What is the maximum number of service objects that can be registered in a one-line policy?

Reply
Highlighted
L2 Linker

What is the maximum number of service objects that can be registered in a one-line policy?


Hello, expert of everyone

I'm using PA-3220
Pan-OS is 8.1

239 objects registered in service group A

I want to allow service group A in the security policy

Can I specify service group A with a one-line policy?

I think you can add up to 1000 objects to a policy group

Will I get an error if I create it with a one-line policy?

Can you tell me

Thank you
 
 
日本語~~~~~~~~~~


こんにちは、エキスパートの皆さん

PA-3220を使っています
Pan-OSは8.1です

サービス グループAにオブジェクトを239個、登録しました

セキュリティポリシーでサービスグループAを指定して許可したいのです

1行のポリシーでサービスグループAを指定することはできないのでしょうか

1つのポリシーグループに最大で1000個のオブジェクトを追加できると考えています

1行のポリシーで作成した場合は、エラーになりますか

教えていただけますか

よろしくお願いします

Highlighted
Cyber Elite

Hello,

Here are my replies to your questions:

 

  • Can I specify service group A with a one-line policy?
    • Yes you can add the group rather than the individual objects
  • Will I get an error if I create it with a one-line policy?
    • Only if there are any applications that have dependencies.

Hope that helps!

Highlighted
L2 Linker

Dear Otakar.Klier 

Thank you for your advice

 

> Only if there are any applications that have dependencies.
What are these restrictions?
I would like to know more, but are there any appropriate materials?
I would be happy if you could tell me the URL

 

Thank you

 

 

日本語~~~~~~~~

Otakar.Kliersさん

あなたのアドバイスに感謝します

 

> Only if there are any applications that have dependencies.

この制限はどのようなものでしょうか
詳しく知りたいのですが、適切な資料などはありますでしょうか
URLなどを教えていただけると嬉しいです

 

ありがとう

Highlighted
L2 Linker

Hello
Is the content of this URL being said?
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClV0CAK

I think the problem is different
I combined 239 services into one group, from zone A to B, from object group C to Any, and the application allowed with Any

sw-version: 8.1.9 was able to commit without problems

Then updated to sw-version: 8.1.9-h4

Then I can't commit
configuration load phase-1 aborted.
Commit job failed

The service was divided into 100 units and changed to a three-line policy.

Then I was able to commit
configuration load phase-2 succeeded.
Config installed
Commit job succeeded

I do n’t know what ’s wrong

Thank you

 

 

 

日本語~~~~~~~~~~

こんにちは
言われているのは、このURLの内容でしょうか
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClV0CAK

問題は違うように思います
私はzone AからBへ、オブジェクトグループCからAnyへ、239個のサービスを1グループにまとめ、アプリケーションはAnyで許可しました

sw-version: 8.1.9では、問題なくコミットできました

その後、sw-version: 8.1.9-h4へアップデートをしました

それから、コミットできなくなりました
configuration load phase-1 aborted.
Commit job failed

サービスを100ずつに分けて、3行のポリシーに変更しました

それからコミットができました
configuration load phase-2 succeeded.
Config installed
Commit job succeeded

何が問題なのかわからなくなりました

ありがとう

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!