<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Supported SR-IOV for Palo Alto in WS in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/supported-sr-iov-for-palo-alto-in-ws/m-p/366146#M1058</link>
    <description>&lt;P&gt;&lt;BR /&gt;SR-IOV and DPDK can be enabled simultaneously.&lt;/P&gt;&lt;P&gt;Slightly misleadingly, SR-IOV is assisted by the network card and DPDK is assisted by the CPU.&lt;BR /&gt;&lt;A href="https://en.wikipedia.org/wiki/Data_Plane_Development_Kit" target="_blank"&gt;https://en.wikipedia.org/wiki/Data_Plane_Development_Kit&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://en.wikipedia.org/wiki/Single-root_input/output_virtualization" target="_blank"&gt;https://en.wikipedia.org/wiki/Single-root_input/output_virtualization&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Enabling SR-IOV bypasses the hypervisor that exists between the PAN-OS(VM-Series) and physical NICs.&lt;/P&gt;&lt;P&gt;Enabling DPDK bypasses the PAN-OS (linux kernel) that resides between the NIC bypassed by SR-IOV and the pan_task (a process that represents the data plane).&lt;/P&gt;&lt;P&gt;DPDK is effective for simple processes such as just moving data from east to west, raising the limit from around 20 Gbps to around 100 Gbps.&lt;/P&gt;&lt;P&gt;I think DPDK probably won't be effective until Threat Prevention's throughput exceeds 30 Gbps, which is not very useful at the moment.&lt;BR /&gt;In other words, I don't think it's very useful at this time (the unconfigured defaults should be the most secure).&lt;/P&gt;&lt;P&gt;Where DPDK is useful is in eliminating most of the bottlenecks, even in configurations that connect via Open vSwitch (OVS).&lt;/P&gt;&lt;P&gt;Here are Intel's test results&lt;BR /&gt;&lt;A href="https://builders.intel.com/docs/networkbuilders/demonstrating-data-plane-performance-improvements-using-enhanced-platform-awareness.pdf" target="_blank"&gt;https://builders.intel.com/docs/networkbuilders/demonstrating-data-plane-performance-improvements-using-enhanced-platform-awareness.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It should be possible to use OVS in AWS as well, but there should be little benefit to using it (although I did some research).&lt;/P&gt;&lt;P&gt;Therefore, I think it's enough to just enable SR-IOV, and I think it's safer to not change the default.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Nov 2020 04:17:58 GMT</pubDate>
    <dc:creator>nanasin</dc:creator>
    <dc:date>2020-11-30T04:17:58Z</dc:date>
    <item>
      <title>Supported SR-IOV for Palo Alto in WS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/supported-sr-iov-for-palo-alto-in-ws/m-p/365659#M1056</link>
      <description>&lt;P&gt;Hello everybody,&lt;BR /&gt;I see that we have SR-IOV and DPDK modes supported for Palo Alto in AWS and understand that DPDK is proffered mode which provides fast processing. &lt;A href="http://www.192168101.com/" target="_self"&gt;&lt;FONT color="#FFFFFF"&gt;192168101.com&lt;/FONT&gt;&lt;/A&gt;&lt;BR /&gt;so are there any specific situation where SR-IOV mode is preferred over DPDK?&lt;BR /&gt;are you know? &lt;A href="https://19216811.dev/" target="_self"&gt;&lt;FONT color="#FFFFFF"&gt;19216811.dev&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2020 03:50:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/supported-sr-iov-for-palo-alto-in-ws/m-p/365659#M1056</guid>
      <dc:creator>MarnieFellows</dc:creator>
      <dc:date>2020-11-29T03:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Supported SR-IOV for Palo Alto in WS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/supported-sr-iov-for-palo-alto-in-ws/m-p/366146#M1058</link>
      <description>&lt;P&gt;&lt;BR /&gt;SR-IOV and DPDK can be enabled simultaneously.&lt;/P&gt;&lt;P&gt;Slightly misleadingly, SR-IOV is assisted by the network card and DPDK is assisted by the CPU.&lt;BR /&gt;&lt;A href="https://en.wikipedia.org/wiki/Data_Plane_Development_Kit" target="_blank"&gt;https://en.wikipedia.org/wiki/Data_Plane_Development_Kit&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://en.wikipedia.org/wiki/Single-root_input/output_virtualization" target="_blank"&gt;https://en.wikipedia.org/wiki/Single-root_input/output_virtualization&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Enabling SR-IOV bypasses the hypervisor that exists between the PAN-OS(VM-Series) and physical NICs.&lt;/P&gt;&lt;P&gt;Enabling DPDK bypasses the PAN-OS (linux kernel) that resides between the NIC bypassed by SR-IOV and the pan_task (a process that represents the data plane).&lt;/P&gt;&lt;P&gt;DPDK is effective for simple processes such as just moving data from east to west, raising the limit from around 20 Gbps to around 100 Gbps.&lt;/P&gt;&lt;P&gt;I think DPDK probably won't be effective until Threat Prevention's throughput exceeds 30 Gbps, which is not very useful at the moment.&lt;BR /&gt;In other words, I don't think it's very useful at this time (the unconfigured defaults should be the most secure).&lt;/P&gt;&lt;P&gt;Where DPDK is useful is in eliminating most of the bottlenecks, even in configurations that connect via Open vSwitch (OVS).&lt;/P&gt;&lt;P&gt;Here are Intel's test results&lt;BR /&gt;&lt;A href="https://builders.intel.com/docs/networkbuilders/demonstrating-data-plane-performance-improvements-using-enhanced-platform-awareness.pdf" target="_blank"&gt;https://builders.intel.com/docs/networkbuilders/demonstrating-data-plane-performance-improvements-using-enhanced-platform-awareness.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It should be possible to use OVS in AWS as well, but there should be little benefit to using it (although I did some research).&lt;/P&gt;&lt;P&gt;Therefore, I think it's enough to just enable SR-IOV, and I think it's safer to not change the default.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 04:17:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/supported-sr-iov-for-palo-alto-in-ws/m-p/366146#M1058</guid>
      <dc:creator>nanasin</dc:creator>
      <dc:date>2020-11-30T04:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Supported SR-IOV for Palo Alto in WS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/supported-sr-iov-for-palo-alto-in-ws/m-p/375177#M1088</link>
      <description>&lt;P&gt;Supported SR-IOV for Palo Alto in WS. Hello everybody,I see that we have SR-IOV and DPDK modes supported for Palo Alto in AWS and understand that DPDK&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 10:10:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/supported-sr-iov-for-palo-alto-in-ws/m-p/375177#M1088</guid>
      <dc:creator>Sidneyy</dc:creator>
      <dc:date>2020-12-18T10:10:29Z</dc:date>
    </item>
  </channel>
</rss>

