<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic QoS cleartext match issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/qos-cleartext-match-issue/m-p/529414#M109292</link>
    <description>&lt;P&gt;We have setup similar to as below&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 840px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47569i19E3623A737EAD2A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created/applied default QoS profiles on AE1 and AE5. However in order to be more granular I want to apply on individual subnets.&lt;BR /&gt;&lt;BR /&gt;As in this example we want to use separate QoS profile for 10.129.0.0/16 subnet for traffic going to internet. I have tried to add subnet under cleartext on both AE1 and AE5, with and without source interface of ae1.3, with/without destination interface of AE5.100, but the traffic still matches the regular traffic and not cleartext policy. How do I make this work,&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 488px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47570i9E3D35C640BB3A77/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Feb 2023 06:27:41 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2023-02-01T06:27:41Z</dc:date>
    <item>
      <title>QoS cleartext match issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-cleartext-match-issue/m-p/529414#M109292</link>
      <description>&lt;P&gt;We have setup similar to as below&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 840px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47569i19E3623A737EAD2A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created/applied default QoS profiles on AE1 and AE5. However in order to be more granular I want to apply on individual subnets.&lt;BR /&gt;&lt;BR /&gt;As in this example we want to use separate QoS profile for 10.129.0.0/16 subnet for traffic going to internet. I have tried to add subnet under cleartext on both AE1 and AE5, with and without source interface of ae1.3, with/without destination interface of AE5.100, but the traffic still matches the regular traffic and not cleartext policy. How do I make this work,&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 488px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47570i9E3D35C640BB3A77/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 06:27:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-cleartext-match-issue/m-p/529414#M109292</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2023-02-01T06:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: QoS cleartext match issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-cleartext-match-issue/m-p/529428#M109299</link>
      <description>&lt;P&gt;QoS is applied on the ingress of a packet, so if you want to limit upload you need to add the profile on AE1, if you want to limit download you need toi add the profile to AE5 (and if you want to control both you'll need a profile on both the interfaces)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this also means if you want to set up subnets in the cleartext section, you'll need to account for both direction: on AE3 you'll use source 10.129.0.0/16, on AE5 you need to set that as destination. On the download you are only able to set a destination interface, not subnet, so you'll need to ensure your QoS policy only triggers for that subnet and then apply a class (ie. &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; thats not used for any other subnet so you dont limit download for other networks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope that makes sense&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 08:27:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-cleartext-match-issue/m-p/529428#M109299</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-02-01T08:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: QoS cleartext match issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-cleartext-match-issue/m-p/529665#M109327</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;Thank you for your insight. I was not taking into direction and where QoS will be applied.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also for someone else's help. if you are using multiple virtual systems. Source and destination both need to be specified or the QoS policy won't match on external interface for downloads.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 448px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47604iAB5FFD343FE44BAB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And unless class is changed from default to 4, all traffic still shows as matching to default-group when you look under statics, i observed.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 19:40:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-cleartext-match-issue/m-p/529665#M109327</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2023-02-02T19:40:21Z</dc:date>
    </item>
  </channel>
</rss>

