<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Path Monitoring - latency in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/path-monitoring-latency/m-p/539062#M1154</link>
    <description>&lt;P&gt;I'm not using PAN SD-WAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have static route path monitoring configured for multiple ISPs.&amp;nbsp; If pings fail, the path goes down as expected.&lt;/P&gt;
&lt;P&gt;If the pings succeed, but latency is abnormally high, the path stays up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I set a latency threshold?&amp;nbsp; Ideally, I'd have a threshold for each monitored path such as 10ms for the next hop and 200ms for a host that's outside if the ISP's network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This would help automatically fail a route that isn't really working correctly.&lt;/P&gt;</description>
    <pubDate>Mon, 17 Apr 2023 18:51:10 GMT</pubDate>
    <dc:creator>jonathanb</dc:creator>
    <dc:date>2023-04-17T18:51:10Z</dc:date>
    <item>
      <title>Path Monitoring - latency</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/path-monitoring-latency/m-p/539062#M1154</link>
      <description>&lt;P&gt;I'm not using PAN SD-WAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have static route path monitoring configured for multiple ISPs.&amp;nbsp; If pings fail, the path goes down as expected.&lt;/P&gt;
&lt;P&gt;If the pings succeed, but latency is abnormally high, the path stays up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I set a latency threshold?&amp;nbsp; Ideally, I'd have a threshold for each monitored path such as 10ms for the next hop and 200ms for a host that's outside if the ISP's network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This would help automatically fail a route that isn't really working correctly.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2023 18:51:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/path-monitoring-latency/m-p/539062#M1154</guid>
      <dc:creator>jonathanb</dc:creator>
      <dc:date>2023-04-17T18:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: Path Monitoring - latency</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/path-monitoring-latency/m-p/539815#M1172</link>
      <description>&lt;P&gt;Hi Jonathanb,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To my knowledge you cannot configure latency threshold on a) static route monitoring, b) BFD monitoring, c) PBF rule with Monitor profile.&lt;/P&gt;
&lt;P&gt;All of the 3 above options monitor failures and not quality of the link/path.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In your scenario there are other options that might suit your needs. consider these two options below.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) QoS and assign different application different priorities.&lt;/P&gt;
&lt;P&gt;2) ECMP load balance the traffic between multiple ISP and if required assign weights to each specific ISP link.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 11:16:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/path-monitoring-latency/m-p/539815#M1172</guid>
      <dc:creator>Y-alwaysMe</dc:creator>
      <dc:date>2023-04-23T11:16:02Z</dc:date>
    </item>
  </channel>
</rss>

