User Group limits on firewall

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

User Group limits on firewall

L2 Linker



Recently I got error below on PA 850 device(8.1.13)

-User Group count of 1098 exceeds threshold of 1000


The log is straight forward, number of group is exceeding the limit, but I have some question.


1. I have one more device,PA-3220, which look same LDAP for group mapping(same configuration).

I found article about this and it says FW has limitation for user group above 8.x and it's on all FW.

But there is no same log on 3220, even it has same number of group,1098.

Is the limit different via devices?


2. The log says number of group exceeding the limit, but FW still holds over 1000 user group.

active)> show user group list | match Total
Total: 1098


Is this log just alert? I don't know how FW can hold more than 1000 group if there is limit.




Community Team Member

Hi @yhlee1 ,


Yes, each platform has its own limits. 

You can make the comparison on this page:,pa-850


In this particular example you'll notice that the PA-850 can have 1000 active and unique groups in policy, compared to the PA-3220 which can have 10,000 (aggregate of LDAP groups, dynamic user groups and XML API groups).


Hope this helps,



LIVEcommunity team member, CISSP
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.


A relatively old post perhaps. But I'm having a bit of a challenge understanding the limitations properly.


So we have a firewall (and a panorma). We'd like to configure our firewall to use (A)AD and user groups in policies and autorisations like portals and gateways.


First the firewall needs to understand where it can get AD group information? So it will query AD for groups? It will receive more groups back than 1000 (which is not a lot) and fail enumeration?
What happens if we narrow down the location in active directory by specifying a location to enumerate? And this contains <1000 groups by itself. However these groups here are filled with groups themselves (nesting). How does that count toward this limit?


Is there a difference in PAN-OS version that may have increased the limits? Or do we really need to work with multiple locations (which is also limited) to create a situation where the firewall is actually capable of obtaining everything it needs to, to be able to do its work ?

  • 2 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!