<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic QoS Best Practices - complete concept/configuration - big picture for QoS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/qos-best-practices-complete-concept-configuration-big-picture/m-p/5651#M4139</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already read the &lt;A href="https://live.paloaltonetworks.com/docs/DOC-3439"&gt;QoS in PAN-OS 4.1&lt;/A&gt; document and the QoS section in the &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6590"&gt;Panorama Administrator's Guide 6.0 (English)&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;But there a still big question marks hovering over my head. :smileyconfused:&lt;/P&gt;&lt;P&gt;The examples show only one use case/qos-profile at one time: "QoS for a Single User" or "QoS for Voice and Video Applications" or "restrict downloads to 15 Mbps".&lt;/P&gt;&lt;P&gt;But I dont see a configuration where all these use cases are combined together.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe someone can provide me with proper screenshots of their qos configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So lets say:&lt;/P&gt;&lt;P&gt;ethernet1/1 - zone untrust = 300MBit internet link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ethernet1/22 with different sub-interfaces = 10GBit = development clients&lt;/P&gt;&lt;P&gt;ethernet1/23 with different sub-interfaces = 10GBit = server infrastructure&lt;/P&gt;&lt;P&gt;ethernet1/24 with different sub-interfaces = 10GBit = clients also different wireless clients/interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At first I didn't understand the need to setup the Egress Max (Mbps) on the physical interface.&lt;/P&gt;&lt;P&gt;Ok at ethernet1/1 this is the only place where it makes sense, I have a 300MBit internet link. (Physical connected to 1GB)&lt;/P&gt;&lt;P&gt;But it's only the egress traffic (uploading to the internet).&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/14682_pastedImage_5.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But what should I do with the ingress traffic from the internet?&lt;/P&gt;&lt;P&gt;I can't limit the egress max on the physical interface for ethernet1/22-24 to 300MBit (as seen in other discussions) because there is a lot of other traffic not only from/to the internet.&lt;/P&gt;&lt;P&gt;And also different interfaces connects to the internet (ethernet1/1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To classify the traffic is easy-peasy but then?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To start with:&lt;/P&gt;&lt;P&gt;a) I want all salesforce traffic to be in class3 (prio high) and a "Egress Guaranteed" with 30MBit&lt;/P&gt;&lt;P&gt;b) I want all video application to be in class1 (prio real-time) and a "Egress Guaranteed" with 20MBit&lt;/P&gt;&lt;P&gt;c) normal web-browsing to be in class5 (prio medium) and a "Egress Guaranteed" with 20MBit but should not have an effect when I browse to an internal server (standing in ethernet1/23)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I should not create a single QoS-Profile for salesforce and video application and web-browsing?&lt;/P&gt;&lt;P&gt;Should i create a QoS-Profile incoming-untrust and outgoing-untrust?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is the right place to set the egress maximum for the ethernet1/1 (ingress/downloading)?&lt;/P&gt;&lt;P&gt;On the QoS-Interface it would affect all traffic not only the traffic that is coming from ethernet1/1 is'nt it?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/14696_pastedImage_13.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I have to do that on the QoS Profile?&lt;/P&gt;&lt;P&gt;Seems that correct to you?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-3 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/14697_pastedImage_14.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And what happends to all the other traffic?&lt;BR /&gt;Goes than untouched bypass-traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phew! &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;P&gt;Sebastian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Jul 2014 17:02:05 GMT</pubDate>
    <dc:creator>sebastian</dc:creator>
    <dc:date>2014-07-25T17:02:05Z</dc:date>
    <item>
      <title>QoS Best Practices - complete concept/configuration - big picture for QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-best-practices-complete-concept-configuration-big-picture/m-p/5651#M4139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already read the &lt;A href="https://live.paloaltonetworks.com/docs/DOC-3439"&gt;QoS in PAN-OS 4.1&lt;/A&gt; document and the QoS section in the &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6590"&gt;Panorama Administrator's Guide 6.0 (English)&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;But there a still big question marks hovering over my head. :smileyconfused:&lt;/P&gt;&lt;P&gt;The examples show only one use case/qos-profile at one time: "QoS for a Single User" or "QoS for Voice and Video Applications" or "restrict downloads to 15 Mbps".&lt;/P&gt;&lt;P&gt;But I dont see a configuration where all these use cases are combined together.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe someone can provide me with proper screenshots of their qos configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So lets say:&lt;/P&gt;&lt;P&gt;ethernet1/1 - zone untrust = 300MBit internet link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ethernet1/22 with different sub-interfaces = 10GBit = development clients&lt;/P&gt;&lt;P&gt;ethernet1/23 with different sub-interfaces = 10GBit = server infrastructure&lt;/P&gt;&lt;P&gt;ethernet1/24 with different sub-interfaces = 10GBit = clients also different wireless clients/interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At first I didn't understand the need to setup the Egress Max (Mbps) on the physical interface.&lt;/P&gt;&lt;P&gt;Ok at ethernet1/1 this is the only place where it makes sense, I have a 300MBit internet link. (Physical connected to 1GB)&lt;/P&gt;&lt;P&gt;But it's only the egress traffic (uploading to the internet).&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/14682_pastedImage_5.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But what should I do with the ingress traffic from the internet?&lt;/P&gt;&lt;P&gt;I can't limit the egress max on the physical interface for ethernet1/22-24 to 300MBit (as seen in other discussions) because there is a lot of other traffic not only from/to the internet.&lt;/P&gt;&lt;P&gt;And also different interfaces connects to the internet (ethernet1/1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To classify the traffic is easy-peasy but then?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To start with:&lt;/P&gt;&lt;P&gt;a) I want all salesforce traffic to be in class3 (prio high) and a "Egress Guaranteed" with 30MBit&lt;/P&gt;&lt;P&gt;b) I want all video application to be in class1 (prio real-time) and a "Egress Guaranteed" with 20MBit&lt;/P&gt;&lt;P&gt;c) normal web-browsing to be in class5 (prio medium) and a "Egress Guaranteed" with 20MBit but should not have an effect when I browse to an internal server (standing in ethernet1/23)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I should not create a single QoS-Profile for salesforce and video application and web-browsing?&lt;/P&gt;&lt;P&gt;Should i create a QoS-Profile incoming-untrust and outgoing-untrust?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is the right place to set the egress maximum for the ethernet1/1 (ingress/downloading)?&lt;/P&gt;&lt;P&gt;On the QoS-Interface it would affect all traffic not only the traffic that is coming from ethernet1/1 is'nt it?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/14696_pastedImage_13.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I have to do that on the QoS Profile?&lt;/P&gt;&lt;P&gt;Seems that correct to you?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-3 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/14697_pastedImage_14.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And what happends to all the other traffic?&lt;BR /&gt;Goes than untouched bypass-traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phew! &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;P&gt;Sebastian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2014 17:02:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-best-practices-complete-concept-configuration-big-picture/m-p/5651#M4139</guid>
      <dc:creator>sebastian</dc:creator>
      <dc:date>2014-07-25T17:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: QoS Best Practices - complete concept/configuration - big picture for QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-best-practices-complete-concept-configuration-big-picture/m-p/5652#M4140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sebastian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lemme clarify this, QoS policy is session based. So if you have a QoS policy for outbound traffic then all the return traffic will also follow the QoS policy and bandwidth limiting is done based on the QoS profile applied to inside interface.&lt;/P&gt;&lt;P&gt;Please take a look at below screenshots and let me know if that makes sense to you.&lt;/P&gt;&lt;P&gt;In below screenshots ethernet1/1(Untrust-L3) is outside interface and ethernet1/2(trust-L3) is inside interface.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="QoS2.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14698_QoS2.PNG" style="height: 112px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="QoS3.PNG" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14699_QoS3.PNG" style="height: 256px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="QoS4.PNG" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/14700_QoS4.PNG" style="height: 365px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="QoS1.PNG" class="jive-image image-3" src="https://live.paloaltonetworks.com/legacyfs/online/14701_QoS1.PNG" style="height: 134px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2014 22:14:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-best-practices-complete-concept-configuration-big-picture/m-p/5652#M4140</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2014-07-25T22:14:26Z</dc:date>
    </item>
  </channel>
</rss>

