<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fast Path vs Slow Path with Content ID in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fast-path-vs-slow-path-with-content-id/m-p/1263994#M7121</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1166535127"&gt;@M.Gannon&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, Content-ID is slower, but technically it is not called slow path.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 09 Sep 2026 17:17:22 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2026-09-09T17:17:22Z</dc:date>
    <item>
      <title>Fast Path vs Slow Path with Content ID</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fast-path-vs-slow-path-with-content-id/m-p/1263898#M7118</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;newish to Palo Alto so trying to understand the demarcation between Fast-Path and Slow path when using Content ID.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My understanding is that when a new traffic flow starts App-ID is used to determine the application and once the flow is established traffic moves to Fast path.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I right though that if Content-ID is used that the traffic must stay in Slow Path because the traffic would need continuous inspection to verify that content isn't being modifed mid-flow to circumvent the policy. eg a malicious actor could initiate a connection with junk PDF file downloads before switching to sensitive PDF file downloads&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2026 23:06:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fast-path-vs-slow-path-with-content-id/m-p/1263898#M7118</guid>
      <dc:creator>M.Gannon</dc:creator>
      <dc:date>2026-09-08T23:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: Fast Path vs Slow Path with Content ID</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fast-path-vs-slow-path-with-content-id/m-p/1263990#M7119</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1166535127"&gt;@M.Gannon&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;A packet that matches an existing session will enter the fast path."&amp;nbsp; This information is found under Section 4 of this page -&amp;gt;&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0&lt;/A&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;"On a Palo Alto Networks firewall, a session is defined by two uni-directional flows each uniquely identified by a 6-tuple key: source-address, destination-address, source-port, destination-port, protocol, and security-zone."&amp;nbsp;&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVECA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVECA0&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;Therefore, App-ID and Content-ID are not used to define a session and have no impact on fast or slow path.&amp;nbsp; The best diagram that I have found to illustrate this process is as follows, where slow path is session setup.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1788971151416.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72505i9947B3E4D92E7AA2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1788971151416.png" alt="TomYoung_0-1788971151416.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Both fast and slow path traffic go through App-ID and Content-ID inspection if determined by the security policy rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With that said, Content-ID (defined as threat prevention) does impact performance as shown in the Compare Firewalls and spec sheets.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/products/product-comparison" target="_blank"&gt;https://www.paloaltonetworks.com/products/product-comparison&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/resources/datasheets/product-summary-specsheet" target="_blank"&gt;https://www.paloaltonetworks.com/resources/datasheets/product-summary-specsheet&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 16:32:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fast-path-vs-slow-path-with-content-id/m-p/1263990#M7119</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2026-09-09T16:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: Fast Path vs Slow Path with Content ID</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fast-path-vs-slow-path-with-content-id/m-p/1263993#M7120</link>
      <description>&lt;P&gt;Thanks Tom,&lt;/P&gt;
&lt;P&gt;That makes sense. So Contect-ID, if selected as part of the policy continues via slow path because of the continuing analysis&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 17:10:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fast-path-vs-slow-path-with-content-id/m-p/1263993#M7120</guid>
      <dc:creator>M.Gannon</dc:creator>
      <dc:date>2026-09-09T17:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Fast Path vs Slow Path with Content ID</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fast-path-vs-slow-path-with-content-id/m-p/1263994#M7121</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1166535127"&gt;@M.Gannon&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, Content-ID is slower, but technically it is not called slow path.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 17:17:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fast-path-vs-slow-path-with-content-id/m-p/1263994#M7121</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2026-09-09T17:17:22Z</dc:date>
    </item>
  </channel>
</rss>

