<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: same zone and throughput in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/same-zone-and-throughput/m-p/27045#M19757</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I ask a stupid question - is there a simple way to report on the throughput on a given interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Apr 2011 22:17:49 GMT</pubDate>
    <dc:creator>KGC</dc:creator>
    <dc:date>2011-04-12T22:17:49Z</dc:date>
    <item>
      <title>same zone and throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-zone-and-throughput/m-p/27043#M19755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is about a Palo Alto PA-500.&lt;/P&gt;&lt;P&gt;The firewall througput is around 250Mbps, and 100Mbps with inspection of packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 1 Firewall PA-500, with 5 interfaces (L3):&lt;/P&gt;&lt;P&gt;Eth1/1: Untrust zone&lt;/P&gt;&lt;P&gt;Eth1/2: DMZ Zone&lt;/P&gt;&lt;P&gt;Eth1/3 to Eth1/5: Trust zone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about the throughput between 2 interfaces (L3) in the same zone ?&lt;/P&gt;&lt;P&gt;As far as I understand, this trafic is allowed with a implicit rule (unless we configure a "deny all" rule at the end of our rules).&lt;/P&gt;&lt;P&gt;Does the firewall inspect (APP-ID) the packets between a same zone or not? What will be the throuhput in this case? 250Mbps? More?&lt;/P&gt;&lt;P&gt;I read the document about the packet flows, but it's not clear for me about these questions I have...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you for your answers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Khay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2011 13:49:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-zone-and-throughput/m-p/27043#M19755</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-04-11T13:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: same zone and throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-zone-and-throughput/m-p/27044#M19756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Khay&lt;/P&gt;&lt;P&gt;The throughout will not change, for inter or intra zone traffic.&amp;nbsp; APPID will still be applied for all traffic . Unless you create an intra zone policy to permit traffic you will not be able to see the detected apps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Jerish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Apr 2011 21:37:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-zone-and-throughput/m-p/27044#M19756</guid>
      <dc:creator>jpa</dc:creator>
      <dc:date>2011-04-12T21:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: same zone and throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-zone-and-throughput/m-p/27045#M19757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I ask a stupid question - is there a simple way to report on the throughput on a given interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Apr 2011 22:17:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-zone-and-throughput/m-p/27045#M19757</guid>
      <dc:creator>KGC</dc:creator>
      <dc:date>2011-04-12T22:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: same zone and throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-zone-and-throughput/m-p/27046#M19758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks you Jerish for your answer.&lt;/P&gt;&lt;P&gt;Just a last question about that:&lt;/P&gt;&lt;P&gt;Is there any way or trick to desactive the APP-ID for particulars flows which go through the firewall ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ksemenov &amp;gt; A simple way will be to use SNMP (SNMP Traffic Grapher / CACTI / etc.) and graphe the real-time throughput on the interfaces. With Palo Alto, maybe there is another way with the WEBUI or CLI...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Khay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Apr 2011 10:33:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-zone-and-throughput/m-p/27046#M19758</guid>
      <dc:creator>alliance</dc:creator>
      <dc:date>2011-04-13T10:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: same zone and throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-zone-and-throughput/m-p/27047#M19759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;alliance ha scritto:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you Jerish for your answer.&lt;/P&gt;&lt;P&gt;Just a last question about that:&lt;/P&gt;&lt;P&gt;Is there any way or trick to desactive the APP-ID for particulars flows which go through the firewall ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ksemenov &amp;gt; A simple way will be to use SNMP (SNMP Traffic Grapher / CACTI / etc.) and graphe the real-time throughput on the interfaces. With Palo Alto, maybe there is another way with the WEBUI or CLI...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Khay&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi alliance.&lt;/P&gt;&lt;P&gt;The only way to deactivate App-ID is through an Application Override policy that match the app you want to exclude from App-ID identification.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Apr 2011 13:59:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-zone-and-throughput/m-p/27047#M19759</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-04-13T13:59:59Z</dc:date>
    </item>
  </channel>
</rss>

