<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query on QoS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-qos/m-p/151878#M50259</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;by default any sessions that do not match any policy,will be set as class4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So you could use class1 to shape your video/voice and then leave class4 open (no guarantee, no limit)&lt;/P&gt;
&lt;P&gt;I would recommend setting a limit to the profile used for the internet so the&amp;nbsp;total bandwidth cannot be exceeded&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the DMZ profile can simply be set to a total limit of 1000 and no classes or policies defined (will default to class 4)&lt;/P&gt;</description>
    <pubDate>Mon, 10 Apr 2017 07:44:39 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-04-10T07:44:39Z</dc:date>
    <item>
      <title>Query on QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-qos/m-p/151595#M50184</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to configure QoS on PA to give priority to VOIP and video based traffic. The Internet connected to the FW is 100Mbps and the connection between the core switch and PA is 1Gbps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I make a QoS profile and I want a guaranteed bandwidth of 25Mbps, but what about max bandwidth? What do I set? 100 Mbps?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If so, when applying this profile to the Egress interfaces, won’t this cause an issue with the 1Gbps link?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also am I able to just create a profile just for voip and video traffic to give them priority, and the rest of the traffic passes through normally after priority has been given to voip and video? Or do I have to create a profile for the rest of the traffic?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 02:06:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/query-on-qos/m-p/151595#M50184</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-04-07T02:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: Query on QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-qos/m-p/151634#M50189</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please check out this article as it explains QoS in more detail: &lt;A title=" Getting Started: Quality of Service" href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Quality-of-Service/ta-p/68633" target="_blank"&gt; Getting Started: Quality of Service&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you activate QoS you'll need to account for all traffic, so you will want to make a few considerations for upload and download: QoS is applied on the egress interface&lt;/P&gt;
&lt;P&gt;So this means you will have 2 different profiles used for every flow, any uploads to the internet will match the QoS profile on the external interface while downloads will hit the QoS profile on the trust interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so consider this example&lt;/P&gt;
&lt;P&gt;eth1/1 is untrust&lt;/P&gt;
&lt;P&gt;eth1/2 is trust&lt;/P&gt;
&lt;P&gt;eth1/3 is dmz&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can also differentiate between source interfaces, so if you want to limit download from the internet (eg eth1/1) but not from your DMZ (eg eth1/3) you can create a 100mbit profile on eth1/2 (trust) for source interface eth1/1 and a 1000mbit one for source interface eth1/3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="qos sources limits.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="qos sources limits.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;make sure to use a different class than class4 for you video as class4 is the default for all traffic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 07:51:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/query-on-qos/m-p/151634#M50189</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-04-07T07:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Query on QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-qos/m-p/151856#M50257</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So I want to apply QoS prioritisation on video and voice traffic to and from the internal network only. That is from the trust zone to the untrust zone, and between the untrust zone and the trust zone.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I only want to give prioritisation to video and voice, I would like all other traffic to be processed normally, I also do NOT want to shape traffic to or from the DMZ zone.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I understand that I need create two rules one for inbound and one for outbound.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But do I need to create policies for all other traffic? So I don’t set a max egress on the physical interface?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Apr 2017 23:55:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/query-on-qos/m-p/151856#M50257</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-04-09T23:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Query on QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-qos/m-p/151878#M50259</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;by default any sessions that do not match any policy,will be set as class4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So you could use class1 to shape your video/voice and then leave class4 open (no guarantee, no limit)&lt;/P&gt;
&lt;P&gt;I would recommend setting a limit to the profile used for the internet so the&amp;nbsp;total bandwidth cannot be exceeded&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the DMZ profile can simply be set to a total limit of 1000 and no classes or policies defined (will default to class 4)&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 07:44:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/query-on-qos/m-p/151878#M50259</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-04-10T07:44:39Z</dc:date>
    </item>
  </channel>
</rss>

