<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The IP quantity limit of a NetworkFeed in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259677#M50932</link>
    <description>&lt;P&gt;How are the IPs listed in this file, individually, or in ranges?&lt;BR /&gt;Because I think the 50,000 refers to the number of items that refer directly to IPs or networks (by IP/mask or range).&lt;BR /&gt;The number of IPs can be much larger, I believe.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Oct 2025 19:40:14 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-10-10T19:40:14Z</dc:date>
    <item>
      <title>The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259512#M50896</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;the &lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm" target="_self"&gt;documentation&lt;/A&gt; states that a network feed:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;A Security Gateway supports up to 500 network feed objects. Each object can hold up to &lt;FONT color="#FF0000"&gt;50,000 IP addresses&lt;/FONT&gt;. There is no limitation on the number of domains per object.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;A Security Gateway supports a total of 5,000 objects of these types: Dynamic objects, Updatable objects, Generic Data Center objects, and &lt;FONT color="#FF0000"&gt;Network Feed objects&lt;/FONT&gt;. A Security Gateway supports a total of &lt;FONT color="#FF0000"&gt;350,000 IP addresses&lt;/FONT&gt; and 12,500 domains across all of these object types combined.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;In my Lab , I can see approximately 140,000 IP entries in the object "IPSUM1".&lt;BR /&gt;[Expert@CPSG:0]# dynamic_objects -efo &lt;FONT color="#FF0000"&gt;IPSUM1&lt;/FONT&gt; | wc -l&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;140842&lt;/FONT&gt;&lt;BR /&gt;[Expert@CPSG:0]# dynamic_objects -efo IPSUM1 | tail&lt;BR /&gt;range 140830 : 223.255.153.194 223.255.153.194&lt;BR /&gt;range 140831 : 223.255.163.249 223.255.163.249&lt;BR /&gt;range 140832 : 223.255.177.204 223.255.177.204&lt;BR /&gt;range 140833 : 223.255.183.10 223.255.183.10&lt;BR /&gt;range &lt;FONT color="#FF0000"&gt;140834&lt;/FONT&gt; : 223.255.183.18 223.255.183.18&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;My original understanding was that seeing 140,000 entries was because of rule 2, but due to rule 1, only 50,000 IP could be processed.&lt;BR /&gt;However, practical testing seems to show that it is not actually the case.&lt;BR /&gt;&lt;BR /&gt;I applied the network feed object to a policy and tested whether the firewall could block the 60,000th IP.&lt;BR /&gt;However, the firewall was still able to block it correctly.&lt;BR /&gt;[Expert@CPSG:0]# dynamic_objects -efo IPSUM1 | grep 60000&lt;BR /&gt;range 60000 : 103.86.1.22 103.86.1.22&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ipsum.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31683iEA44BF89E0EC0FB0/image-size/large?v=v2&amp;amp;px=999" role="button" title="ipsum.jpg" alt="ipsum.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;So what exactly does the 50,000 IP in rule1 mentioned here refer to?&lt;BR /&gt;Thank you!&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 05:06:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259512#M50896</guid>
      <dc:creator>TONYFU</dc:creator>
      <dc:date>2025-10-09T05:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259677#M50932</link>
      <description>&lt;P&gt;How are the IPs listed in this file, individually, or in ranges?&lt;BR /&gt;Because I think the 50,000 refers to the number of items that refer directly to IPs or networks (by IP/mask or range).&lt;BR /&gt;The number of IPs can be much larger, I believe.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 19:40:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259677#M50932</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-10-10T19:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259704#M50934</link>
      <description>&lt;P&gt;Interesting you ask, because when I spoke to TAC about it few months ago, guy told me would check internally and advised that documentation was actually wrong, that there was no limit. I believe that is 100% true, since I tested feed with 15M entries, no issues.&lt;/P&gt;
&lt;P&gt;I was hoping documentation would be corrected, but not yet.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 11 Oct 2025 11:24:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259704#M50934</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-11T11:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259706#M50935</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Sat, 11 Oct 2025 11:55:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259706#M50935</guid>
      <dc:creator>TONYFU</dc:creator>
      <dc:date>2025-10-11T11:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259710#M50936</link>
      <description>&lt;P&gt;Glad we can help!&lt;/P&gt;</description>
      <pubDate>Sat, 11 Oct 2025 13:34:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259710#M50936</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-11T13:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259715#M50937</link>
      <description>&lt;P&gt;For the context, Fortinet feeds are limited to 32000 entries, so really noticeable difference.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 11 Oct 2025 17:56:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/259715#M50937</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-11T17:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274426#M104543</link>
      <description>&lt;P&gt;What about domains limit for network feed?&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 06:53:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274426#M104543</guid>
      <dc:creator>C0rwin</dc:creator>
      <dc:date>2026-03-30T06:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274470#M104558</link>
      <description>&lt;P&gt;The various limits for Network Feeds are in the documentation:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm&lt;/A&gt;&lt;BR /&gt;For domains specifically, it states: "&lt;SPAN&gt;There is no limitation on the number of domains per object."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 14:54:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274470#M104558</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-03-30T14:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274523#M104578</link>
      <description>&lt;P&gt;But there is also statement -&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;A Security Gateway supports a total of 350,000 IP Addresses&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;and &lt;STRONG&gt;12,500 domains&lt;/STRONG&gt; across all of these object types combined.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So is it possible and supported to use network feed with domains up to the mentioned limit? Any experience with that.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm asking about it - because I found on cluster R82 JHF Take_60 huge issue with network feed containing 150k domains - cpu spikes, failovers, lack of responsivness during policy install or feed refresh time.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;BR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Daniel&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 06:35:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274523#M104578</guid>
      <dc:creator>C0rwin</dc:creator>
      <dc:date>2026-03-31T06:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274585#M104592</link>
      <description>&lt;P&gt;You're right, maybe we can fix that contradiction.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2208"&gt;@Sergei_Shir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sounds like you're exceeding the limit of 12,500 domains by a factor of 10, which might explain the behavior.&lt;BR /&gt;TAC might be able to suggest an adjustment you an make to support that many.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 22:54:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274585#M104592</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-03-31T22:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274597#M104597</link>
      <description>&lt;P&gt;TAC already suggested and we moved public feed to internal one - divided it to many network feeds up to 10k, but it didn't solve the issue. Every update of single network feed with 10k domains is also causing cpu spikes, failovers, cpu soft lockup etc.&lt;/P&gt;&lt;P&gt;TAC suggested RFE but it seems that we need to move from network feed to external ioc feed in TP policy to make it work without impact.&lt;/P&gt;&lt;P&gt;What's a pitty that network feed has such huge limitation.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Daniel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2026 06:32:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274597#M104597</guid>
      <dc:creator>C0rwin</dc:creator>
      <dc:date>2026-04-01T06:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274651#M104623</link>
      <description>&lt;P&gt;The limits are "total per gateway" not "per feed" which explains why splitting the feeds up didn't work.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2026 14:20:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274651#M104623</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-04-01T14:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274687#M104637</link>
      <description>&lt;P&gt;So it seems to be really poor mechanism for resolving dns in background written for network feed. I did similar test in demopoint and results are the same:&lt;/P&gt;&lt;P&gt;- network feed with about 150k domains = performance issues, rad errors in fwk.elg etc.&lt;/P&gt;&lt;P&gt;- external ioc feed with the same number of 150k domains working fine, even if by default there is 5 min refresh for feed&lt;/P&gt;&lt;P&gt;BR&amp;nbsp;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2026 20:10:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274687#M104637</guid>
      <dc:creator>C0rwin</dc:creator>
      <dc:date>2026-04-01T20:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274859#M104705</link>
      <description>&lt;P&gt;Please clarify, what is the required correction in the admin guide?&lt;/P&gt;</description>
      <pubDate>Sun, 05 Apr 2026 06:55:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274859#M104705</guid>
      <dc:creator>Ronit_Segal</dc:creator>
      <dc:date>2026-04-05T06:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: The IP quantity limit of a NetworkFeed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274926#M104717</link>
      <description>&lt;P&gt;Under the "Use Cases" section, the second and third bullet points conflict with each other.&lt;BR /&gt;The second bullet point says "no limit" where the third bullet point clearly states there is (not in the object, but at the gateway level).&lt;BR /&gt;This is where the confusion lies.&lt;BR /&gt;I would remove the statement "There is no limitation on the number of domains per object" to make it more clear.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33947i74BA6C7E2D119A37/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2026 15:54:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-IP-quantity-limit-of-a-NetworkFeed/m-p/274926#M104717</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-04-06T15:54:28Z</dc:date>
    </item>
  </channel>
</rss>

