PrismaAccess: Maximum limit for tunnel settings in the GlobalProtect app

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PrismaAccess: Maximum limit for tunnel settings in the GlobalProtect app

L0 Member

Hello
I would like to know the upper limits for tunnel settings in the GlobalProtect app in PrismaAccess.
① Upper limit for tunnel settings profiles
② Upper limit for IP address matches
③ Upper limit for routes to exclude

The background is that we plan to use GP with PrismaAccess at 30 companies with over 100 locations, and we would like to route as much traffic as possible through Prisma. * We will also set up MU and VPN within the company.

Thank you.

1 REPLY 1

Community Team Member

Hi @H.Tsuboi ,

 

The firewall can handle up to 100 excluded routes in a split tunnel setup. But if you're using GlobalProtect app version 4.1 or newer, you can have up to 200 excluded routes instead.

Source: https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-gateways/spli...

 

Prisma Access allows for the creation of up to 10,000 IP address pools per tenant. Each pool can be linked with specific match criteria such as user ID, user group, or location group.

Source: https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-use...

 

As for the maximum number of tunnel settings profiles... I was unable to find the exact number in the documentation. That being said, as mentioned, Prisma Access supports up to 10,000 IP address pool profiles per tenant and each profile can contain up to 10 IP prefixes and support up to 256 users. 

This provides some insight into the scalability of IP address assignments but I would recommended reaching out to TAC for precise limits on tunnel settings profiles.

 

Kind regards,

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 317 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!