: Maximum Limits Based on Memory
Focus
Focus

Maximum Limits Based on Memory

Table of Contents
End-of-Life (EoL)

Maximum Limits Based on Memory

These limits apply to flexible licenses for VM-Series firewalls running PAN-OS 10.0.4 or later.
The following tables provide the maximum number for a particular object or resource that a single VM-Series firewall deployment can create, store, manage, or interact with on a firewall configured with 4.5, 5.5, 6.5, 9, 16, or 56 GB memory.
The memory profile and the total number of vCPUs determine how many cores are automatically assigned to the management plane and the dataplane.
If you are using SW NGFW licensing you can choose a memory profile that supports your requirements for one or more of the following resources:

Sessions

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Max sessions (IPv4 or IPv6)
50,000
64,000
250,000
819,200
2,000,000
10,000,000

Policies

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Security rules2002501,50010,00010,00020,000
Security rule schedules
256256256
256
256
256
NAT rules
400400
3,000
5,0008,00015,000
Decryption rules
100100
1,000
1,0001,000
2,000
App override rules
100100
1,000
1,0001,000
2,000
Tunnel content inspection rules
100100100
500
500
2,000
SD-WAN rules
NA100100100
300
300
Policy based forwarding rules
100100
100
500
500
2,000
Captive portal rules
1010
1,000
1,0001,000
2,000
DoS protection rules
100100
1,000
1,0001,000
1,000

Security Zones

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Max security zones
15154040200200

Objects (addresses and services)

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Address objects
2,0002,500
10,000
10,000
20,000
40,000
Address groups
100125
1,000
1,000
2,500
4,000
Members per address group
2,5002,500
2,500
2,500
2,500
2,500
Service objects
1,0001,000
2,000
2,000
2,000
5,000
Service groups
250250500
500
250
500
Members per service group
500500
500
500
500
500
FQDN address objects
2,0002,000
2,000
2,000
2,000
2,000
Max DAG IP addresses*
(system wide capacity)
1,0001,000
2,500
200,000
300,000
300,500
Tags per IP address
3232
32
32
32
32
* Firewall throughput measured with App-ID and User-ID features enabled utilizing AppMix transactions.

Security Profiles

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Security Profiles
3838375
375
750
750

App-ID

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Custom App-ID signatures
6,0006,0006,000
6,000
6,000
6,000
Shared custom App-IDs
512
512
512
512
512
512
Custom App-IDs
(virtual system specific)
3,2081,000
6,416
1,000
6,416
6,416

User-ID

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
IP-User mappings (management plane)
524,288
524,288
524,288
524,288
524,288
524,288
IP-User mappings (data plane)
64,00064,00064,000
64,000
512,000
512,000
Active and unique groups used in policy (aggregate of LDAP groups, XML API Groups, and Dynamic User Group).*
1,000
1,000
1,000
1,000
10,000
10,000
Number of User-ID agents
100
100
100
100
100
100
Monitored servers for User-ID
100
100
100
100
100
100
Terminal server agents
400
400
400
400
2,0002,500
Tags per User*
(PAN-OS 9.1 and later)
32
32
32
32
32
32
*Firewall throughput measured with App-ID and User-ID features enabled utilizing AppMix transactions.

SSL Decryption

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Max SSL inbound certificates
1,000
1,000
1,000
1,000
1,000
1,000
SSL certificate cache
(forward proxy)
128128128
2,000
4,000
8,000
Max concurrent decryption sessions
1,0241,0246,40015,00050,000100,000
SSL Port Mirror
YesYesYes
Yes
Yes
Yes
SSL Decryption Broker
No No No
Yes
No
Yes
HSM Supported
YesYesYes
Yes
Yes
Yes

URL Filtering

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Total entries for allow list, block list and custom categories
25,000
25,000
25,000
25,000
25,000
100,000
Max custom categories
2,849
2,849
2,849
2,849
2,849
2,849
Max custom categories (virtual system specific)
500
500
500
500
500
500
Dataplane cache size for URL filtering
90,000
90,000
90,000
90,000
90,000
250,000
Management plane dynamic cache size
100,000
100,000
100,000
100,000
100,000
600,000

EDL

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Max number of custom lists
30
30
30
30
30
30
Max number of IPs per system
50,000
50,000
50,000
50,000
50,000
50,000
Max number of DNS Domains per system
50,000
50,000
50,000
5000,000
2,000,0002,000,00
Max number of URL per system
50,000
50,000
50,000
100,000
100,000
100,000
Shortest check interval (min)
5
5
5
5
5
5

Interfaces

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Mgmt - out-of-band
NA
NA
NA
NA
NA
NA
Mgmt - 10/100/1000 high availability
NA
NA
NA
NA
NA
NA
Mgmt - 40Gbps high availability
NA
NA
NA
NA
NA
NA
Mgmt - 10Gbps high availability
NA
NA
NA
NA
NA
NA
Traffic - 10/100/1000
NA
NA
NA
NA
NA
NA
Traffic - 100/1000/10000
NA
NA
NA
NA
NA
NA
Traffic - 1Gbps SFP
NA
NA
NA
NA
NA
NA
Traffic - 10Gbps SFP+
NA
NA
NA
NA
NA
NA
Traffic - 40/100Gbps QSFP+/QSFP28
NA
NA
NA
NA
NA
NA
802.1q tags per device
4,094
4,094
4,094
4,094
4,094
4,094
802.1q tags per physical interface
4,094
4,094
4,094
4,094
4,094
4,094
Max interfaces (logical and physical)
5125122,0482,048
4,096
40,96
Maximum aggregate interfaces
NA
NA
NA
NA
NA
NA
Maximum SD-WAN virtual interfaces
NA150300
500
1,000
1,000

Virtual Routers

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Virtual routers
3331020
125

Virtual Wires

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Virtual wires2412
12
12
12

Virtual Systems

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Base virtual systems
1
1
1
1
1
1
Max virtual systems
Additional licenses are required for virtual system capacities above the base virtual system’s capacity
NA
NA
NA
NA
NA
NA

Routing

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
IPv4 forwarding table size*
(Entries shared across virtual routers)
1,0002,5005,000
10,000
32,000
100,000
IPv6 forwarding table size*
(Entries shared across virtual routers)
1,0001,0005,000
10,000
32,000
100,000
System total forwarding table size
1,0001,0005,000
10,000
32,000
100,000
Max route maps per virtual router
505050
50
50
50
Max routing peers (protocol dependent)
500500500
500
1,000
1,000
Static entries - DNS proxy
1,0241,0241,024
1,024
1,024
1,024
Bidirectional Forwarding Detection (BFD) Sessions
N/AN/A128512
1,024
1,024
*Firewall throughput measured with App-ID and User-ID features enabled utilizing AppMix transactions.

L2 Forwarding

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
ARP table size per device
1,5001,5002,500
10,000
32,000
128,000
IPv6 neighbor table size
5005002,500
10,000
32,000
128,000
MAC table size per device
1,5001,5002,5005,000
32,000
128,000
Max ARP entries per broadcast domain
1,5001,5002,500
10,000
32,000
128,000
Max MAC entries per broadcast domain
1,5001,5002,500
5,000
32,000
128,000

NAT

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Total NAT rule capacity
1604003,000
5,000
8,000
8,000
Max NAT rules (static)*
(Configuring static NAT rules to full capacity requires that no other NAT rule types are used.)
1604003,000
5,000
8,000
8,000
Max NAT rules (DIP)*
(Configuring DIP NAT rules to full capacity requires that no other NAT rule types are used.)
1604002,000
3,000
8,000
8,000
Max NAT rules (DIPP)
160200400
800
2,000
2,000
Max translated IPs (DIP)
16,00016,000
128,000
128,000
160,000
160,000
Max translated IPs (DIPP)*
(DIPP translated IP capacity is proportional to the DIPP pool oversubscription value. The capacity shown here is based on an oversubscription value of 1x.)
200200400
800
2,000
2,000
Default DIPP pool oversubscription*
(Source IP and source port reuse across concurrent sessions)
2
2
2
2
88
*Firewall throughput measured with App-ID and User-ID features enabled utilizing AppMix transactions.

Address Assignment

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
DHCP servers
33310
20
125
DHCP relays*
(Maximum capacity represents total DHCP servers and DHCP relays combined)
500
500
500
500
500
500
Max number of assigned addresses64,00064,00064,00064,00064,00064,000
*Firewall throughput measured with App-ID and User-ID features enabled utilizing AppMix transactions.

High Availability

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Devices supported
2
2
2
2
2
2
Max virtual addresses
3232128
32
32
128

QoS

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Number of QoS policies
100
100
500
1,000
2,000
4,000
Physical interfaces supporting QoS
6
6
6
6
1212
Clear text nodes per physical interface
31
31
31
636363
DSCP marking by policy
Yes
Yes
Yes
Yes
Yes
Yes
Subinterfaces supported
NA
NA
NA
NA
NA
NA

IPSec VPN

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Max IKE Peers
25250
1,000
1,000
1,000
2,000
Site to site (with proxy id)
25
250
1,000
2,000
4,000
8,000
SD-WAN IPSec tunnels
NA
250
1,000
1,000
1,000
2,000

GlobalProtect Client VPN

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Max tunnels (SSL, IPSec, and IKE with XAUTH)
25
250
500
2,000
6,000
12,000

GlobalProtect Clientless VPN

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Max SSL tunnels
4040100
400
1,200
2,500

Multicast

Feature4.5 GB5.5 GB6.5 GB9 GB16 GB56 GB
Replication (egress interfaces)
100100100
100
100
100
Routes
500500
2,000
2,000
4,000
4,000