<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PA 850 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-850/m-p/572769#M115238</link>
    <description>&lt;P&gt;hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have deployed a HA 850 series cluster&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have users complaining about problems with:&lt;/P&gt;
&lt;P&gt;voice quality on MS Teams&amp;nbsp;&lt;/P&gt;
&lt;P&gt;screen freezes&amp;nbsp;&lt;/P&gt;
&lt;P&gt;video &amp;amp; audio out of sync&lt;/P&gt;
&lt;P&gt;Q is there a configuration I should&amp;nbsp; use to optimise the MS Teams network performance ?&lt;/P&gt;
&lt;P&gt;Q are there any logs /packet captures I should run to try and identify the issue ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jan 2024 20:34:06 GMT</pubDate>
    <dc:creator>paloaltousername</dc:creator>
    <dc:date>2024-01-11T20:34:06Z</dc:date>
    <item>
      <title>PA 850</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-850/m-p/572769#M115238</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have deployed a HA 850 series cluster&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have users complaining about problems with:&lt;/P&gt;
&lt;P&gt;voice quality on MS Teams&amp;nbsp;&lt;/P&gt;
&lt;P&gt;screen freezes&amp;nbsp;&lt;/P&gt;
&lt;P&gt;video &amp;amp; audio out of sync&lt;/P&gt;
&lt;P&gt;Q is there a configuration I should&amp;nbsp; use to optimise the MS Teams network performance ?&lt;/P&gt;
&lt;P&gt;Q are there any logs /packet captures I should run to try and identify the issue ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 20:34:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-850/m-p/572769#M115238</guid>
      <dc:creator>paloaltousername</dc:creator>
      <dc:date>2024-01-11T20:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: PA 850</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-850/m-p/572883#M115248</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I would recommend disabling URL filtering on the security policy that is inspecting the traffic. Other than that, its a matter of looking at the traffic packets and interface and bandwidth utilization. Another thing to possible try is checking the box for&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1705081154882.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56466i64D8A91F6B8DDBAE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1705081154882.png" alt="OtakarKlier_0-1705081154882.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;in the security policy. Perhaps also looking into QoS, but if its cloud based, that might not make a difference since the internet doesnt respect or adhere to QoS in packets.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 17:40:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-850/m-p/572883#M115248</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-01-12T17:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: PA 850</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-850/m-p/572997#M115260</link>
      <description>&lt;P&gt;"Disable Server Response Inspection" eliminates threat prevention against traffic sent from server to client.&lt;/P&gt;
&lt;P&gt;Quite a risky option to set in general but specially if clients are inside and servers in internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you monitoring bandwidth utilization to be sure you are not hitting limit set by ISP?&lt;/P&gt;
&lt;P&gt;Use QoS to prioritize MS Teams traffic.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jan 2024 19:08:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-850/m-p/572997#M115260</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-01-14T19:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: PA 850</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-850/m-p/573172#M115276</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/283023"&gt;@paloaltousername&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Just going to echo what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;stated about the "Disable Server Response Inspection" risks. This isn't a feature to be utilized lightly and I won't want to enable it on something as broad as Teams traffic. It's something that I'll utilize in some scenarios internal to the network where you absolutely need it, but you'd really want to understand the risks associated with it before doing so.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's some examples where disabling it can be an acceptable solution where speed is prioritized over the inspection of the server to client flow. One that you'll see utilized often is in instances of file servers and SMB traffic, as you'll still be inspecting the client to server flow for someone uploading a new file, but you wouldn't be inspecting a client downloading a file from the server. In&amp;nbsp;&lt;EM&gt;some&amp;nbsp;&lt;/EM&gt;situations that's preferred from a performance standpoint if you have mitigating factors on the file servers to ensure that they aren't feeding anything malicious to your clients.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you have a large enough ISP connection and a big enough box you shouldn't need to do anything for Teams to work properly. The biggest thing Microsoft will tell you before you implement Teams for telephony is to ensure that you have a large enough connection to support the traffic and to implement QoS, with QoS and properly prioritized voice traffic being one of the biggest things that will cause connection issues.&lt;/P&gt;
&lt;P&gt;One thing that you don't mention in your post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/283023"&gt;@paloaltousername&lt;/a&gt;&amp;nbsp;is where you're running into this issue. If it's on-prem traffic I'd absolutely be looking at QoS and insuring you have a large enough ISP connection to actually support the transition. However if it's people operating across GlobalProtect then you need to think about the possibility of splitting that traffic and allowing the Microsoft "Optimize Required" entries to exit locally instead of tunneling back to your firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 11:55:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-850/m-p/573172#M115276</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-01-16T11:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: PA 850</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-850/m-p/573305#M115291</link>
      <description>&lt;P&gt;thank you for all your help&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have asked the ISP to report back on any QoS or shaping on their on-prem WAN router&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the users reporting the issue&amp;nbsp; are located on the LAN with no reported VPN users&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the WAN router is local to these users&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not sure if this service ever worked to an acceptable standard&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 10:28:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-850/m-p/573305#M115291</guid>
      <dc:creator>paloaltousername</dc:creator>
      <dc:date>2024-01-17T10:28:30Z</dc:date>
    </item>
  </channel>
</rss>

