Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Commit Error

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Commit Error

L0 Member

We're getting the following commit error on our PA-820 device:

Error: Number of addresses, dynamic groups, external-ip-lists, external-predefined-ip-lists and predefined ip-block-lists (2547) exceeds platform capacity (2500)

2 REPLIES 2

L4 Transporter

Hi 

 

The capacity for dynamic addresses on the pa-820 according to this article is 1000 https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/policy/monitor-changes-in-the-virtual-envi...

But that seems to be a little out of the 2500 that your commit error has which is the limit of the 850, hope that helps a little at least.

PCCSA PCNSA PCNSE PCSAE
Mode44 LTD Palo Alto Consultants

Cyber Elite
Cyber Elite

@Ayesha,

Are you managing this directly or through Panorama? Panorama by default will attempt to sync all shared objects to a firewall even if they aren't being utilized in policy on that device. You can modify this by clearing the Share Unused Address and Service Objects with Devices option so that only shared objects that are actually referenced are being pushed. 

 

If you are managing this locally directly on the firewall then I would do the following:

  • Ensure that you don't have any unused objects that people have simply failed to actually cleanup with time. If you attempt to delete an object that is in use you'll receive an error and it won't be removed. 
  • Combine objects when and where you can to cut down on object count. 

 

@laurence64,

The article that you mentioned is very specific to DAG IP addresses and not actual address objects, where the 820 can have 2,500. 

  • 2984 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!