<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: QoS: only ever matches default-group in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537715#M110422</link>
    <description>&lt;P&gt;Howdy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;QoS is applied on the 'egress' interface (out of firewall), so for uploads you need to have a profile on the WAN interface and downloads have another profile on the LAN interface (I.e. a single session touches 2 different QoS profiles on the c2s and s2c)&lt;/P&gt;
&lt;P&gt;The class is applied on the c2s flow and applies to both profiles&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps&lt;/P&gt;</description>
    <pubDate>Mon, 17 Apr 2023 10:58:13 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2023-04-17T10:58:13Z</dc:date>
    <item>
      <title>QoS: only ever matches default-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537671#M110400</link>
      <description>&lt;P&gt;I'm obviously missing something simple here, but nothing I've tried makes a difference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Creating a QoS Profile to configure the 8 classes:&amp;nbsp; works great.&lt;/P&gt;
&lt;P&gt;Creating a series of QoS Policies to classify AppIDs, URLs, users, etc into difference classes:&amp;nbsp; works great.&lt;/P&gt;
&lt;P&gt;Creating multiple QoS Profiles to limit bandwidth for separate networks:&amp;nbsp; &lt;STRONG&gt;nothing works&lt;/STRONG&gt; everything ends up in default-group (when viewing the live QoS Statistics on ethernet1/&lt;STRONG&gt;4&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ethernet1/&lt;STRONG&gt;4&lt;/STRONG&gt; is the WAN interface.&amp;nbsp; 100 Mbps symmetric link shared between two sites.&lt;/P&gt;
&lt;P&gt;ethernet1/&lt;STRONG&gt;3&lt;/STRONG&gt; is the LAN interface for site 1.&lt;/P&gt;
&lt;P&gt;ethernet1/&lt;STRONG&gt;2&lt;/STRONG&gt; is the LAN interface for site 2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I want to do is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;give site 1 a guaranteed 49 Mbps for uploads&lt;/LI&gt;
&lt;LI&gt;give site 1 a guaranteed 49 Mbps for downloads&lt;/LI&gt;
&lt;LI&gt;give site 2 a guaranteed 49 Mbps for uploads&lt;/LI&gt;
&lt;LI&gt;give site 2 a guaranteed 49 Mbps for downloads&lt;/LI&gt;
&lt;LI&gt;allow either site to use the full 100 Mbps if the other site is idle&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;What I'm trying to prevent is having one site hog all the bandwidth, but I also don't want to limit each site.&amp;nbsp; I just want to guarantee a minimum bandwidth for each site (they can use more if the other site isn't using it).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems pretty simple in theory, according to the docs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just create a QoS Profile with guaranteed egress of 49 Mbps and max egress of 99 Mbps for each site (to keep it under the 100 Mbps max for the interface).&amp;nbsp; Then in the QoS setup for ethernet1/&lt;STRONG&gt;4&lt;/STRONG&gt;, on the Clear Text Traffic tab, add separate entries for each source subnet and/or source interface and attach the corresponding QoS Profile to it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nope, doesn't work.&amp;nbsp; All traffic gets classified into the default-group.&amp;nbsp; The other two groups never see any traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Doesn't matter if both source interface and source subnet are set, only one or the other is set, or neither of them is set.&amp;nbsp; All traffic shows in the Statistics as being in the default-group.&amp;nbsp; (On the bright side, all the QoS Policies are working, and traffic is being classified correctly into the 8 classes.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Assigning the QoS profile to the LAN interfaces works, but that's not the shared interface where we need the QoS to apply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, what am I missing?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 23:16:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537671#M110400</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2023-04-04T23:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: QoS: only ever matches default-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537715#M110422</link>
      <description>&lt;P&gt;Howdy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;QoS is applied on the 'egress' interface (out of firewall), so for uploads you need to have a profile on the WAN interface and downloads have another profile on the LAN interface (I.e. a single session touches 2 different QoS profiles on the c2s and s2c)&lt;/P&gt;
&lt;P&gt;The class is applied on the c2s flow and applies to both profiles&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2023 10:58:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537715#M110422</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-04-17T10:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: QoS: only ever matches default-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537729#M110427</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;I think you have a typo there.&lt;/P&gt;
&lt;P&gt;QoS is on egress not ingress.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/quality-of-service/qos-concepts/qos-egress-interface" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/quality-of-service/qos-concepts/qos-egress-interface&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 12:59:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537729#M110427</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-04-05T12:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: QoS: only ever matches default-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537738#M110429</link>
      <description>&lt;P&gt;I tested and works well.&lt;/P&gt;
&lt;P&gt;What PANOS are you running?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1680702498987.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49281i46713AB85AF911C3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1680702498987.png" alt="Raido_Rattameister_0-1680702498987.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 13:51:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537738#M110429</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-04-05T13:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: QoS: only ever matches default-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537742#M110430</link>
      <description>&lt;P&gt;I found interesting discrepancy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I pushed config from Panorama and in Panorama there is also destination interface option that firewall QoS setting don't have.&lt;/P&gt;
&lt;P&gt;Not sure if it made difference. Will test directly setting QoS on firewall when I have time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_1-1680703188100.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49282i5A2F729CE23B6AE1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_1-1680703188100.png" alt="Raido_Rattameister_1-1680703188100.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 14:01:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537742#M110430</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-04-05T14:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: QoS: only ever matches default-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537757#M110435</link>
      <description>&lt;P&gt;PA-220 firewall running PanOS 9.1.15-h1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your setup appears to be almost identical to mine, but yours works and mine doesn't.&amp;nbsp; Wonder if it's a PanOS version issue (you appear to be running 10.x?).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Doesn't matter if I use the physical interface, or the VLAN sub-interface on the Clear Text Traffic tab, the traffic never gets assigned to the different groups in the Statistics dialog.&amp;nbsp; Always shows under default-group only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could it be a layer2 vs layer3 interface configuration?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 15:46:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537757#M110435</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2023-04-05T15:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: QoS: only ever matches default-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537758#M110436</link>
      <description>&lt;P&gt;The larger firewalls (3x00, 5x00, 7x00) allow you to set the destination interface.&amp;nbsp; The smaller firewalls only support the source interface.&amp;nbsp; Panorama shows both and only pushes the relevant interface based on the destination hardware.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 15:35:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537758#M110436</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2023-04-05T15:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: QoS: only ever matches default-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537759#M110437</link>
      <description>&lt;P&gt;The docs show QoS is applied on egress.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have QoS configured on 3 interfaces in the firewall:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ethernet1/&lt;STRONG&gt;2&lt;/STRONG&gt; has the Pineridge-QoS-Profile assigned (LAN for Pineridge, for "download" traffic)&lt;/LI&gt;
&lt;LI&gt;ethernet1/&lt;STRONG&gt;3&lt;/STRONG&gt; has the Maint-QoS-Profile assigned (LAN for Maint, for "download" traffic)&lt;/LI&gt;
&lt;LI&gt;ethernet1/&lt;STRONG&gt;4&lt;/STRONG&gt; has both Pineridge-QoS-Profile and Maint-QoS-Profile assigned under the Clear Text Traffic tab, with the source interface set to 2 and 3 respectively (WAN for both sites, for "upload" traffic)&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 05 Apr 2023 15:41:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/537759#M110437</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2023-04-05T15:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: QoS: only ever matches default-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/538976#M110604</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;I think you have a typo there.&lt;/P&gt;
&lt;P&gt;QoS is on egress not ingress.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/quality-of-service/qos-concepts/qos-egress-interface" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/quality-of-service/qos-concepts/qos-egress-interface&lt;/A&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;yep my bad, made a booboo there &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2023 10:58:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/538976#M110604</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-04-17T10:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: QoS: only ever matches default-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/591297#M117748</link>
      <description>&lt;P&gt;I'm observing the same issue on VM-series 11.0.3-h3. I can successfully configure QoS in all directions and there are no misunderstandings about ingress/egress etc., but for the life of me I can't make traffic hit anything else than the default-group, in other words, the "Clear Text Traffic" tab in "QoS Interface" does not have any effect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone ever found out something useful?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jul 2024 13:23:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-only-ever-matches-default-group/m-p/591297#M117748</guid>
      <dc:creator>jkvalk59s</dc:creator>
      <dc:date>2024-07-06T13:23:00Z</dc:date>
    </item>
  </channel>
</rss>

