Is there a way to increase the PA-5220 platform capacity limit for security policies, objects, or zones?

Is there a way to increase the PA-5220 platform capacity limit for security policies, objects, or zones?

24883
Created On 02/22/19 03:22 AM - Last Modified 03/22/19 20:37 PM


Question


Limited policy and object capacity of the PA-5220 platforms may present challenges for large configurations

Sample of error message when exceeding the platform's max capacity:
Server error :  zone-DMZ constraints failed : Maximum number of zones exceeded


Environment


  • PAN-OS
  • PA-5220


Answer


Feature is automatically enabled on upgrade to PAN-OS 9.0 where no configuration or additional licensing required

PA-5220 PAN-OS Chart Comparison
FeaturePAN-OS
8.1

PAN-OS
9.1

Security Zones  
Max security zones
2,5005,000
Policy  
Security rulebase
20,00030,000
Security rule schedules
256256
SSL decryption rulebase
2,0003,500
 App Override rulebase
2,0003,500
Tunnel content inspection rules
2,0002,500
Policy Based Forwarding
2,0002,000
Captive Portal
2,0002,000
DoS Protection
1,0001,000
Objects (Addresses & Services)  
Max address entries
40,00080,000
Max address groups
4,00040,000
Max members per address group
2,5002,500
Max services entries
2,0008,000
Max services groups
2504,000
Max members per services group
5002,500
FQDN
6,1446,144
Total IPs across all
Dynamic Address Groups
100,000100,000
Yellow highlighted values indicates that the numbers have been changed

*Note: Downgrade will fail if PAN-OS 8.1 capacities are exceeded. Reduce the amount of policies and objects in config if downgrade is needed


Additional Information


Refer to the 9.0 PAN-OS® New Features Guide for more information 
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features.html


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boAQCAY&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language