29T10:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Confused over EBL size limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/129554#M98716</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39199"&gt;@Sistemas_SanLucar﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;check here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/policy/use-a-dynamic-block-list-in-policy.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/policy/use-a-dynamic-block-list-in-policy.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your PA-500 with PAN-OS 6.1 can have:&lt;/P&gt;
&lt;P&gt;- up to 10 Dynamic Block Lists&lt;/P&gt;
&lt;P&gt;- each DBL can contain up to (max-addresses-300) entries = 2200 IPs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: this has changed in PAN-OS 7.1, check&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36318"&gt;@Greg_R﻿&lt;/a&gt;&amp;nbsp;previous post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In MineMeld you can use the "n" and "s" feed parameter to slice a feed. Example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;https://&amp;lt;minemeld ip&amp;gt;/feeds/inboundhc =&amp;gt; full list of indicators&lt;/P&gt;
&lt;P&gt;https://&amp;lt;minemeld ip&amp;gt;/feeds/inboundhc&lt;STRONG&gt;?n=2200&lt;/STRONG&gt; =&amp;gt; first 2200 entries in the list&lt;/P&gt;
&lt;P&gt;https://&amp;lt;minemeld ip&amp;gt;/feeds/inboundhc&lt;STRONG&gt;?s=2200&amp;amp;n=2200&lt;/STRONG&gt; =&amp;gt; entries 2201-4400 in the list&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: feeds by default are sorted based on the update time, this means that when you retrieve the first N entries these will be the N most recent entries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 11:50:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/129554#M98716</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-11-29T11:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Confused over EBL size limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/129627#M98717</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV dir="ltr" style="zoom: 1;"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;I continue with the doubt.&lt;/SPAN&gt; &lt;SPAN class=""&gt;If the list has 5000 ip.&lt;/SPAN&gt; &lt;SPAN&gt;What does Palo Alto do?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;Does it only read from the list the ip that it allows?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;Does it give error and does not read anything?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV dir="ltr" style="zoom: 1;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr" style="zoom: 1;"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Thank you&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 29 Nov 2016 15:53:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/129627#M98717</guid>
      <dc:creator>Sistemas_SanLucar</dc:creator>
      <dc:date>2016-11-29T15:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Confused over EBL size limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/129628#M98718</link>
      <description>&lt;P&gt;If the list is larger than the firewall can support, it will download its max allowed (starting at the top and working down) and then drop anything longer than it can accomdate. At this point it will also throw a warning that the max limit has been hit. I'm trying to dig up the exact message, but I believe it was posted in the forums before.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 15:57:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/129628#M98718</guid>
      <dc:creator>Greg_R</dc:creator>
      <dc:date>2016-11-29T15:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Confused over EBL size limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/129631#M98719</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 16:14:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/129631#M98719</guid>
      <dc:creator>Sistemas_SanLucar</dc:creator>
      <dc:date>2016-11-29T16:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Confused over EBL size limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/141976#M98720</link>
      <description>&lt;P&gt;Hi Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried splitting the list but still getting error that maximum in the list is exceeded.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Config firewall:&lt;/P&gt;
&lt;P&gt;xxx-Ransomware-IPv4-01 {&lt;BR /&gt; recurring {&lt;BR /&gt; hourly {&lt;BR /&gt; at 45;&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; url https://ip/feeds/xxx-Ransomware-IPv4?n=4600;&lt;BR /&gt; type ip;&lt;BR /&gt; description "Ransomware Minemeld list Medium confidence level";&lt;BR /&gt; }&lt;BR /&gt;xxx-Ransomware-IPv4-02 {&lt;BR /&gt; recurring {&lt;BR /&gt; hourly {&lt;BR /&gt; at 46;&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; url https://ip/feeds/xxx-Ransomware-IPv4?s=4600&amp;amp;n=4600;&lt;BR /&gt; type ip;&lt;BR /&gt; }&lt;BR /&gt;xxx-Ransomware-IPv4-03 {&lt;BR /&gt; recurring {&lt;BR /&gt; hourly {&lt;BR /&gt; at 47;&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; url https://ip/feeds/xxx-Ransomware-IPv4?s=9200&amp;amp;n=4600;&lt;BR /&gt; type ip;&lt;BR /&gt; }&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Running lateste Minemeld and PAN-OS 7.0.9.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error received when commit is done:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;EBL(vsys1/xxx-Ransomware-IPv4-02) Exceeding max number of ips at line 4701&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When I check in CLI it is starting at 4600 but not ending untill the end of the list.&lt;/P&gt;
&lt;P&gt;I think&amp;nbsp;that the parameter is n=4600 is not working.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 20:15:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/141976#M98720</guid>
      <dc:creator>kevin_thys</dc:creator>
      <dc:date>2017-02-08T20:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Confused over EBL size limit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/141985#M98721</link>
      <description>&lt;P&gt;Just tested this and works for me. Could you try this and paste the output ?&lt;/P&gt;
&lt;PRE&gt;$ curl -s https://&amp;lt;minemeld&amp;gt;/feeds/inboundFeedMC\?s=4600\&amp;amp;n=4600  | wc
    4600    4600  133432&lt;/PRE&gt;
&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 21:25:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/confused-over-ebl-size-limit/m-p/141985#M98721</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-02-08T21:25:40Z</dc:date>
    </item>
  </channel>
</rss>

