cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4637
Views
20
Helpful
5
Replies

Network Object Limit on Cisco FMC

Garry Cooper
Level 1
Level 1

So initially we deployed a pair of FTD's 4120's running 6.6.4.

We ran into an problem with limits to groups size as we have more than 100 entries in some of our groups.  We had to split the groups, ( each group had not more that 100 in each).

Since upgrading to 6.6.4 we can add more to some of these groups.

Has anyone got any info on this as info from cisco as I cannot find or is unavailable.

 

TIA

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

yes that Limitation still i guess as for i know 6.6.X not sure 7.X  has any enhancement :

Looks some work around people doing :

 

https://community.cisco.com/t5/network-security/fmc-maximum-objects-in-an-object-group/td-p/3374958

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

mpetty001
Level 1
Level 1

After looking at the link to an earlier forum thread posted by Balaji (BB), I have to say I'm more than a little disappointed (but obviously not surprised in the slightest) that Cisco has had customers asking for this information literally for years, along with the fact that Cisco themselves programmed those arbitrary limits into the Firepower operating system, and even *increased* the number of allowed entries in later versions (I've noticed that just like the original poster), yet apparently they haven't deigned it important enough to document those limits or changes anywhere, despite the fact that numerous customers have hit the object limits previously.

nspasov
Cisco Employee
Cisco Employee

The limit (100) that you are hitting is for literal objects where you manually type/define and add the values to an object-group. If you don't use literals (Objects that are already created and saved in the FMC) then the limit is 2152 objects in an object-group. 

I hope this helps!

Thank you for rating helpful posts!

Thank you for rating helpful posts!

nspasov, thank you for following up! That clarification is very useful and good to know.

nspasov
Cisco Employee
Cisco Employee

Sure thing! I know it is more work to define and save the objects and then use them but that way the limit is much higher. Also, you can use the RestAPI or import to take care of bulk creations. 

Thank you for rating helpful posts!

Thank you for rating helpful posts!
Review Cisco Networking for a $25 gift card