Object/Rule Reached Limits?

Reply
Highlighted
L1 Bithead

Object/Rule Reached Limits?

A Panorama file of 72Mb with 48900+ addresses and 32000+ security rules.  The file was imported to Expedition, but it's a hit and miss when trying to launch into the objects or other tabs.  Most often times it won't be able to get to the other tabs with a Failed Error.  The php.ini size have increased as below and the issue persist:

 

post_max_size = 250M

upload_max_filesize = 250M

memory_limit = 2048M

 

The VM has the below specs:

 

4 CPUs

16 Gigs of Memory (16384 MB)

HD 1 is 40 GB

HD 2 is 1024 GB

 

How to resolve the issue?  Any help is appreciated.

Highlighted
L3 Networker

So would you like to increase the memory used to on the parser script?

 

If so log into the GUI and head to "settings" > "custom parameters" > "parser max execution memory" and change it to something higher.

 

Screen Shot 2020-06-24 at 2.03.03 PM.png

Highlighted
L5 Sessionator

This is indeed a large number of security rules and address objects.

 

For some scenarios this is a normal number and Expedition (if running in a fast instance) may be able to handle it correctly.

However, if the Expedition backend would require more than 30 seconds to process a request (such as displaying all the objects in a single view), this would give a front-end timeout.

 

We would like to help you finding an alternative to manage the objects for the activity you have in mind.

If you can give us some information regarding what you want to accomplish, we may try to identify alternative methods that would avoid facing this frontend timeout.

 

Notice that php.ini does not have an impact in these timeouts, as it is not the PHP failing (most probably), but the frontend getting a timeout because the backend is still processing the request after 30 seconds.

Highlighted
L1 Bithead

Thanks for the reply.  I changed the max_execution_memory and time as below and doesn't appear to make a difference.

 

Annotation 2020-06-25 081214.png

Highlighted
L1 Bithead

Thanks for the reply.  I'm trying to use Expedition to manage the config file.  Basically to remove unused objects, modify/delete security rules, etc...  Most of the objects are not shared among device groups.  The config file can be pulled from the Panorama as a direct connected device.  Have not tried to load as individual device groups or if that's even possible.  Let me know what  alternative methods you have in mind.

Expedition_dashboard.png

Highlighted
L3 Networker

Can you go ahead and email us at

 

fwmigrate@paloaltonetworks.com

 

I would like to take a look at your issue.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!