address-group limitation

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

address-group limitation

Not applicable

Hi @all,

we’re using a PA-5020 active-passive Firewall-Cluster.

We recently noticed that the address-groups are limited to 500 items per group. As we have a list of nearly 1500 items (ip-address and network-addresses) to manage, I want to ask whether there are any performance issues known if we split the items in three or more groups.

2 REPLIES 2

L6 Presenter

Either performance or hardware limitations due to that the addressgroup is "compiled" into a list of actual addresses which is then loaded to the fpga/asics. However 500 as limit sounds to me more of a GUI limit than a true hardware limit (but thats just a feeling I got).

You could test this easily by creating another address-group and then try to use both of them in the same security rule (like both of them as sourceip or such). However be prepared to quickly rollback your config in case things go wrong...

OK thanks for your answer!

Well I'll try using three groups in a rule, and see whether I manage to blow the system Smiley Wink

cya

chris

  • 1958 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!