<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto  QOS configuration question in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-qos-configuration-question/m-p/1236274#M6224</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149928371"&gt;@ciscojuniperf5&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Two important notes that you need to remember for PAN QoS &lt;BR /&gt;- Traffic is "labeled" with &lt;STRONG&gt;class4&lt;/STRONG&gt; by default, if no class is explicitly assigned to the traffic.&lt;/P&gt;
&lt;P&gt;- QoS is applied on&amp;nbsp;&lt;STRONG&gt;egress only&lt;/STRONG&gt;. Which means if you want to limit download from public internet you need to apply the QoS profile on the inside interface (when traffic egress from the firewall to the user). If you want to limit/shape the upload to public Internet, you need to apply the QoS profile on the outside interface (when traffic egress from firewall to Interne)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;It is not clear which is your public interface and which internal, but I would guess (based on the sub-interface to Veem) that eth1/6 is your inside interface, which means that applying a QoS there will shape/limit the download from Internet. If am understand you are trying to limit the upload from Veem to Wasabi, correct?&lt;/P&gt;
&lt;P&gt;If that is the case you need QoS interface for your public interface. Under the Clear Text Traffic tab, configure the same rule - where you use 1/6.201 as source and Veem QoS profile. This will tell the firewall to apply the Veem QoS profile when traffic is sourced from eth1/6.201 and egressing to public internet.&lt;/P&gt;
&lt;P&gt;Note that -&amp;nbsp;"Default Profile" under the QoS Interface is the profile that will be applied the traffic that is egressing this interface and does not match any of the "rules" under the Clear Text Traffic tab.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Aug 2025 22:50:34 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2025-08-19T22:50:34Z</dc:date>
    <item>
      <title>Palo Alto  QOS configuration question</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-qos-configuration-question/m-p/1235574#M6173</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;created the below QOS configuration to limit the bandwidth to wasabi to 10 mbps on PA 440. When I checked the QOS statistics, the default group is getting used and not the one I created and also the default group is restricted to 10 Mbps. Please guide me how do I fix it.&lt;/P&gt;&lt;P&gt;Interface Ethernet 1/6 has a subinterface Ethernet 1/6.201.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create the QoS Policy Rule&lt;/P&gt;&lt;P&gt;Navigate to Policies &amp;gt; QoS.&lt;/P&gt;&lt;P&gt;Click Add to create a new QoS policy rule.&lt;/P&gt;&lt;P&gt;Name : Limit Veeam Backup&lt;/P&gt;&lt;P&gt;Source Zone : Trust&lt;/P&gt;&lt;P&gt;Source Address : Select All VMs&lt;/P&gt;&lt;P&gt;Destination Zone: Untrust&lt;/P&gt;&lt;P&gt;Destination Address : Wasabi&lt;/P&gt;&lt;P&gt;Application : wasabi&lt;/P&gt;&lt;P&gt;Other settings: Class 8&lt;/P&gt;&lt;P&gt;Click OK&lt;/P&gt;&lt;P&gt;Create a QoS Profile:&lt;/P&gt;&lt;P&gt;Navigate to Network &amp;gt; Network Profiles &amp;gt; QoS.&lt;/P&gt;&lt;P&gt;Click Add to create a new QoS Profile. "Veeam-Backup-QoS"&lt;/P&gt;&lt;P&gt;Egress Max (MBPS): 10&lt;/P&gt;&lt;P&gt;Egress Guaranteed (MBPS): 0&lt;/P&gt;&lt;P&gt;1.25 MBPS = 10 Mbps&lt;/P&gt;&lt;P&gt;In the Classes section, click Add:&lt;/P&gt;&lt;P&gt;Class: Class 8&lt;/P&gt;&lt;P&gt;Priority: Low&lt;/P&gt;&lt;P&gt;Egress Max: 10&lt;/P&gt;&lt;P&gt;Egress Guaranteed: 0&lt;/P&gt;&lt;P&gt;Click OK&lt;/P&gt;&lt;P&gt;Enable QoS on the Interface:&lt;/P&gt;&lt;P&gt;Navigate to Network &amp;gt; QoS&lt;/P&gt;&lt;P&gt;Select Ethernet 1/6&lt;/P&gt;&lt;P&gt;Under the Default Profile, select the QoS profile "Veeam-Backup-QoS"&lt;/P&gt;&lt;P&gt;Set the Egress Max (Mbps): 1024&lt;/P&gt;&lt;P&gt;Under Clear Text Traffic&lt;/P&gt;&lt;P&gt;Egress Guaranteed (Mbps) = 0&lt;/P&gt;&lt;P&gt;Egress Max (Mbps) = 10&lt;/P&gt;&lt;P&gt;Name :Veeam&lt;/P&gt;&lt;P&gt;Qos Profile : "Veeam-Backup-QoS"&lt;/P&gt;&lt;P&gt;Source Interface : Ethernet 1/6.201&lt;/P&gt;&lt;P&gt;Click OK&lt;/P&gt;&lt;P&gt;QOS settings on interface:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ciscojuniperf5_1-1754548028266.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68781i6C4912A7FB910AA0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ciscojuniperf5_1-1754548028266.png" alt="ciscojuniperf5_1-1754548028266.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I set the default profile to default, Veeam is getting more bandwidth, when I set it to Veeam-Backup-QOS, All traffic get 10 Mbps&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ciscojuniperf5_2-1754548044354.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68782iE0F6DB52284E9A10/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ciscojuniperf5_2-1754548044354.png" alt="ciscojuniperf5_2-1754548044354.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ciscojuniperf5_4-1754548077387.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68784i443D112C5889F459/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ciscojuniperf5_4-1754548077387.png" alt="ciscojuniperf5_4-1754548077387.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2025 06:29:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-qos-configuration-question/m-p/1235574#M6173</guid>
      <dc:creator>ciscojuniperf5</dc:creator>
      <dc:date>2025-08-07T06:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  QOS configuration question</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-qos-configuration-question/m-p/1236274#M6224</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149928371"&gt;@ciscojuniperf5&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Two important notes that you need to remember for PAN QoS &lt;BR /&gt;- Traffic is "labeled" with &lt;STRONG&gt;class4&lt;/STRONG&gt; by default, if no class is explicitly assigned to the traffic.&lt;/P&gt;
&lt;P&gt;- QoS is applied on&amp;nbsp;&lt;STRONG&gt;egress only&lt;/STRONG&gt;. Which means if you want to limit download from public internet you need to apply the QoS profile on the inside interface (when traffic egress from the firewall to the user). If you want to limit/shape the upload to public Internet, you need to apply the QoS profile on the outside interface (when traffic egress from firewall to Interne)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;It is not clear which is your public interface and which internal, but I would guess (based on the sub-interface to Veem) that eth1/6 is your inside interface, which means that applying a QoS there will shape/limit the download from Internet. If am understand you are trying to limit the upload from Veem to Wasabi, correct?&lt;/P&gt;
&lt;P&gt;If that is the case you need QoS interface for your public interface. Under the Clear Text Traffic tab, configure the same rule - where you use 1/6.201 as source and Veem QoS profile. This will tell the firewall to apply the Veem QoS profile when traffic is sourced from eth1/6.201 and egressing to public internet.&lt;/P&gt;
&lt;P&gt;Note that -&amp;nbsp;"Default Profile" under the QoS Interface is the profile that will be applied the traffic that is egressing this interface and does not match any of the "rules" under the Clear Text Traffic tab.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 22:50:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-qos-configuration-question/m-p/1236274#M6224</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2025-08-19T22:50:34Z</dc:date>
    </item>
  </channel>
</rss>

