Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pa-400 series on pan os 11 & later accept 100K Ip now #7

Open
nrgneilo opened this issue Nov 25, 2024 · 5 comments
Open

Pa-400 series on pan os 11 & later accept 100K Ip now #7

nrgneilo opened this issue Nov 25, 2024 · 5 comments

Comments

@nrgneilo
Copy link

Please update or create new URL for 100K ip for Pa-400 series. Pa-400 series on pan os 11& later accept 100K Ip and 1M Url

https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/external-dynamic-list

Thanks.

@nrgneilo nrgneilo changed the title Pa-400 series on pan os 11 $ later accept 100K Ip now Pa-400 series on pan os 11 & later accept 100K Ip now Nov 25, 2024
@romainmarcoux
Copy link
Owner

Thank you to help me improve the project.

Are you sure that the limit of the total number of IP addresses for entry-level Palo Alto FW has been increased to 100,000? Are you not confusing it with the maximum number of URLs?

On the link you provide, I still read: "IP address—The PA-3200 Series, PA-5200 Series, and the PA-7000 Series firewalls support a maximum of 150,000 total IP addresses; all other models support a maximum of 50,000 total IP addresses. No limits are enforced for the number of IP addresses per list. When the maximum supported IP address limit is reached on the firewall, the firewall generates a syslog message. The IP addresses in predefined IP address lists do not count toward the limit."

@nrgneilo
Copy link
Author

Good catch! I'm mistaken. Yeah, restricted to 50K ip. Sorry. i thought the URL section was IP's That's to bad.

@romainmarcoux
Copy link
Owner

Yes, it's a shame. That's why I'm keeping the full-40k file.
FortiGates have much higher limits.

@nrgneilo
Copy link
Author

From my understanding, the FW will only use up to 50k Ip's say in a auto ip block at one time.

"When the maximum supported IP address limit is reached on the firewall, the firewall generates a syslog message. The IP addresses in predefined IP address lists do not count toward the limit."

Sounds like you can still have the entire list? I will confirm with PA.

@romainmarcoux
Copy link
Owner

I agree that the wording of the sentence is not explicit.
You can test on a PAN-OS FW by adding the full-aa and full-ab segments (131k IP each) and see if it is 50k IP per segment or 50k IP in total that are taken into account.

@romainmarcoux romainmarcoux reopened this Nov 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants