<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Qos profile in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150207#M49904</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt; would really recommend that you work on creating QOS statements on your access layer before you worry to much about working with QOS on your firewall unless your dataplane is constantly starved for resources."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it ok setting &amp;nbsp;qos &amp;nbsp;for skype through gpo on end user's pc&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://blogs.perficient.com/microsoft/2014/12/configuring-quality-of-service-for-lync-online/" target="_blank"&gt;http://blogs.perficient.com/microsoft/2014/12/configuring-quality-of-service-for-lync-online/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;or &amp;nbsp;is it must we need to do on access switches or in distribution switches&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Mar 2017 17:33:10 GMT</pubDate>
    <dc:creator>sib2017</dc:creator>
    <dc:date>2017-03-29T17:33:10Z</dc:date>
    <item>
      <title>Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/149936#M49854</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="traffice.JPG" style="width: 580px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8537i627EF4E8955ADA6B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="traffice.JPG" alt="traffice.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the above &amp;nbsp;which class will get high priority ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2017 15:28:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/149936#M49854</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-03-28T15:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/149990#M49862</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11223"&gt;@sib2017&lt;/a&gt;&amp;nbsp;The priority is listed in the far right &amp;nbsp;column. Class 2 traffic being real-time will be given the highest priority and everything but class4 is being assigned high priority. Keep in mind that everything by default is class4 on the PA., you need to enable QoS on the interface level, and it looks like whoever setup the Maximum egress didn't really care about anything but the default class4 traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would look at some of the QoS articles on live; most of them do a really good job of explaining things but setting up QoS on the PA can be seen as weird from someone used to primarly working with switches and routers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2017 18:57:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/149990#M49862</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-28T18:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150039#M49871</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you for the reply , I am using &amp;nbsp;class 2 for &amp;nbsp;skype and skype probe , the issue is &amp;nbsp;sometimes the audio is lagging &amp;nbsp;than video&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 01:51:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150039#M49871</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-03-29T01:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150040#M49872</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is it necessary to mark qos in the switch level ( from the access layer or distribution layer ), if we are enabling &amp;nbsp;qos on PA ?.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pa will mark &amp;nbsp;qos on the packet if we are sennding to the upstream router ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 02:37:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150040#M49872</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-03-29T02:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150067#M49877</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11223"&gt;@sib2017&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the PANW QoS is going to apply limits/make reservations and prioritize sessions on the system but will not mark packets&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;marking is supported on the security policies, but then an external device becomes responsible for enforcing QoS:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="qos marking.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/5DE745A4213343D2E26844B0146B285E/responsive_peak/images/image_not_found.png" alt="qos marking.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you want to prevent the audio/video from lagging, it may also be a good idea to set a reservation for bandwidth, so you don't run out.&lt;/P&gt;
&lt;P&gt;even with the priority set to realtime (which will assign top priority queueing in a dedicated queue) there may still be a bandwidth issue preventing you from achieving lossless audio/video&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 07:17:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150067#M49877</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-29T07:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150076#M49881</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi reaper ,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Usually the enforcing device must be the upstream device ( router or firewall ) ? .&lt;/P&gt;&lt;P&gt;I have deployed pa in vw mode. my upstream device is asa fw and then router&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 08:10:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150076#M49881</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-03-29T08:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150077#M49882</link>
      <description>&lt;P&gt;if you use the 'QoS marking' option, then yes, an upstream device needs to do the shaping&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you configure QoS on the PANW, it will&amp;nbsp;apply shaping just fine and you wont need external devices&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 08:17:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150077#M49882</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-29T08:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150083#M49884</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;If we configure the qos on PANOS and the packet reached on upstream asa or router , How the asa will treat this packet if there is no qos related service enabled ( policy )&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 09:01:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150083#M49884</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-03-29T09:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150090#M49886</link>
      <description>&lt;P&gt;sensing much confusion, I am&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ok ok lemme start fresh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) there are QoS policies and QoS profiled on the panw firewall which allow you to set maximum throughput or guaranteed throughput for certain classes of traffic. you can also set a priority which, in case the firewall is starved for resources (high DP load) can prioritize the IO of certain sessions. all this is achieved on the firewall without the outside being aware something is being limited or prioritized&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) QoS marking through a security policy: &lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/quality-of-service/enforce-qos-based-on-dscp-classification#_11409" target="_self"&gt;the firewall adds a QoS 'color' to the packets&lt;/A&gt; in a session (DSCP codepoint, like a flag in tcp header) so&amp;nbsp;external devices can pick up on these colored packets (upstream loadbalancers or other firewalls/routers) and prioritize/deprioritize based on the 'color' of the packet, IF they understand DSCP codepoints&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 09:45:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150090#M49886</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-29T09:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150130#M49891</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11223"&gt;@sib2017&lt;/a&gt;&amp;nbsp;if you're putting the time and effort to do QOS mappings on your ASA and PA then you really should enable it on the access layer. When setting up QOS you pretty much want to have it on the full stream if possible, but usually most people would do QOS on the access and distribution layer and then would have the firewall scaled&amp;nbsp;to the point they don't have to worry about doing QOS on it as much, as most ISPs won't listen to DSCP codepoints.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would really recommend that you work on creating QOS statements on your access layer before you worry to much about working with QOS on your firewall unless your dataplane is constantly starved for resources. It is far more likely that the access or distribution layer is dropping packets in the queue than your firewall dropping them, unless of course your ASA or PA is not scaled for your network properly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also yes if you have the PA set to do DSCP codepoints you also need to tell your ASA what to do with them so that it prioritizes things properly. It's important to note that QOS simply tells the device how it should be processing the traffic; so if the traffic can all be processed almost instantly and not build up in the queue then you really never take advantage of your QOS statements, but if the queue starts to fill up then the device uses the QOS statements to know what you want to prioritize and actually process first, second, third, and so on.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 13:29:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150130#M49891</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-29T13:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150207#M49904</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt; would really recommend that you work on creating QOS statements on your access layer before you worry to much about working with QOS on your firewall unless your dataplane is constantly starved for resources."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it ok setting &amp;nbsp;qos &amp;nbsp;for skype through gpo on end user's pc&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://blogs.perficient.com/microsoft/2014/12/configuring-quality-of-service-for-lync-online/" target="_blank"&gt;http://blogs.perficient.com/microsoft/2014/12/configuring-quality-of-service-for-lync-online/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;or &amp;nbsp;is it must we need to do on access switches or in distribution switches&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 17:33:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150207#M49904</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-03-29T17:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150216#M49906</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you verify how much class 2 traffic goes through your firewall when you test Skype? Does it constantly cap at 25 Mbps? You can see the real-time statistics under the Network tab, then QoS and click on Statistics for the desired interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 17:44:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150216#M49906</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2017-03-29T17:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150227#M49908</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11223"&gt;@sib2017&lt;/a&gt;&amp;nbsp;end-user qos is usually done more so for simplified QOS markings; basically so that you know what DSCP value will come across so that you can quickly build the QOS statements on your switches. Once the traffic is tagged with DSCP 46 you still need to tell the switch how to actually process the DSCP 46 traffic and what priority it should actually get that traffic out of the outbound/inbound queue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sounds like what you should do is&lt;/P&gt;&lt;P&gt;1) Build the GPO so that you know what DSCP value is going to be marked&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Build out the qos statements on your switches (no idea what brand you are using for this, I could provide a Cisco example if that is what you are using). Depending on the brand it may default to standard QOS statements, but likely qos isn't enabled out of the box.&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) If it's still choppy then start looking at QOS on the PA; likely though you are running into issues before you reach the firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 18:35:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150227#M49908</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-29T18:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: Qos profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150317#M49931</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;yes I am using cisco 3850 at access layer&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 05:17:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-profile/m-p/150317#M49931</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-03-30T05:17:46Z</dc:date>
    </item>
  </channel>
</rss>

