The quick answer is 1500. I was asked to go redo one of the school's topology where the "bring your own device" network was having problems. They had around 1700 devices that would attach to this network. So what happens when 1501 entries get put in the ARP table on the PA-3020? Nothing, except that 1501 cant be in the ARP table. The PA-3020 is limited to 1500 entries. Therefor, there will never be 1501 entries on this device. I verified this on Palo Alto's site:
https://live.paloaltonetworks.com/docs/DOC-4011
Here is the topology:
I had to do a few things to get this going. Create a vlan between the Palo Alto and the Brocade Core Switch. IP the wireless vlan to be the default gateway (that used to be the Palo Alto, now the Core Switch). Add a static route on the Palo Alto to point the wireless network to the Core Switch. And add a route-map on the Brocade Core Switch so that the wireless traffic wont take the default route, but the path of the Palo Alto.
So, why did we change the topology? Because the Brocade Core Switch can handle a whole lot more ARP entries than the Palo Alto.
This is the retired Shane Killen personal blog, an IT technical blog about configs and topics related to the Network and Security Engineer working with Cisco, Brocade, Check Point, and Palo Alto and Sonicwall. I hope this blog serves you well. -- May The Lord bless you and keep you. May He shine His face upon you, and bring you peace.
Subscribe to:
Post Comments (Atom)
Updated - With the release of 6.0, the 3020 can now support 3000 arp entries but you will need to issue an unlock command and restart the firewall for it to take effect.
ReplyDeleteVery good. Thanks for the update.
ReplyDeleteVery good. Thanks for the update.
ReplyDelete