How to reduce the number of Security Policies configured on the Firewall
9484
Created On 02/01/23 09:31 AM - Last Modified 09/15/23 05:14 AM
Objective
- To Check the maximum capacity of the Firewall in the number of Security Policies.
- To Check the current number of configured Security Policies on the Firewall.
- To Determine which Security Policies that can be deleted.
- To Reduce the Security Policies of a locally managed Firewall.
- To Reduce the Security Policies of a Panorama-managed Firewall.
Environment
- Palo Alto Firewalls (FW)
- Supported PAN-OS
- Security Policies
Procedure
Attention Strata Cloud Manager Users: If you've been redirected to this knowledge article, please skip ahead and start with Step 2 .
- Check the maximum capacity of Security Policies for your Firewall.
- Use Firewall CLI:
show system state filter cfg.general.max* | match max-policy-rule
Note: In case the value is listed in hexadecimal format 0x then it needs to be converted to decimal. Most recent platforms and PAN-OS versions will list the value in decimal.
- Use the Product Selection web page click Show More under your platform name to find the maximum Security rules.
- For VM-Series Firewall see Maximum Limits Based on Tier and Memory.
- Check the current number of Security Policies from GUI: Policies > Security
Note: if the FW is configured for multi-vsys, Add the number of items listed under each vsys to get the total of Security Policies configured on the FW.
- To determine which Security Policies can be deleted, use the following accordingly:
- If AIOps-Premium monitors the Firewall and Panorama, you can optimize your security policy using Policy Analyzer . Take a look at the Types of Anomalies that Policy Analyzer Detects
- For non-AIOps-Premium monitored firewalls, use How to Identify Unused Policies on a Palo Alto Networks Device .
- For locally managed Firewall:
- Delete the unused Security Policies configured under GUI: Policies > Security
- For Panorama managed Firewall:
- Revisit your device-group hierarchy: consider placing the FW(s) with lesser capacity limit under a different device-group than the FW(s) with a higher capacity limit.
- Reduce the number of Security Policies configured under Device Groups > Policies > Security.
- If the number of Security Policies cannot be reduced below the capacity limit after following the recommendations above, consider upgrading your FW to a higher capacity platform.