<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Leveraging The Full Power Of Prisma SD-WAN App SLA Assurance in Prisma SD-WAN Articles</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-articles/leveraging-the-full-power-of-prisma-sd-wan-app-sla-assurance/ta-p/582968</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Introduction&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Building upon the strong application identification and performance characterization capabilities of Prisma SD-WAN,&amp;nbsp;App SLA Assurance enables a flexible framework for the both Application and Network SLAs.&amp;nbsp; By first understanding the application using Palo Alto Networks App-ID technology, Prisma SD-WAN is able to identify thousands of applications out of the box in addition to custom L3/L4 and L7 application definitions.&amp;nbsp; By combining the application and network performance characterization with the control of the Prisma SD-WAN policy model, network operators are able to deliver an exceptional end-user experience while simplifying day 2 operations.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Real-User Performance Characterization&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After an application is identified the performance of each real user session is characterized including:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Initialization Success / Failure Rate - TCP 3-way handshake&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Transaction Success / Failure Rate - TCP Retransmission&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Application Round Trip Time&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Application Server Response Time&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Application Transaction Time&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Voice MOS&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Voice / Video Packet Loss&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Voice / Video Jitter&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Link Quality Metrics&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additionally there are two "Always On" technologies used to determine point to point transport (IE Link Quality) performance as well as service performance.&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;For Link Quality the following metrics are measured:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Round Trip Latency&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Packet Loss (Bi-directional)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Jitter (Bi-directional)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Link MOS (Bi-directional)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Bandwidth Consumption (Bi-directional)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Service Probing&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;The second "Always On" performance characterization method uses defined (default and custom) service probing for multiple protocols including ICMP, DNS, HTTP, HTTPS and measures:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;HTTP/S Response Time&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;HTTP/S Response Code&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;HTTP/S Response String&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;HTTP/S Response Success / Failure&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;DNS Response Success / Failure&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;DNS Transaction Time&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;ICMP Packet Loss&lt;/LI&gt;
&lt;LI&gt;ICMP Round Trip Latency&lt;/LI&gt;
&lt;LI&gt;ICMP Round Trip Jitter&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The default probes measure:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ICMP response to Google G-suite : apps.google.com&lt;/LI&gt;
&lt;LI&gt;ICMP response to CloudFlare DNS :&amp;nbsp;&lt;SPAN&gt;1.1.1.1&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;ICMP response to Microsoft Teams : teams.microsoft.com&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These probes enable the system to determine the per path performance to a specific service endpoint which is then used to make the most informed path selection decision.&amp;nbsp; Up to 8 probes can be configured per Circuit and can be sent on any combination of Prisma SD-WAN overlay, Standard VPN overlay, and Underlay.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Path Selection&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The various real time metrics are each fed back into path selection and used to protect existing application sessions by moving active traffic around issues as well as placing new application sessions onto the best performing path.&amp;nbsp; The path selection intent is specified in path policy rules.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Quality-Based Control&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The definition of application and network SLAs is controlled via the Prisma SD-WAN Performance Policy.&amp;nbsp; In Performance Policy desired actions are first selected.&amp;nbsp; These include:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Generate Incident - If the SLA parameters are violated an incident will be created.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Move Flows - Move new and existing flows away from paths that do not meet the SLA.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Forward Error Correction - If a SLA compliant path is not available then invoke adaptive FEC to correct packet loss.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Packet Duplication - Duplicate the packets of a flow on up to 3 paths.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Visibility - Link Quality SLAs configured will be reflected on the Link Quality time series charts.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Furthermore, detailed match criteria enable flexible tuning of the SLA parameters:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Application IDs - One or more App-IDs&lt;/LI&gt;
&lt;LI&gt;Application Transfer Types&lt;/LI&gt;
&lt;LI&gt;Circuit Categories&lt;/LI&gt;
&lt;LI&gt;Path Types&lt;/LI&gt;
&lt;LI&gt;Service &amp;amp; DC Groups&lt;/LI&gt;
&lt;LI&gt;SLA Type - Application, Network, Probe&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Summary&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Prisma SD-WAN Application SLA assurance provides out of the box protection and can be tuned to most nuanced needs of any enterprise, thus enabling the delivery of an exceptional end user application experience while simplifying day 2 operations.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For step by step guides on how to configure App SLA rules please review the Prisma SD-WAN Admin Guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-sd-wan/prisma-sd-wan-admin" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/prisma/prisma-sd-wan/prisma-sd-wan-admin&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Wed, 10 Apr 2024 20:42:54 GMT</pubDate>
    <dc:creator>BPruitt</dc:creator>
    <dc:date>2024-04-10T20:42:54Z</dc:date>
    <item>
      <title>Leveraging The Full Power Of Prisma SD-WAN App SLA Assurance</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-articles/leveraging-the-full-power-of-prisma-sd-wan-app-sla-assurance/ta-p/582968</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Introduction&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Building upon the strong application identification and performance characterization capabilities of Prisma SD-WAN,&amp;nbsp;App SLA Assurance enables a flexible framework for the both Application and Network SLAs.&amp;nbsp; By first understanding the application using Palo Alto Networks App-ID technology, Prisma SD-WAN is able to identify thousands of applications out of the box in addition to custom L3/L4 and L7 application definitions.&amp;nbsp; By combining the application and network performance characterization with the control of the Prisma SD-WAN policy model, network operators are able to deliver an exceptional end-user experience while simplifying day 2 operations.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Real-User Performance Characterization&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After an application is identified the performance of each real user session is characterized including:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Initialization Success / Failure Rate - TCP 3-way handshake&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Transaction Success / Failure Rate - TCP Retransmission&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Application Round Trip Time&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Application Server Response Time&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Application Transaction Time&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Voice MOS&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Voice / Video Packet Loss&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Voice / Video Jitter&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Link Quality Metrics&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additionally there are two "Always On" technologies used to determine point to point transport (IE Link Quality) performance as well as service performance.&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;For Link Quality the following metrics are measured:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Round Trip Latency&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Packet Loss (Bi-directional)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Jitter (Bi-directional)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Link MOS (Bi-directional)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Bandwidth Consumption (Bi-directional)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Service Probing&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;The second "Always On" performance characterization method uses defined (default and custom) service probing for multiple protocols including ICMP, DNS, HTTP, HTTPS and measures:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;HTTP/S Response Time&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;HTTP/S Response Code&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;HTTP/S Response String&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;HTTP/S Response Success / Failure&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;DNS Response Success / Failure&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;DNS Transaction Time&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;ICMP Packet Loss&lt;/LI&gt;
&lt;LI&gt;ICMP Round Trip Latency&lt;/LI&gt;
&lt;LI&gt;ICMP Round Trip Jitter&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The default probes measure:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ICMP response to Google G-suite : apps.google.com&lt;/LI&gt;
&lt;LI&gt;ICMP response to CloudFlare DNS :&amp;nbsp;&lt;SPAN&gt;1.1.1.1&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;ICMP response to Microsoft Teams : teams.microsoft.com&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These probes enable the system to determine the per path performance to a specific service endpoint which is then used to make the most informed path selection decision.&amp;nbsp; Up to 8 probes can be configured per Circuit and can be sent on any combination of Prisma SD-WAN overlay, Standard VPN overlay, and Underlay.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Path Selection&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The various real time metrics are each fed back into path selection and used to protect existing application sessions by moving active traffic around issues as well as placing new application sessions onto the best performing path.&amp;nbsp; The path selection intent is specified in path policy rules.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Quality-Based Control&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The definition of application and network SLAs is controlled via the Prisma SD-WAN Performance Policy.&amp;nbsp; In Performance Policy desired actions are first selected.&amp;nbsp; These include:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Generate Incident - If the SLA parameters are violated an incident will be created.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Move Flows - Move new and existing flows away from paths that do not meet the SLA.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Forward Error Correction - If a SLA compliant path is not available then invoke adaptive FEC to correct packet loss.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Packet Duplication - Duplicate the packets of a flow on up to 3 paths.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Visibility - Link Quality SLAs configured will be reflected on the Link Quality time series charts.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Furthermore, detailed match criteria enable flexible tuning of the SLA parameters:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Application IDs - One or more App-IDs&lt;/LI&gt;
&lt;LI&gt;Application Transfer Types&lt;/LI&gt;
&lt;LI&gt;Circuit Categories&lt;/LI&gt;
&lt;LI&gt;Path Types&lt;/LI&gt;
&lt;LI&gt;Service &amp;amp; DC Groups&lt;/LI&gt;
&lt;LI&gt;SLA Type - Application, Network, Probe&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Summary&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Prisma SD-WAN Application SLA assurance provides out of the box protection and can be tuned to most nuanced needs of any enterprise, thus enabling the delivery of an exceptional end user application experience while simplifying day 2 operations.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For step by step guides on how to configure App SLA rules please review the Prisma SD-WAN Admin Guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-sd-wan/prisma-sd-wan-admin" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/prisma/prisma-sd-wan/prisma-sd-wan-admin&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 10 Apr 2024 20:42:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-articles/leveraging-the-full-power-of-prisma-sd-wan-app-sla-assurance/ta-p/582968</guid>
      <dc:creator>BPruitt</dc:creator>
      <dc:date>2024-04-10T20:42:54Z</dc:date>
    </item>
  </channel>
</rss>

