Rule object members limit enhancement for Firewall Policy
Starting with this release of 10.1, Network Security Platform offers support for enhanced rule object member count for Firewall Policy.
Following table lists the maximum count of rule object members (Rule Members) that can be added under each rule object type:
|
Rule object type |
Rule Members (Maximum count) |
|---|---|
|
Host DNS Name |
5000 |
|
IPv4 Address Range |
20000 |
|
IPv4 Endpoint |
140000 |
|
IPv4 Network |
140000 |
|
IPv6 Address Range |
20000 |
|
IPv6 Endpoint |
140000 |
|
IPv6 Network |
140000 |
|
Application Group, Application on Custom Port, Finite Time Period, Network Group, Network Group for Ignore Rules, Recurring Time Period, Recurring Time Period Group, Service, Service Group, Service Range |
10 |
Note
The rule member count specified in the above table is applicable only for Firewall policy, and it varies with the Sensor model being used.
For QoS policy, Ignore Rules, Outbound SSL Decryption Exclusions, Quarantine Zones and NTBA Communication Rules, the maximum rule member count applicable for each rule object type is 10.
The above rule object count specified for IPv4/IPv6 based rule objects is also applicable for Central Managers starting 10.1.7.61. Central Managers running on older versions, however, support only 10 rule members per each rule object.
If you are using a Central Manager, do not add more than 10 entries in the Central Manager Rule Objects which are associated with QoS policies, Ignore Rules, Outbound SSL Decryption Exclusions, Quarantine Zones or Quarantine Exceptions in a Manager.
The following table lists the cumulative rule object member count of all the rule objects selected in a Firewall policy for each NS-series Sensor model. This table provides comparison of the limits supported on each Sensor model in this release and the previous releases.
| Model |
Cumulative rule object member count of all the rule objects selected |
|
|---|---|---|
| For Sensors before 10.1.5.170 | For Sensors starting 10.1.5.170 | |
| NS9500 stack - 100 Gbps throughput | 140000 | 240000 |
| NS9500 stack - 60 Gbps throughput | 140000 | 240000 |
| NS9500 stack - 40 Gbps throughput | 140000 | 170000 |
| NS9500 standalone - 30 Gbps throughput | 140000 | 240000 |
| NS9500 standalone - 20 Gbps throughput | 140000 | 240000 |
| NS9500 standalone - 10 Gbps throughput | 70000 | 170000 |
| NS9300 | 140000 | 240000 |
| NS9200 | 140000 | 240000 |
| NS9100 | 70000 | 170000 |
| NS7500 - 7.5 Gbps throughput | 35000 | 135000 |
| NS7500 - 5 Gbps throughput | 35000 | 135000 |
| NS7500 - 3Gbps throughput | 35000 | 135000 |
| NS7350 | 35000 | 135000 |
| NS7250 | 21000 | 121000 |
| NS7150 | 21000 | 121000 |
| NS7300 | 35000 | 135000 |
| NS7200 | 21000 | 121000 |
| NS7100 | 21000 | 121000 |
| NS5200 | 14000 | 34000 |
| NS5100 | 14000 | 34000 |
| NS3500 | 7000 | 17000 |
| NS3200/NS3100 | 7000 | 17000 |
Note
The increment in the cumulative rule member count for Sensors starting 10.1.5.170 is with respect to the Source and Destination Address fields you set in the Firewall Access Rules. This is done to support more IOCs (Indicators of compromise) for blocking matching traffic.
This release also comes with an option to enable automatic deployment of Firewall rule objects to specific Sensors whenever any changes are made in the Firewall Rule Objects. These changes include addition, deletion or modification of IPv4 and IPv6 addresses or CIDRs.
A new page has been added to enable users to automatically deploy Firewall rule objects to the Sensors. This page can be found under Devices → <Admin Domain Name> → Global → IPS Device Settings → Firewall Rule Objects.
Note
Automatic deployments are applicable only if:
The rule object being modified is of the following type: IPv4 Endpoint, IPv4 Network, IPv6 Endpoint, or IPv6 Network.
The rule object being modified is used in a Firewall policy and assigned to a Sensor running on software version 10.1.5.170 and later.
Terminology updates in the UI
This release contains the following terminology updates in the Manager UI:
| Navigation Path | Prior to 10.1.7.61 | 10.1.7.61 and later |
|---|---|---|
| Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions | The option available:
SSL Decryption Exclusions |
The option is renamed to Outbound SSL Decryption Exclusions |
| Policy → <Admin Domain Name> → Intrusion Prevention → Advanced → Policy Import | The option available:
SSL Decryption Exclusions |
The option is renamed to Outbound SSL Decryption Exclusions |
| Policy → <Admin Domain Name> → Intrusion Prevention → Advanced → Policy Export | The option available:
SSL Decryption Exclusions |
The option is renamed to Outbound SSL Decryption Exclusions |