<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: QoS and interfaces - some conception advice needed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/102978#M44600</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx for your replays. I had a lot of work with migration and network rearranging...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used all my phisical interfaces.&lt;/P&gt;&lt;P&gt;But I still ned advice ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 50Mbit link from ISP. I'd like to share on ethernet1/2 10Mbit max but when this bandwith is not used on this interface I would to consume that bandwitch on other interfaces.&lt;/P&gt;&lt;P&gt;How to get it working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know article &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Incorrect-QoS-Configuration-Caused-Network-Traffic-Outage/ta-p/62576" target="_self"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Incorrect-QoS-Configuration-Caused-Network-Traffic-Outage/ta-p/62576&lt;/A&gt; and other&lt;/P&gt;&lt;P&gt;But I cant find exact examples with ISP speed and limitation on interfaces like in my example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;</description>
    <pubDate>Mon, 15 Aug 2016 11:14:23 GMT</pubDate>
    <dc:creator>_slv_</dc:creator>
    <dc:date>2016-08-15T11:14:23Z</dc:date>
    <item>
      <title>QoS and interfaces - some conception advice needed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/101228#M44434</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will migrate fom PA200 to PA500. I have some local networks (DMZ, Wifi for students, Wifi for stuff, LANs)&lt;/P&gt;&lt;P&gt;I need to use QoS but I need some advice with that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that I can controll only on outgoing interfaces but I have no idea how to get it working with one condition: I wouldnt limit traffic from/to my local servers in DMZ.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I have all my lans as a subinterfaces of ethernet1/4&lt;/P&gt;&lt;P&gt;Should I separate my lans ir: DMZ to ethernet 1/2, WIfi to 1/3, LAN_1 to 1/4 and so on?&lt;/P&gt;&lt;P&gt;I assume that ISP is on ethernet 1/1 as an Untrust zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to _not_ limit traffc to ie. Wifi from DMZ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN&gt;I will be&lt;/SPAN&gt; &lt;SPAN&gt;grateful&lt;/SPAN&gt; &lt;SPAN class=""&gt;for any suggestions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text"&gt;SLawek&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 15:12:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/101228#M44434</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2016-08-04T15:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: QoS and interfaces - some conception advice needed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/101310#M44477</link>
      <description>&lt;P&gt;no one ?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 14:30:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/101310#M44477</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2016-08-05T14:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: QoS and interfaces - some conception advice needed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/101328#M44483</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You cannot apply QoS on subinterfaces, so you don't really have a choice here. Each network will need his own physical interface. You can apply multiple QoS profiles on an interface, based on the source interface or subnet, so you&amp;nbsp;could have different limits depending on the source of the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 18:38:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/101328#M44483</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2016-08-05T18:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: QoS and interfaces - some conception advice needed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/101405#M44502</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;100% agree with Baudy, QoS can't be configured on sub-interface.&lt;/P&gt;&lt;P&gt;QoS only impact outcomming traffic. Mean if you want to limit donwload / Streaming traffic from wifi, you need to configure QoS rule not on your ISP interface but on your physical wifi interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;link:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/quality-of-service/configure-qos" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/quality-of-service/configure-qos&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sense ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 14:02:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/101405#M44502</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2016-08-08T14:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: QoS and interfaces - some conception advice needed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/102520#M44574</link>
      <description>&lt;P&gt;Let's say you have an interface for untrust zone, another for trust zone, a third for wifi, and a fourth for DMZ. &amp;nbsp;Seems you want to be able to use QoS on all interfaces but not mess with DMZ. &amp;nbsp;The process is to setup QoS on each interface with no limitations, so it functions as a monitor. &amp;nbsp;Then use the QoS levels as buckets to hold your apps (see below). &amp;nbsp;Finally, apply the actual caps to the QoS profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are a couple very good articles describing in detail how to setup QoS. &amp;nbsp;Here is a quick summary of what I would do in your situation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First define QoS profiles for each zone, with a max set to 1000, and define the levels such that each has a guaranteed min of .01 &amp;amp; max of 1000. &amp;nbsp;This setup allows you to begin monitoring the traffic on each interface. &amp;nbsp;Once you apply each named policy to each interface (Trust-profile to Trust interface, etc.), you'll notice that all the traffic is in the default level 4. &amp;nbsp;The next step is to actually control the traffic. So set levels 1-3 as bogus stuff, and levels 5 &amp;amp; above as time-sensitive and critical. &amp;nbsp;Leave Level 4 alone, since that is your normal business traffic and catch all. For example, level 1 can be reserved for "games" and the highest level for "VoIP" - Using just this simple Q0S profile example, apply it to the Trust Interface and monitor QoS in the Network tab. &amp;nbsp;You'll see the actual usage of these apps that you defined for each level. &amp;nbsp;Once you understand what bandwidth the applications are actually using, go back to the profile and in the coresponding level, set a max limit for the bandwidth. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By defining separate QoS profiles for each interface, you can monitor them all, with minimal configuration. Customize the profile assigned to the interface you want to manage, and you can actually control the traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2016 06:58:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/102520#M44574</guid>
      <dc:creator>rabolfathi</dc:creator>
      <dc:date>2016-08-12T06:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: QoS and interfaces - some conception advice needed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/102978#M44600</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx for your replays. I had a lot of work with migration and network rearranging...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used all my phisical interfaces.&lt;/P&gt;&lt;P&gt;But I still ned advice ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 50Mbit link from ISP. I'd like to share on ethernet1/2 10Mbit max but when this bandwith is not used on this interface I would to consume that bandwitch on other interfaces.&lt;/P&gt;&lt;P&gt;How to get it working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know article &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Incorrect-QoS-Configuration-Caused-Network-Traffic-Outage/ta-p/62576" target="_self"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Incorrect-QoS-Configuration-Caused-Network-Traffic-Outage/ta-p/62576&lt;/A&gt; and other&lt;/P&gt;&lt;P&gt;But I cant find exact examples with ISP speed and limitation on interfaces like in my example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2016 11:14:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/102978#M44600</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2016-08-15T11:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: QoS and interfaces - some conception advice needed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/103389#M44616</link>
      <description>&lt;P&gt;Hi Slawek&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there is no configuration that would allow you to share 'leftover' bandwidth from one interface with another interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you illustrate the scenario you're trying to achieve? maybe there's&amp;nbsp; different solution&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;right now you can simply divy up available bandwidth on a single interface in terms of maximum allowed usage or minimum guaranteed bandwidth. on a policy where only a guarantee is defined, any 'leftover' bandwidth on that same interface will be used up until another guarantee is enforced. if no sessions exist for a guaranteed policy, that bandwidth will also be available to other policies&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 09:54:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-and-interfaces-some-conception-advice-needed/m-p/103389#M44616</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-08-16T09:54:45Z</dc:date>
    </item>
  </channel>
</rss>

