User Group limits on firewall

Showing results for 
Search instead for 
Did you mean: 

User Group limits on firewall

L2 Linker



Recently I got error below on PA 850 device(8.1.13)

-User Group count of 1098 exceeds threshold of 1000


The log is straight forward, number of group is exceeding the limit, but I have some question.


1. I have one more device,PA-3220, which look same LDAP for group mapping(same configuration).

I found article about this and it says FW has limitation for user group above 8.x and it's on all FW.

But there is no same log on 3220, even it has same number of group,1098.

Is the limit different via devices?


2. The log says number of group exceeding the limit, but FW still holds over 1000 user group.

active)> show user group list | match Total
Total: 1098


Is this log just alert? I don't know how FW can hold more than 1000 group if there is limit.




Community Team Member

Hi @yhlee1 ,


Yes, each platform has its own limits. 

You can make the comparison on this page:,pa-850


In this particular example you'll notice that the PA-850 can have 1000 active and unique groups in policy, compared to the PA-3220 which can have 10,000 (aggregate of LDAP groups, dynamic user groups and XML API groups).


Hope this helps,



LIVEcommunity team member, CISSP
Don't forget to hit that Like button if a post is helpful to you!
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!