<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: segmentation of bandwidth: in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51499#M37885</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P data-canvas-width="36.40256108488083" data-font-name="g_font_p0_4" dir="ltr" style="font-size: 14.72px; font-family: sans-serif;"&gt;Look for the QoS use cases in the doc - &lt;A href="https://live.paloaltonetworks.com/docs/DOC-3439"&gt;QoS in PAN-OS 4.1&lt;/A&gt;&lt;/P&gt;&lt;P data-canvas-width="36.40256108488083" data-font-name="g_font_p0_4" dir="ltr" style="font-size: 14.72px; font-family: sans-serif;"&gt;Case 2 – Sharing Bandwidth with Fairness&lt;/P&gt;&lt;P data-canvas-width="36.40256108488083" data-font-name="g_font_p0_4" dir="ltr" style="font-size: 14.72px; font-family: sans-serif;"&gt;&lt;/P&gt;&lt;P data-canvas-width="36.40256108488083" data-font-name="g_font_p0_4" dir="ltr" style="font-size: 14.72px; font-family: sans-serif;"&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Aug 2013 09:50:29 GMT</pubDate>
    <dc:creator>harshanatarajan</dc:creator>
    <dc:date>2013-08-30T09:50:29Z</dc:date>
    <item>
      <title>segmentation of bandwidth:</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51497#M37883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Hi All,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; One of our customers has an internet acces of 20Mbits and 4 types of users so he wants to segment the internet acces into&amp;nbsp; 4&amp;nbsp; acces in order to ensure that every user groups has a bandwidth of 5Mbits.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is it possible to do this treatment with a Palo Alto firewall ?&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 09:38:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51497#M37883</guid>
      <dc:creator>Lahcen</dc:creator>
      <dc:date>2013-08-30T09:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: segmentation of bandwidth:</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51498#M37884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use Active directory user groups in QOS rules.&lt;/P&gt;&lt;P&gt;For eaach group you can use a max 5mbit class and all for the related qos profile.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3439"&gt;QoS in PAN-OS 4.1&lt;/A&gt; You can configure details related to document.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 09:45:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51498#M37884</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-30T09:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: segmentation of bandwidth:</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51499#M37885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P data-canvas-width="36.40256108488083" data-font-name="g_font_p0_4" dir="ltr" style="font-size: 14.72px; font-family: sans-serif;"&gt;Look for the QoS use cases in the doc - &lt;A href="https://live.paloaltonetworks.com/docs/DOC-3439"&gt;QoS in PAN-OS 4.1&lt;/A&gt;&lt;/P&gt;&lt;P data-canvas-width="36.40256108488083" data-font-name="g_font_p0_4" dir="ltr" style="font-size: 14.72px; font-family: sans-serif;"&gt;Case 2 – Sharing Bandwidth with Fairness&lt;/P&gt;&lt;P data-canvas-width="36.40256108488083" data-font-name="g_font_p0_4" dir="ltr" style="font-size: 14.72px; font-family: sans-serif;"&gt;&lt;/P&gt;&lt;P data-canvas-width="36.40256108488083" data-font-name="g_font_p0_4" dir="ltr" style="font-size: 14.72px; font-family: sans-serif;"&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 09:50:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51499#M37885</guid>
      <dc:creator>harshanatarajan</dc:creator>
      <dc:date>2013-08-30T09:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: segmentation of bandwidth:</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51500#M37886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;I have another question is it possible to limit the bandwidth for users (users are defined by IP adress) I mean if a user exceeds a bandwith threshold example 1Go per day the internet connection for this user will be denied and he will not be able to connect to the internet till the next bussines day.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 10:58:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51500#M37886</guid>
      <dc:creator>Lahcen</dc:creator>
      <dc:date>2013-08-30T10:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: segmentation of bandwidth:</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51501#M37887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This function is not supported for now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 11:00:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51501#M37887</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-30T11:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: segmentation of bandwidth:</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51502#M37888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 14:18:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51502#M37888</guid>
      <dc:creator>Lahcen</dc:creator>
      <dc:date>2013-08-30T14:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: segmentation of bandwidth:</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51503#M37889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;While true out of the box, there is a way to accomplish this manually using the API interface and the dynamic address object feature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. You could create a dynamic address object that is referenced by the QoS policy. This policy is committed even though the DAO is empty.&lt;/P&gt;&lt;P&gt;2. When a user is manually detected as consuming too much bandwidth (DDoS protection looks at session levels, not bandwidth), you would add those users to the XML document referenced by a script (several ways to do that - manual script manipulation or the use of a block list API added into the GUI)&lt;/P&gt;&lt;P&gt;3. A process on your server would detect that the script was updated and execute the API to push the document to firewall(s) directly or via Panorama to populate the DAO on the firewall with your bad user(s)&lt;/P&gt;&lt;P&gt;4. Another automated process on your server would then remove the IP address of the bad actors at a set time every day based on the timestamp of the actor's addition&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See here as a potential basis for your workflow - &lt;A href="https://live.paloaltonetworks.com/docs/DOC-5411"&gt;Sample API workflow for Dynamic Address Objects&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obvious challenges here - besides writing scripts and monitoring CRON (or CRON-like processes) is tracking on bandwidth consumption by user. The function that is missing on the appliance is the lack of such a report. The only way to get that out of the appliance is to apply QoS as a reporting only (i.e. no max bandwidth) function, but you would need to create a policy per user - which is unrealistic. You would want to look to an external tool to gather this kind of information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 14:26:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/segmentation-of-bandwidth/m-p/51503#M37889</guid>
      <dc:creator>drwillis07</dc:creator>
      <dc:date>2013-08-30T14:26:15Z</dc:date>
    </item>
  </channel>
</rss>

