How to reduce the number of Security Policies configured on the Firewall

How to reduce the number of Security Policies configured on the Firewall

9484
Created On 02/01/23 09:31 AM - Last Modified 09/15/23 05:14 AM


Objective


  • To Check the maximum capacity of the Firewall in the number of Security Policies.
  • To Check the current number of configured Security Policies on the Firewall.
  • To Determine which Security Policies that can be deleted.
  • To Reduce the Security Policies of a locally managed Firewall.
  • To Reduce the Security Policies of a Panorama-managed Firewall.


Environment


  • Palo Alto Firewalls (FW)
  • Supported PAN-OS
  • Security Policies


Procedure



Attention Strata Cloud Manager Users: If you've been redirected to this knowledge article, please skip ahead and start with Step 2 .
 
  1. Check the maximum capacity of Security Policies for your Firewall.
    1. Use Firewall CLI:
show system state filter cfg.general.max* | match max-policy-rule
Note: In case the value is listed in hexadecimal format 0x then it needs to be converted to decimal. Most recent platforms and PAN-OS versions will list the value in decimal.
  1. Use the Product Selection  web page click Show More under your platform name to find the maximum Security rules.
  2. For VM-Series Firewall see Maximum Limits Based on Tier and Memory.
  1. Check the current number of Security Policies from GUI: Policies > Security
security-policy2.png
Note: if the FW is configured for multi-vsys, Add the number of items listed under each vsys to get the total of Security Policies configured on the FW.
  1. To determine which Security Policies can be deleted, use the following accordingly:
  1. If AIOps-Premium monitors the Firewall and Panorama, you can optimize your security policy using Policy Analyzer . Take a look at the Types of Anomalies that Policy Analyzer Detects
  2. For non-AIOps-Premium monitored firewalls, use How to Identify Unused Policies on a Palo Alto Networks Device .
  1. For locally managed Firewall:
    1. Delete the unused Security Policies configured under GUI: Policies > Security
  2. For Panorama managed Firewall:
    1. Revisit your device-group hierarchy: consider placing the FW(s) with lesser capacity limit under a different device-group than the FW(s) with a higher capacity limit.
    2. Reduce the number of Security Policies configured under Device Groups > Policies > Security.
  3. If the number of Security Policies cannot be reduced below the capacity limit after following the recommendations above, consider upgrading your FW to a higher capacity platform.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kGl6CAE&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language