<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SD-WAN Traffic Control from the Hub Side in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sd-wan-traffic-control-from-the-hub-side/m-p/997531#M5206</link>
    <description>&lt;P&gt;Good Day&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not sure which version of the SDWAN solution (PanOS vs Prisma SDWAN) you are using, so I am presuming PANOS SDWAN, else you would have mentioned IONs and SCM configurations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did not hear mention of the required Panorama and SDWAN licensing in your query.&amp;nbsp; I presume the SDWAN licensing has been utilized.&lt;/P&gt;
&lt;P&gt;Can you just confirm that Panorama is also part of the solution, so push down the configurations from the Panorama to the FWs (both HuB and Branch sites)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have 3 uplinks of various speeds, the SDWAN configurations (presuming you are using Panorama with current SDWAN plugin) and FWs with the correct SDWAN licensing, should utilize the expected feature that the best link should be used in communicating from Branch to Hub.&amp;nbsp; How much Hub-sourced to Branch-destined traffic is occurring.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may want to speak with your local PANW Domain Consultant (formerly SEs) to further assistance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Dec 2024 20:30:24 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2024-12-10T20:30:24Z</dc:date>
    <item>
      <title>SD-WAN Traffic Control from the Hub Side</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sd-wan-traffic-control-from-the-hub-side/m-p/996955#M5179</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;our Palo Alto on the HUB side is equipped with a single 10G uplink interface. On the Spoke side, there are three uplinks with varying bandwidths, and in this setup, the Panorama SD-WAN plugin generates three IPsec tunnels. I can manage traffic from the Spoke to the HUB using SD-WAN Rules and Traffic Distribution Profiles.&lt;/P&gt;
&lt;P&gt;However, is it possible to control traffic from the HUB to the Spoke? Currently, traffic is evenly distributed across all three links. This causes issues, as a link with very low bandwidth is also used, leading to congestion and degraded performance.&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;BR /&gt;&amp;nbsp;Dirk&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 12:23:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sd-wan-traffic-control-from-the-hub-side/m-p/996955#M5179</guid>
      <dc:creator>D.Henze</dc:creator>
      <dc:date>2024-12-06T12:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Traffic Control from the Hub Side</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sd-wan-traffic-control-from-the-hub-side/m-p/997531#M5206</link>
      <description>&lt;P&gt;Good Day&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not sure which version of the SDWAN solution (PanOS vs Prisma SDWAN) you are using, so I am presuming PANOS SDWAN, else you would have mentioned IONs and SCM configurations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did not hear mention of the required Panorama and SDWAN licensing in your query.&amp;nbsp; I presume the SDWAN licensing has been utilized.&lt;/P&gt;
&lt;P&gt;Can you just confirm that Panorama is also part of the solution, so push down the configurations from the Panorama to the FWs (both HuB and Branch sites)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have 3 uplinks of various speeds, the SDWAN configurations (presuming you are using Panorama with current SDWAN plugin) and FWs with the correct SDWAN licensing, should utilize the expected feature that the best link should be used in communicating from Branch to Hub.&amp;nbsp; How much Hub-sourced to Branch-destined traffic is occurring.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may want to speak with your local PANW Domain Consultant (formerly SEs) to further assistance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 20:30:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sd-wan-traffic-control-from-the-hub-side/m-p/997531#M5206</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2024-12-10T20:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Traffic Control from the Hub Side</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sd-wan-traffic-control-from-the-hub-side/m-p/998038#M5220</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thank you very much.&lt;/P&gt;
&lt;P&gt;You are absolutely correct; we are using PANOS SD-WAN, and the SD-WAN licensing has been utilized.&lt;BR /&gt;I can also confirm that we exclusively use the Panorama SD-WAN configuration.&lt;/P&gt;
&lt;P&gt;The communication from the branch side works as expected. However, I am unable to control the traffic flow from the hub to the branch side.&lt;BR /&gt;It seems that traffic from the hub to the branch side is distributed in a round-robin fashion across all three tunnel interfaces.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 11:32:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sd-wan-traffic-control-from-the-hub-side/m-p/998038#M5220</guid>
      <dc:creator>D.Henze</dc:creator>
      <dc:date>2024-12-12T11:32:19Z</dc:date>
    </item>
  </channel>
</rss>

