Maximum mappings per device

The identity module is optimized to accommodate a higher number of mappings. The mappings include users, shared users, ISE Exchange Protocol (SXP), and Attribute-Based Policy (ABP) IP bindings. The maximum number of mappings depends on the managed device model. A single user can have multiple sessions from different IP addresses. An IP address can have multiple mappings.

This table shows the maximum number of mappings and the experimental enhanced values for each Firewall Threat Defense device.

Maximum Mapping Limits by Firewall Threat Defense

Firewall Threat Defense Model

Maximum Mappings

Enhanced Maximum Mappings (Beta)*

Firewall Threat Defense Virtual 1:

  • 4 vCPU / 8 GB RAM

  • 8 vCPU / 16 GB RAM

  • 12 vCPU / 24 GB RAM

  • 16 vCPU / 32 GB RAM

50,000

128,000

Firewall Threat Defense Virtual 1:

  • 32 vCPU / 64 GB RAM

  • 64 vCPU / 128 GB RAM

50,000

300000

Secure Firewall 220

10,000

10,000

Firepower 1010, 1120, 1140, 1150 1

50,000

128,000

Firepower 1210, 1220, 1230, 1240, 1250 1

50,000

128,000

Firepower 2110, 2120, 2130 1

50,000

NA

Firepower 2140

150,000

NA

Secure Firewall 3105, 3110, 3120, 3130, 3140 1

50,000

300,000

Firepower 4112, 4115, 4125, 4145, 4215

150,000

300,000

Firepower 9300 2

225,000

300,000

Secure Firewall 4225, 4245

300,000

600,000

Secure Firewall 6160, 6170

300,000

600,000

The Secure Firewall 200 series devices can download a cumulative total of 10,000 user IPs, SXP/SGT mappings, endpoint profiles, and dynamic objects. After reaching the total of 10,000, the device stops downloading new objects until previously downloaded objects are removed. For example, when users log out, the memory frees space for other objects.

1 These devices support a maximum of 64,000 mappings when you restrict to using only Active Directory user mappings.

2 This device supports a maximum of 300,000 mappings when you restrict to using only Active Directory user mappings.

Maximum unique user groups and dynamic objects in a policy (Beta)*

An access control policy supports the following number of unique user groups and dynamic objects, across all device models.

  • Maximum number of AD and Azure AD groups: 4,000

  • Maximum number of dynamic objects: 8,000

These values are experimental. Typically, an IP address can be associated with 32 unique dynamic objects. A user can normally be associated with 32 groups.

Note

*This is a Beta feature. Enabling enhanced maximum mappings may increase memory utilization on the firewall in larger scale deployments. Carefully evaluate and monitor the use of this feature in your environment.