<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: qos in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/156523#M51388</link>
    <description>&lt;P&gt;Download traffic is also egress on the untrust side as well. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess I don't follow what limitations&amp;nbsp;you are trying to support.&lt;/P&gt;</description>
    <pubDate>Sat, 13 May 2017 12:25:16 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2017-05-13T12:25:16Z</dc:date>
    <item>
      <title>qos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/155267#M51082</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;After egress max set &amp;nbsp;in the following order ,&lt;/P&gt;&lt;P&gt;If &amp;nbsp;100 Mb is the internet speed&amp;nbsp;and &amp;nbsp; through the trust link (1 GB) &amp;nbsp;traffic is going other than untrust ( internet zone ) ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;the below configuration is ok ? .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;class 1 10&lt;/P&gt;&lt;P&gt;class 2 10&lt;/P&gt;&lt;P&gt;class 3 10&lt;/P&gt;&lt;P&gt;class 4 &amp;nbsp;40&lt;/P&gt;&lt;P&gt;class 5 10&lt;/P&gt;&lt;P&gt;class 6 10&lt;/P&gt;&lt;P&gt;class 7 5&amp;nbsp;&lt;/P&gt;&lt;P&gt;class 8 5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 15:06:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/155267#M51082</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-05T15:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: qos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/155394#M51117</link>
      <description>&lt;P&gt;Sorry, I'm not understanding the question fully. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you are wondering about applying a QoS setting to trust that would perhaps limit traffic pre-maturely because the internet bandwidth is much more limited than your local one.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This would be a concern and you should have the internet QoS only applied to your untrust internet facing interface and NOT the trust interface.&lt;/P&gt;</description>
      <pubDate>Sun, 07 May 2017 12:19:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/155394#M51117</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-05-07T12:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: qos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/156520#M51387</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the reply&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"This would be a concern and you should have the internet QoS only applied to your untrust internet facing interface and NOT the trust interface"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To limit &amp;nbsp;the download bandwidth we should apply on our trust interface (egress ) &amp;nbsp;, correct me if i am wrong ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2017 09:13:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/156520#M51387</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-13T09:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: qos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/156523#M51388</link>
      <description>&lt;P&gt;Download traffic is also egress on the untrust side as well. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess I don't follow what limitations&amp;nbsp;you are trying to support.&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2017 12:25:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/156523#M51388</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-05-13T12:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: qos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/156530#M51393</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I was trying to limit download from the internet by the user &amp;nbsp;who is sitting inside the campus network .&lt;/P&gt;&lt;P&gt;If I have internet bandwidth 100 Mbps,&amp;nbsp;all the suers ( from class 1 - 8 ) should not send traffic to the service provider more than that ( I mean ISP should not have a chance to drop the traffic ) .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope I could clarify&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2017 15:02:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/156530#M51393</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-13T15:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: qos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/156532#M51395</link>
      <description>&lt;P&gt;QoS has to be applied to the interface where traffic will exit firewall.&lt;BR /&gt;For download traffic it has to be applied to trust interface.&lt;/P&gt;&lt;P&gt;Only be careful if you have multiple zones.&lt;BR /&gt;Assume you have 3 zones - internet, servers, users.&lt;BR /&gt;If you apply QoS on "users" zone then it means that download is limited from internet&amp;gt;users and also servers&amp;gt;users.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;To avoid that you should tune QoS interface &amp;gt; Clear Text Traffic&lt;BR /&gt;Also same place is where you set your Egress Max 100Mbit.&lt;BR /&gt;It does not make sense to set Classes so that aggregate max is 100Mbit becase your traffic will never balance between classes to get full 100Mbit.&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2017 16:18:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/156532#M51395</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-13T16:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: qos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/156554#M51405</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;We should apply all the egress interface (inside and outside ) to limit the download and upload .&lt;BR /&gt;For example user a is trying to access website cnn.com from the internal host ,&lt;BR /&gt;the traffic is flowing from the internal network to internet and also in reverse direction .&lt;BR /&gt;let 's say if we have 100 Mbps internet bandwidth and if we have profile only to limit the download (on the inside interface)&lt;BR /&gt;the traffic will flow from the internal network to the internet ,So there is chance ISP drop this traffic(so the traffic does not exceed network capacity which is alotted by the &amp;nbsp;ISP )&lt;BR /&gt;Please correct me if I am wrong&lt;/P&gt;&lt;P&gt;So we should have profile on both egress( internal and wan) .&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 14 May 2017 07:39:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos/m-p/156554#M51405</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-14T07:39:57Z</dc:date>
    </item>
  </channel>
</rss>

