How to mitigate configuration size reaching device capacity limit

How to mitigate configuration size reaching device capacity limit

68555
Created On 07/19/23 15:58 PM - Last Modified 04/01/26 03:19 AM


Objective


To mitigate High MP Memory issue due to the configuration size reaching device capacity limit. This root cause of high MP Memory would have been determined by noticing that the increase in MP Memory coincided with an increase in Firewall's/Panorama's config size.

Environment


  • Palo Alto Firewall
  • MP Memory
  • Config size


Procedure


  1. Check the Firewall last committed configuration size and candidate configuration size using CLI command:
    show management-server last-committed config-size
    show management-server candidate config-size
  2. Reduce the number of Address , Address Group , Service , Service Group , FQDN and EDL Objects.
  3. Delete unused Security policies and NAT policies. Refer to Tips & Tricks: How to Identify Unused Policies on a Palo Alto Networks Device.
  4. For Panorama VM consider increasing its memory size refer to "Increase CPUs and Memory on the Panorama Virtual Appliance".
  5. If even after following the recommendation listed above you are unable to reduce the configuration size below the capacity limit of your hardware platform then contact your SE to check with them if you should consider upgrading your platform to a higher capacity platform.


Additional Information


  • To check the maximum configuration file size supported by Panorama refer to: Total Configuration Size for Panorama.
    To check the maximum configuration file size recommended for firewalls refer to below table.
  • These limits may increase with newer PAN-OS releases.
  • If your configuration requires more space than listed, please contact TAC to verify if a more recent version supports your specific needs.
FIREWALL MODELMAXIMUM CONFIGURATION FILE SIZE
PA-326032 MB
PA-325032 MB
PA-85030 MB
PA-82030 MB
PA-526061 MB
PA-528061 MB
PA-522061 MB
PA-44035 MB
PA-45035 MB
PA-46035 MB
PA-41023 MB
PA-141035 MB
PA-142035 MB
PA-341035 MB
PA-342035 MB
PA-343050 MB
PA-344050 MB
PA-541055 MB
PA-542055 MB
PA-543055 MB
PA-544055 MB
PA-41518 MB
PA-44535 MB
PA-545065 MB
PA-7500125 MB
PA-5540105 MB
PA-5550105 MB
PA-5560105 MB
PA-5570105 MB
PA-5580105 MB
PA-7050125 MB
PA-7080125 MB

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000bqUICAY&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language