USER ID MAX USERS IN A GROUP???

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

USER ID MAX USERS IN A GROUP???

L3 Networker

Hello,

I've configured on PA5060 an Idenfication with AD:

PA5060: 4.1.6    USER ID AGENT : 4.1.4-3

LDAP SERVER 389

I do a group mapping  by group but this group have more than 16000 users.

when I do a show user usersIDS , I can't see all my users. I know that AD have a limitation of page size to 1000 users by request.

do you know if they are an limitation for the numbers of users in a group when you use PA ???

do you have a workaround for this problem???

thanks,

1 accepted solution

Accepted Solutions

The limit is in the number of groups and user-mappings each firewall can hold. For now it is 64K users and 640 groups. Per my understanding, there is no hard limit of maximum number of users each group can hold. You can have all 64k users in one group or can evenly or unevenly distribute them in each group. Please let me know if this is helpful.

View solution in original post

8 REPLIES 8

L6 Presenter

I would also be interrested in if someone has some more information regarding this matter.

The limit is in the number of groups and user-mappings each firewall can hold. For now it is 64K users and 640 groups. Per my understanding, there is no hard limit of maximum number of users each group can hold. You can have all 64k users in one group or can evenly or unevenly distribute them in each group. Please let me know if this is helpful.

Is this a hard limit due to restrictions in pfga/asics being used or is this a software limit (which PA, after a feature request, could make larger for lets say PA-5xxx series)?

To be a little bit more specific concerning the 640 groups "a firewall can hold": --> This is only the number of groups that can be used in the policies of the firewall (source or destination user section), but the firewall can store more than 640 groups in its database, which of course is a MUST because many customers might have more than 640 groups in their ADs.

To see the actual number of different groups, you can use the following command on the CLI:

show user group list | match Total

This shows the number of groups.

L2 Linker

Not sure if it's relevant to the query your doing.. but be wary when doing ldap queries of the Microsoft AD group "domain users".. it's generally not a standard/normal group. It's usually whats known as the "primary" group and as such doesn't show up when doing a "memberof" query. Some ldap query systems have built in workarounds to deal with this.. I'm unsure if PAN has caught up with this since last time I was testing "domain users" queries back in the early PANOS 4.x days.

User accounts can sometimes have had their "primary group" changed which can cause some confusions..

A sorta explanation from Microsoft

Setting Primary Group Excludes the User from the Group Membership in Active Directory

There's other better explanations around on the internet if you look around for "active director primary group"..

I am having a difficult time finding the 160 limit in the Palo Alto docs.

 

Can you send me a link to that please?

Where is this limit documented?

L0 Member

Does anyone know if a nested group counts against the limit of 640, so if one group contains 10, does that count as 1, or as 11?

  • 1 accepted solution
  • 12594 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!