Is there a way to increase the PA-3220 platform capacity limit for security policies, objects, or zones?

Is there a way to increase the PA-3220 platform capacity limit for security policies, objects, or zones?

31947
Created On 02/21/19 02:48 AM - Last Modified 03/22/19 20:35 PM


Question


Limited policy and object capacity of the PA-3220 platforms may present challenges for large configurations

Sample of error message when exceeding the platform's max capacity:
Server error :  zone-DMZ constraints failed : Maximum number of zones exceeded

 


Environment


  • PAN-OS
  • PA-3220


Answer


Feature is automatically enabled on upgrade to PAN-OS 9.0 where no configuration or additional licensing required

PA-3220 PAN-OS Chart Comparison
FeaturePAN-OS
8.1

PAN-OS
9.1

Security Zones  
Max security zones
60200
Policy  
Security rulebase
2,50010,000
Security rule schedules
256256
SSL decryption rulebase
2501,500
 App Override rulebase
2501,500
Tunnel content inspection rules
5001,000
Policy Based Forwarding
5001,000
Captive Portal
1,0002,000
DoS Protection
1,0002,000
Objects (Addresses & Services)  
Max address entries
5,00030,000
Max address groups
1,50015,000
Max members per address group
2,5002,500
Max services entries
1,0004,000
Max services groups
3752,000
Max members per services group
1,0001,000
FQDN
2,0002,000
Total IPs across all
Dynamic Address Groups
5,00010,000
Yellow highlighted values indicates that the numbers have been changed

*Note: Downgrade will fail if PAN-OS 8.1 capacities are exceeded. Reduce the amount of policies and objects in config if downgrade is needed


Additional Information


Refer to the 9.0 PAN-OS® New Features Guide for more information 
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features.html


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000bo9cCAA&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language