DEAG and DEAO Maximums:
We manage several hundred TZ's and NSA's, both Gen6 & 7
We use Dynamic External Address Groups to whitelist FQDNs from GAV, DPI-SSL, and App Control services.
This works great, however we seem to have reached a limit.
DEAG and DEAO Maximums:
Maximum DEAGs:
The maximum number of DEAGs, including both IP address and FQDN types, is 25% of the total number of address groups supported by the device.
The maximum number of DEAGs that can be created cannot exceed the number of address groups remaining before exceeding the total number supported on the firewall. For example, if a device supports 1024 Address Groups and you are using only 20 Address Groups, then 256 DEAGs (25% of 1024) can be created. However, if you have already manually created 1000 Address Groups, then only 24 DEAGs can be created.
Maximum DEAOs:
The maximum number of IP address type DEAOs is 25% of the total number of address objects supported by the device.
The maximum number of FQDN type DEAOs is 50% of the total number of address objects supported by the device.
The maximum number of DEAOs that can be created cannot exceed the number of address objects remaining before exceeding the total number supported on the firewall.
My question is:
Where can I find a data sheet that shows all the Firewalls and the DEAG/DEAO that each support?
Thanks
Graham
Best Answer
-
Saravanan Moderator
Hi @GrahamBarnes,
Thank you for visiting SonicWall Community.
Unfortunately, I don't think so that your requested information is handy available on the Datasheet. But this info can be procured from the SonicWall's TSR file. The info varies with firewall models and hence it is dynamic depending upon the hardware.
- Please download the TSR file from SonicWall as per above link.
- Open up the TSR file in Notepad or Notepad++.
- Search for keyword Address Objects_START and you could see the supported values for Max objects and Max groups.
Please try and let me know if this helps.
Regards
Saravanan V
Technical Support Advisor - Premier Services
Professional Services
0
Answers
Hi Saravanan,
That just what I need.
Thanks
Graham
You are most welcome @GRAHAMBARNES. It was a pleasure helping you. Have a good day!!!
Regards
Saravanan V
Technical Support Advisor - Premier Services
Professional Services
On a further comment on the limitations of DEAG objects: