<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic Distribution methodology in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-distribution-methodology/m-p/520079#M533</link>
    <description>&lt;P&gt;We have 35 PA firewalls all using SD-WAN and have (typically) the following configuration for WAN connections...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;100M TC4 Internet&lt;/P&gt;
&lt;P&gt;20M TC2 Internet (best quality)&lt;/P&gt;
&lt;P&gt;5G Cellular Internet (always on)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have the following traffic distribution profiles...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Critical Traffic - TC2, TC4, Cellular (top down priority)&lt;/P&gt;
&lt;P&gt;Standard Traffic - TC4, TC2, Cellular (top down priority)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Critical traffic is used for voice and internal web traffic, as well as AD services (dns, kerberos, ldap).&amp;nbsp; Standard traffic is used for anything else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have seen large amounts of traffic (approx. 400G/month) across the Cellular services.&amp;nbsp; I have done further inspection and not seen any failure of TC4 or TC2 services that correspond with dates when there are large amounts of traffic shown on the Cellular equipment.&amp;nbsp; Whilst the cellular service is an 'always on' (not dial on demand) the equipment provider (Cradlepoint) indicated keepalive/management traffic should be well les than 1G per day.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;As noted, the priority is a 'top down' configuration.&amp;nbsp; The best path for traffic is not necessarily the highest bandwidth.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Q:&amp;nbsp; What constitutes going to the next path in the selection order?&lt;/P&gt;
&lt;P&gt;Q:&amp;nbsp; Is top down the best approach?&lt;/P&gt;
&lt;P&gt;Q:&amp;nbsp; If not, what would the best approach be to ensure only fixed line services are used unless there is a total failure of both fixed line services?&lt;/P&gt;
&lt;P&gt;Q:&amp;nbsp; Should the above be used in conjunction with either/or/and Path Quality and SaaS Quality profiles?&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2022 21:33:22 GMT</pubDate>
    <dc:creator>Reece.Boucher</dc:creator>
    <dc:date>2022-11-02T21:33:22Z</dc:date>
    <item>
      <title>Traffic Distribution methodology</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-distribution-methodology/m-p/520079#M533</link>
      <description>&lt;P&gt;We have 35 PA firewalls all using SD-WAN and have (typically) the following configuration for WAN connections...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;100M TC4 Internet&lt;/P&gt;
&lt;P&gt;20M TC2 Internet (best quality)&lt;/P&gt;
&lt;P&gt;5G Cellular Internet (always on)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have the following traffic distribution profiles...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Critical Traffic - TC2, TC4, Cellular (top down priority)&lt;/P&gt;
&lt;P&gt;Standard Traffic - TC4, TC2, Cellular (top down priority)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Critical traffic is used for voice and internal web traffic, as well as AD services (dns, kerberos, ldap).&amp;nbsp; Standard traffic is used for anything else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have seen large amounts of traffic (approx. 400G/month) across the Cellular services.&amp;nbsp; I have done further inspection and not seen any failure of TC4 or TC2 services that correspond with dates when there are large amounts of traffic shown on the Cellular equipment.&amp;nbsp; Whilst the cellular service is an 'always on' (not dial on demand) the equipment provider (Cradlepoint) indicated keepalive/management traffic should be well les than 1G per day.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;As noted, the priority is a 'top down' configuration.&amp;nbsp; The best path for traffic is not necessarily the highest bandwidth.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Q:&amp;nbsp; What constitutes going to the next path in the selection order?&lt;/P&gt;
&lt;P&gt;Q:&amp;nbsp; Is top down the best approach?&lt;/P&gt;
&lt;P&gt;Q:&amp;nbsp; If not, what would the best approach be to ensure only fixed line services are used unless there is a total failure of both fixed line services?&lt;/P&gt;
&lt;P&gt;Q:&amp;nbsp; Should the above be used in conjunction with either/or/and Path Quality and SaaS Quality profiles?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 21:33:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-distribution-methodology/m-p/520079#M533</guid>
      <dc:creator>Reece.Boucher</dc:creator>
      <dc:date>2022-11-02T21:33:22Z</dc:date>
    </item>
  </channel>
</rss>

