Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
PhoneBoy
Admin
Admin

How Many Rules Supported? How Many Objects Supported?

We now have sk178325 that details the various limits related to the maximum number of:

  • Rules supported (per policy)
  • Objects supported (includes Multi-Domain specifics)
  • Objects per group
  • Changes per Publish operation
  • Interfaces per gateway (above and beyond the limits specified in sk31631)

Actual limits you experience will depend on a number of factors, as noted in the SK. 

9 Replies
the_rock
Legend
Legend

I recall even 15 years ago, number 10000 was always floating around : - )

Andy

0 Kudos
PhoneBoy
Admin
Admin

That number may have been valid in R7x and earlier for the number of rules.
In practice, if you've got a policy of several thousand rules, it's going to be hard to manage regardless of potential performance issues that result from using a large number of objects/rules.

0 Kudos
the_rock
Legend
Legend

Honestly, I cant think of any company on this planet that would even need 1000 rules, though I recall once seeing someone with 5000 + rules, probably 3000 of them disabled LOL

When I asked the guy the reason, he just told me they were scared to clean it up, JUST IN CASE...some people : - )

Andy

0 Kudos
S_E_
Advisor

hi,

there are companies who do have this request:

https://community.checkpoint.com/t5/Management/Maximum-number-of-rules-in-R80-40-and-above/m-p/13826...

But it is great that CheckPoint creates an official document with numbers/limitations. 

Regards

 

0 Kudos
S_E_
Advisor

hi,

b.t.w. is there also a SK for gateways ?

Limitations for BGP, routing table / max connections...

Appliance Sizing Tool (AST) /CPSizeMe is not really helpful in our cases.

Thanks/bye

0 Kudos
the_rock
Legend
Legend

I had personally never seen one.

Best,

Andy

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Max concurrent connections is reported on the appliance datasheets

Note it's otherwise a function of memory population and enabled blades.

CCSM R77/R80/ELITE
0 Kudos
the_rock
Legend
Legend

Make sure below is enabled, as it lets firewall calculate the connections based on the resourses available.

Andy

 

Screenshot_1.png

0 Kudos
S_E_
Advisor

hi yes, thanks. Just cross-checked and auto optimization seems to be default.

Data sheet mentioned 8M (for the lab but not real data) which is far beyond 400K connections.

Thanks

 

 
 

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events