User Group limits on firewall

Announcements

Changes to the LIVEcommunity experience are coming soon... Here's what you need to know.

Reply
yhlee1
L2 Linker

User Group limits on firewall

Hello,

 

Recently I got error below on PA 850 device(8.1.13)

-User Group count of 1098 exceeds threshold of 1000

 

The log is straight forward, number of group is exceeding the limit, but I have some question.

 

1. I have one more device,PA-3220, which look same LDAP for group mapping(same configuration).

I found article about this and it says FW has limitation for user group above 8.x and it's on all FW.

But there is no same log on 3220, even it has same number of group,1098.

Is the limit different via devices?

 

2. The log says number of group exceeding the limit, but FW still holds over 1000 user group.

active)> show user group list | match Total
Total: 1098

 

Is this log just alert? I don't know how FW can hold more than 1000 group if there is limit.

 

 

kiwi
Community Team Member

Hi @yhlee1 ,

 

Yes, each platform has its own limits. 

You can make the comparison on this page:

 

https://www.paloaltonetworks.com/products/product-comparison?chosen=pa-3220,pa-850

 

In this particular example you'll notice that the PA-850 can have 1000 active and unique groups in policy, compared to the PA-3220 which can have 10,000 (aggregate of LDAP groups, dynamic user groups and XML API groups).

 

Hope this helps,

-Kiwi.

 

 
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!