<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clear Text and Tunnel traffic same physical interface QoS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532214#M109729</link>
    <description>&lt;P&gt;As QoS applies to egress interface your screenshot shows upload throttling not download throttling.&lt;/P&gt;
&lt;P&gt;To apply how much users can download from internet you need to apply QoS to INSIDE interface.&lt;/P&gt;
&lt;P&gt;On Clear Text Traffic and Tunneled Traffic tabs you can choose source interface and apply different QoS profiles to them.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Feb 2023 18:19:29 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-02-24T18:19:29Z</dc:date>
    <item>
      <title>Clear Text and Tunnel traffic same physical interface QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532189#M109720</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a scenario in mind, for example:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. We have physical interface for Internet link with a bandwidth of 50 Mbits/s, which is used to peer with our ISP and send internet-bound traffic through;&lt;/P&gt;
&lt;P&gt;2. We have regular internet for users and VPN tunnel (to Prisma) using same link concurrently;&lt;/P&gt;
&lt;P&gt;3. We have Subinterface configured on Physical interface for internet as upstream device expects tagged traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently our setup in regards to QoS looks like following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a. We set 50 Mbit/s as MAX Egress for Physical interface;&lt;/P&gt;
&lt;P&gt;b. We set 0 as MAX Egress and 0 as MAX Guaranteed as Clear Text traffic on that interface;&lt;/P&gt;
&lt;P&gt;c. We set 0 Mbit/s as MAX Egress and 0 Mbit/s for tunneled traffic, but within profile assigned here we set different percentages based on class for Guaranteed traffic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Overall it looks like this:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2023-02-24_16-08-20.png" style="width: 846px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48184iD97C267B86098ED7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2023-02-24_16-08-20.png" alt="2023-02-24_16-08-20.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The main problem here is as you can see although same physical interface is restricted to 50 Mbit/s, EACH TYPE OF TRAFFIC gets 50 Mbit/s, while we want to have both types of traffic combined use same link up to 50 Mbit/s on that link and use it concurrently. In case of the congestion we would like tunneled traffic to be preferred, hence we are setting guaranteed percentage only for this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is such design actually possible to achieve in Palo?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 15:16:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532189#M109720</guid>
      <dc:creator>Andreikin</dc:creator>
      <dc:date>2023-02-24T15:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Text and Tunnel traffic same physical interface QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532206#M109723</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check out this article, I think it might help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS0CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS0CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 17:57:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532206#M109723</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-02-24T17:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Text and Tunnel traffic same physical interface QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532208#M109725</link>
      <description>&lt;P&gt;Thanks, but it doesn't help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 18:01:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532208#M109725</guid>
      <dc:creator>Andreikin</dc:creator>
      <dc:date>2023-02-24T18:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Text and Tunnel traffic same physical interface QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532212#M109727</link>
      <description>&lt;P&gt;OK I might have misunderstood the question. Since the physical interface is the egress, that is where you want to set your policy, try making the changes there as QoS is applied at the egress interface.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 18:10:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532212#M109727</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-02-24T18:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Text and Tunnel traffic same physical interface QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532213#M109728</link>
      <description>&lt;P&gt;Well, my general question was - is it possible to have Clear Text and Tunneled traffic on a same interface to share shame MAX Egress Value? So if you have MAX Egress on interface of 50 Mbit/s, current Internet usage is at 30 Mbit/s, so Tunneled can use only&amp;nbsp;its Guranateed 20 Mbit/s only and overall bandwith usage of Internet link not going higher than 50 Mbits? Without using MAX Egress on Clear Traffic and Tunnel Traffic profiles, as at one time we might have 10 Mbit/s for Internet and 40 Mbit/s for Tunneled and other time - 35 Mbit/s for Internet and 15 Mbit/s for Tunneled.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 18:16:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532213#M109728</guid>
      <dc:creator>Andreikin</dc:creator>
      <dc:date>2023-02-24T18:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Text and Tunnel traffic same physical interface QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532214#M109729</link>
      <description>&lt;P&gt;As QoS applies to egress interface your screenshot shows upload throttling not download throttling.&lt;/P&gt;
&lt;P&gt;To apply how much users can download from internet you need to apply QoS to INSIDE interface.&lt;/P&gt;
&lt;P&gt;On Clear Text Traffic and Tunneled Traffic tabs you can choose source interface and apply different QoS profiles to them.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 18:19:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532214#M109729</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-02-24T18:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Text and Tunnel traffic same physical interface QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532216#M109730</link>
      <description>&lt;P&gt;Given that we have a PE and CPE provider's eiupement where bandwith is already policed at 50 Mbit/s both ways there's no point for me to do anything with dowload. Hence I am talking here ONLY about traffic leaving from firewall towards internet - Clear and Tunneled.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 18:22:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-text-and-tunnel-traffic-same-physical-interface-qos/m-p/532216#M109730</guid>
      <dc:creator>Andreikin</dc:creator>
      <dc:date>2023-02-24T18:22:11Z</dc:date>
    </item>
  </channel>
</rss>

