- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-09-2012 03:37 AM
Hello,
I've configured on PA5060 an Idenfication with AD:
PA5060: 4.1.6 USER ID AGENT : 4.1.4-3
LDAP SERVER 389
I do a group mapping by group but this group have more than 16000 users.
when I do a show user usersIDS , I can't see all my users. I know that AD have a limitation of page size to 1000 users by request.
do you know if they are an limitation for the numbers of users in a group when you use PA ???
do you have a workaround for this problem???
thanks,
09-12-2012 11:28 PM
The limit is in the number of groups and user-mappings each firewall can hold. For now it is 64K users and 640 groups. Per my understanding, there is no hard limit of maximum number of users each group can hold. You can have all 64k users in one group or can evenly or unevenly distribute them in each group. Please let me know if this is helpful.
08-20-2012 03:11 PM
I would also be interrested in if someone has some more information regarding this matter.
09-12-2012 11:28 PM
The limit is in the number of groups and user-mappings each firewall can hold. For now it is 64K users and 640 groups. Per my understanding, there is no hard limit of maximum number of users each group can hold. You can have all 64k users in one group or can evenly or unevenly distribute them in each group. Please let me know if this is helpful.
09-13-2012 02:00 AM
Is this a hard limit due to restrictions in pfga/asics being used or is this a software limit (which PA, after a feature request, could make larger for lets say PA-5xxx series)?
08-13-2013 05:50 AM
To be a little bit more specific concerning the 640 groups "a firewall can hold": --> This is only the number of groups that can be used in the policies of the firewall (source or destination user section), but the firewall can store more than 640 groups in its database, which of course is a MUST because many customers might have more than 640 groups in their ADs.
To see the actual number of different groups, you can use the following command on the CLI:
show user group list | match Total
This shows the number of groups.
08-14-2013 01:44 AM
Not sure if it's relevant to the query your doing.. but be wary when doing ldap queries of the Microsoft AD group "domain users".. it's generally not a standard/normal group. It's usually whats known as the "primary" group and as such doesn't show up when doing a "memberof" query. Some ldap query systems have built in workarounds to deal with this.. I'm unsure if PAN has caught up with this since last time I was testing "domain users" queries back in the early PANOS 4.x days.
User accounts can sometimes have had their "primary group" changed which can cause some confusions..
A sorta explanation from Microsoft
Setting Primary Group Excludes the User from the Group Membership in Active Directory
There's other better explanations around on the internet if you look around for "active director primary group"..
03-15-2021 08:21 AM
I am having a difficult time finding the 160 limit in the Palo Alto docs.
Can you send me a link to that please?
03-15-2021 08:28 AM
Where is this limit documented?
10-20-2021 12:33 PM
Does anyone know if a nested group counts against the limit of 640, so if one group contains 10, does that count as 1, or as 11?
04-18-2024 01:54 AM
how many users we can create in the PA-440 Model for the splash page (Captive Portal-based login)?
04-18-2024 11:31 AM
@RajendraSolanki wrote:
how many users we can create in the PA-440 Model for the splash page (Captive Portal-based login)?
Are you wanting to use local authentication for the captive portal authentication process? If you are asking for the local database it sounds like there might not be a hard limit per se: https://live.paloaltonetworks.com/t5/general-topics/number-of-users-on-local-database/td-p/37268 (This topic is really old, but still probably accurate.)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!