<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: QoS in specifig configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/qos-in-specifig-configuration/m-p/25662#M18714</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found very bad for me information &lt;A class="active_link" href="http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB12939&amp;amp;cat=DSCP&amp;amp;actp=LIST&amp;amp;smlogin=true" title="http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB12939&amp;amp;cat=DSCP&amp;amp;actp=LIST&amp;amp;smlogin=true"&gt;http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB12939&amp;amp;cat=DSCP&amp;amp;actp=LIST&amp;amp;smlogin=true&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I'm using 6.3r8 ScreenOS. So my plan &lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps"&gt;fizzled out.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;What you can recomdate in my situation?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;I can't move SSG,but I thinking of it.irst I have to learn about more than one VR I'm not sure that PA200 can handle 2 VR. Another problem that I have is that at the moment I have 9 security zones. Limit is 10 for PA200. If I remove SSG and do the same on PA I will have 3 security zones (untrust/A/B) - I'm right?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;Slawek&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 May 2013 19:13:43 GMT</pubDate>
    <dc:creator>_slv_</dc:creator>
    <dc:date>2013-05-17T19:13:43Z</dc:date>
    <item>
      <title>QoS in specifig configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-in-specifig-configuration/m-p/25660#M18712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My network looks:&lt;/P&gt;&lt;P&gt;ISP (25Mbit symmetric) is connected to Juniper SSG-140 with two interfaces:&lt;/P&gt;&lt;P&gt;- A&lt;/P&gt;&lt;P&gt;- B &lt;/P&gt;&lt;P&gt;Behind B there is PA200 and two serwers connected by switch to B interface of SSG.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to use QoS on SSG. I put 25Mbit limit on untrust interface, and 10Mbit limit on A interface.&lt;/P&gt;&lt;P&gt;On B I try to use policy base QoS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question is how to set DSCP on PAN on NAT rule?&lt;/P&gt;&lt;P&gt;I'd like to mark VoIP/SSH/RDP traffic with higher mark than other traffic. How to do that? Maybe I should do it in other way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 15:56:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-in-specifig-configuration/m-p/25660#M18712</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-05-17T15:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: QoS in specifig configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-in-specifig-configuration/m-p/25661#M18713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The diffserv Qos mark is done in Security Policy not in NAT rules. In the option field you case choose IP dscp or IP Precedence according to your Juniper configuration and all the traffic voice, ie sip application, can be marked to higher priority.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic shaping Qos is the second technology, useful to limit/guarantee certain amount of traffic, but in your topology maybe is better to handle this with Juniper. On the contrary, if your juniper can be moved to outside to inside, for example as vpn concentrator, you can use directly traffic shaping.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 16:19:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-in-specifig-configuration/m-p/25661#M18713</guid>
      <dc:creator>NGS_SOC</dc:creator>
      <dc:date>2013-05-17T16:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: QoS in specifig configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-in-specifig-configuration/m-p/25662#M18714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found very bad for me information &lt;A class="active_link" href="http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB12939&amp;amp;cat=DSCP&amp;amp;actp=LIST&amp;amp;smlogin=true" title="http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB12939&amp;amp;cat=DSCP&amp;amp;actp=LIST&amp;amp;smlogin=true"&gt;http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB12939&amp;amp;cat=DSCP&amp;amp;actp=LIST&amp;amp;smlogin=true&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I'm using 6.3r8 ScreenOS. So my plan &lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps"&gt;fizzled out.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;What you can recomdate in my situation?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;I can't move SSG,but I thinking of it.irst I have to learn about more than one VR I'm not sure that PA200 can handle 2 VR. Another problem that I have is that at the moment I have 9 security zones. Limit is 10 for PA200. If I remove SSG and do the same on PA I will have 3 security zones (untrust/A/B) - I'm right?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;Slawek&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 19:13:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-in-specifig-configuration/m-p/25662#M18714</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-05-17T19:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: QoS in specifig configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-in-specifig-configuration/m-p/25663#M18715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure having fully understood your goal, if I were you I'll remove the SSG and put PA-200 in its place. The little PA device is able to handle layer3 topology with multiple WAN connections using vrouters (2 available) and PBR. &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;The simplest topology that can be suited you is WAN (untrusted) DMZ (servers) and LAN (trusted). In this choice traffic shaping &amp;amp; qos for servers/client are directly managed by PA-200 either with diffserv of qos polycy.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 20:55:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-in-specifig-configuration/m-p/25663#M18715</guid>
      <dc:creator>NGS_SOC</dc:creator>
      <dc:date>2013-05-17T20:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: QoS in specifig configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-in-specifig-configuration/m-p/25664#M18716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For better undestanding I atached simple draw&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-05-28_123133.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6692_2013-05-28_123133.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;My topology exactly as on this pictures and can't be changed. I'd like to limit WAN2 to 10Mbit/10Mbit and I want to setup SSG to keep VoIP/SSH/RDP with maximum proirytet.&lt;/P&gt;&lt;P&gt;According to kb from Juniper it's problably impossible because SSG will ignore DSCP from PA200, or I can setup polisy bandwitch on SSG but only per IP (not per aplications).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 10:47:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-in-specifig-configuration/m-p/25664#M18716</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-05-28T10:47:59Z</dc:date>
    </item>
  </channel>
</rss>

