Total number of profiles (xx) exceeds platform capacity (xx)

Reply
Highlighted
L1 Bithead

Total number of profiles (xx) exceeds platform capacity (xx)

Some of our smaller PAs are starting to have their commits fail do to the number of profiles configured in Panorama.  The error I receive is "Total number of profiles (xx) exceeds platform capacity (xx)".  I followed this link but it does not seem to have helped: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm0DCAS

 

This had me disable the "Share Unused Address and Service Objects with Devices".  Even though this has been disabled all of the unused  security profiles are still applied to my firewalls where they are not needed.  Is there something else that can be done to remove the unused security profiles?

 

-Thanks!

Highlighted
Cyber Elite

@JohnJones,

So profile is actually every policy in your entire rulebase; Security, NAT, QoS, PBF, Decryption, Tunnel Inspection, Application Override, Atuh, and DoS Protection. Remove any policies that you aren't actually using on the device and you'll be good to go.

 

View Max Profiles on device.

'show system state filter cfg.general.max* | match profile'

 

Highlighted
Cyber Elite


@BPry wrote:

@JohnJones,

So profile is actually every policy in your entire rulebase; Security, NAT, QoS, PBF, Decryption, Tunnel Inspection, Application Override, Atuh, and DoS Protection.


@BPry are you sure? Doesn't this mean security profiles like url, antivirus, anrispyware, vulnerability? Because these profiles are still shared with the firewalls even if you have the option "share unused ..." disabled (this option is only for address-, addressgroup-, service- and servicegroupobjects)

Highlighted
Cyber Elite

@vsys_remo,

Nope, I was actually just modifying this. Really bad article on the knowledgebase that once I was looking at it more shouldn't exist. Profile accounts for the security profiles as you mention. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!