<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Filtering Traffic Throughput in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-traffic-throughput/m-p/139770#M48175</link>
    <description>&lt;P&gt;there is no 'slowdown' when only URL filtering is applied as the traffic does not need to be scanned as it does with threats. there is simply a category lookup and then an allow or deny action with no further actions on that session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also&lt;/P&gt;
&lt;P&gt;Traffic will never ever ever be throttled&lt;/P&gt;
&lt;P&gt;these throughput numbers are _measured_ througputs (not limited) when only AppID was enabled and when all bells and whistles were enabled, so there is some throughput impact when all traffic is being scanned, but this is related to how the traffic is flowing through the system and is being inspected for threats, there is no throttle preventing traffic to surpass the 5Gbps mark&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in some cases, if your traffic is 'scan friendly' you may even have close to the 10gbps traffic even with threat prevention enabled, it depends on how much work your chassis needs to put in to get all the traffic scanned&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jan 2017 14:21:17 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-01-27T14:21:17Z</dc:date>
    <item>
      <title>URL Filtering Traffic Throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-traffic-throughput/m-p/139748#M48173</link>
      <description>&lt;P&gt;Does anyone know for certain what the maximum throughput of a Palo firewall is if the only security profile applied is URL Filtering?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The PA-5050 can do 10Gbps of App-ID firewall throughput and 5 Gbps of Threat Prevention throughput.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you pushed 6 Gbps of traffic through a PA-5050 with only URL filtering applied, would the PA-5050 throttle&amp;nbsp;the traffic to 5 Gbps because of the limit to Threat Prevention throughput or would it let the traffic through at full speed given the 10 Gbps App-ID throughput?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to decode the HTTP header to determine the URL correctly and this means Content Inspection (which implies the traffic is limited to Threat Prevention throughput).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, according to the link below, the URL match happens on the same processors that do the App-ID (Security processor) and not the same as IPS, spyware, etc (Signature matching processors) so possibly URL filtering can happen at App-ID throughput speeds.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.paloaltonetworks.com/products/secure-the-network/next-generation-firewall/pa-5000-series" target="_blank"&gt;https://www.paloaltonetworks.com/products/secure-the-network/next-generation-firewall/pa-5000-series&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 12:51:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-traffic-throughput/m-p/139748#M48173</guid>
      <dc:creator>catalan</dc:creator>
      <dc:date>2017-01-27T12:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Traffic Throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-traffic-throughput/m-p/139770#M48175</link>
      <description>&lt;P&gt;there is no 'slowdown' when only URL filtering is applied as the traffic does not need to be scanned as it does with threats. there is simply a category lookup and then an allow or deny action with no further actions on that session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also&lt;/P&gt;
&lt;P&gt;Traffic will never ever ever be throttled&lt;/P&gt;
&lt;P&gt;these throughput numbers are _measured_ througputs (not limited) when only AppID was enabled and when all bells and whistles were enabled, so there is some throughput impact when all traffic is being scanned, but this is related to how the traffic is flowing through the system and is being inspected for threats, there is no throttle preventing traffic to surpass the 5Gbps mark&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in some cases, if your traffic is 'scan friendly' you may even have close to the 10gbps traffic even with threat prevention enabled, it depends on how much work your chassis needs to put in to get all the traffic scanned&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 14:21:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-traffic-throughput/m-p/139770#M48175</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-01-27T14:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Traffic Throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-traffic-throughput/m-p/140008#M48212</link>
      <description>&lt;P&gt;Thank you for the clarification on how the traffic is processed.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2017 10:10:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-traffic-throughput/m-p/140008#M48212</guid>
      <dc:creator>catalan</dc:creator>
      <dc:date>2017-01-30T10:10:28Z</dc:date>
    </item>
  </channel>
</rss>

