: Cloud NGFW for Azure Limits and Quotas
Focus
Focus

Cloud NGFW for Azure Limits and Quotas

Table of Contents

Cloud NGFW for Azure Limits and Quotas

Learn the limits and quotas of the Cloud NGFW for Azure.
The following tables list the limits and performance data for your Cloud NGFW tenant. Unless indicated otherwise, you can request an increase for these limits.
Use the Cloud NGFW for Azure pricing estimator to help you determine Azure limits and quotas for your Cloud NGFW subscription.

Local Rulestack Policy Management

Name
Default Limits per Cloud NGFW Tenant
Adjustable
Number of Cloud (Azure) accounts in a tenant
200
No
Cloud NGFW Resources in a Tenant
50 per account per region
No
Cloud NGFW Endpoints in a Tenant
50 per account per region
N/A
Cloud NGFW Endpoints for each Cloud NGFW Resource
50
Yes
Outstanding Global Rulestacks not associated with NGFW Resources
10
Yes
Outstanding Local Rulestacks not associated with NGFW Resources
10
No
To change any of the adjustable limits listed above, contact Palo Alto Networks Customer Support.

Native Policy Management (Rulestack)

Attribute
Maximum Limit per Cloud NGFW Resource
Adjustable
Security rules
1,000
No
Addresses objects (FQDN list and IP prefix lists)
1,000
No
Number of IP prefix list
1,000
No
FQDN objects across all FQDN lists
2,000
No
Prefix objects for each IP prefix list
2,500
No
URLs across all URL categories
25,000
No
Intelligent feeds (including the five predefined feeds)
30
No
IP addresses across all feeds
50,000
No
Certificate objects
100
No

Panorama Policy Management

Attribute
Maximum Limit per Cloud NGFW Resource*
Policy
Security rules
10,000
Decryption rules
1,000
Objects
Address objects
10,000
Address groups
1,000
Members per address group
2,500
FQDN address groups
2,000
Service objects
2,000
Service groups
500
Members per service group
500
EDL
Max number of DNS per domain system
500,000
Max number of IPs per system
50,000
Max number of URLs per system
100,000
Max number of custom lists
30
URL Filtering
Total entities for allow list, block list and custom categories
25,000
Max custom categories
500
* The limits on policy and objects specified are unidimensional maximum. Palo Alto Networks recommends additional testing within your environment to ensure you meet your policy authoring objectives.

Cloud NGFW for Azure Performance

The following table provides performance information for your Cloud NGFW for Azure tenant.
The information provided in the following table assumes a maximum of 40 instances.
Attribute
Performance metric
Firewall Throughput (App-ID enabled)
Maximum throughput: 100 Gbps; per instance is 2.92 Gbps
Coldstart: 8.55 Gbps
For coldstart traffic, Content Threat Detection is enabled. Without Content Threat Protection, each firewall instance is capped at 3.00 Gbps due to the instance type. This is an Azure limitation.
Threat Prevention Throughput
Maximum throughput: 92 Gbps; per instance is 2.31 Gbps
Encrypted Traffic Throughput
44 Gbps (with Content Threat Detection); per instance is 1.11 Gbps
60 Gbps (without Content Threat Detection); per instance is 1.52 Gbps