USG FLEX H series external block list records limit

Options
Mk88_it
Mk88_it Posts: 80 image  Ally Member
First Comment Friend Collector Fourth Anniversary

Hello,

The online guide and the PDF manual for the H-series firewalls specify that there is a limit of 50,000 records for external block lists.
On Nebula, I haven't seen this limitation mentioned anywhere.
Does this limitation apply to both on-premises and Nebula deployments for the H series?
If so, would it be possible to remove this limitation? These lists usually have far more than 50,000 records...

Thank you

Accepted Solution

  • Zyxel_Tina
    Zyxel_Tina Posts: 813 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
    Answer ✓

    Hi @Mk88_it,

    Thank you for sharing the specific lists.

    To answer your question: The 50,000-record limit for external block lists applies to the H-series in both on-premises and Nebula deployments. This is a fixed system specification for custom external lists at this time.

    Since the lists you mentioned significantly exceed this limit, we recommend a "hybrid" approach using the IP Reputation service (included in the Gold Security Pro pack):

    • Built-in Capacity: The IP Reputation service provides a pre-defined database of over 700,000 entries. It is specifically designed to handle the scale of global threat intelligence that you are looking for.
    • Custom Flexibility: You can reserve the 50,000-record external list slots for specialized or private lists that are not covered by global threat databases.

    This way, you can achieve the security coverage you need without being restricted by the manual import limit.

    Zyxel Tina

All Replies

  • Zyxel_Tina
    Zyxel_Tina Posts: 813 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments

    Hi @Mk88_it,

    Regarding your request to remove this limitation, may I first ask what your use case is and approximately how many records you would need for the external block lists?

    Zyxel Tina

  • Mk88_it
    Mk88_it Posts: 80 image  Ally Member
    First Comment Friend Collector Fourth Anniversary

    Hello @Zyxel_Tina Yes, It's easy I would like to connect my lists to improve the security preventing inbound and outbound connections to known bad IPs and DNS name. For example these list have all over 50k records

    GitHub - hagezi/dns-blocklists: DNS-Blocklists: For a better internet - keep the internet clean! · GitHub

    GitHub - bitwire-it/ipblocklist: IP lists full of bad IPs - Updated every 2H · GitHub

  • Mk88_it
    Mk88_it Posts: 80 image  Ally Member
    First Comment Friend Collector Fourth Anniversary

    Hello @Zyxel_Tina do you have something for me?

  • Zyxel_Tina
    Zyxel_Tina Posts: 813 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
    Answer ✓

    Hi @Mk88_it,

    Thank you for sharing the specific lists.

    To answer your question: The 50,000-record limit for external block lists applies to the H-series in both on-premises and Nebula deployments. This is a fixed system specification for custom external lists at this time.

    Since the lists you mentioned significantly exceed this limit, we recommend a "hybrid" approach using the IP Reputation service (included in the Gold Security Pro pack):

    • Built-in Capacity: The IP Reputation service provides a pre-defined database of over 700,000 entries. It is specifically designed to handle the scale of global threat intelligence that you are looking for.
    • Custom Flexibility: You can reserve the 50,000-record external list slots for specialized or private lists that are not covered by global threat databases.

    This way, you can achieve the security coverage you need without being restricted by the manual import limit.

    Zyxel Tina