<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Qos question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/157698#M51694</link>
    <description>&lt;OL&gt;&lt;LI&gt;Policy -&amp;gt; QoS&lt;/LI&gt;&lt;LI&gt;Add&lt;UL&gt;&lt;LI&gt;Name: Youtube&lt;/LI&gt;&lt;LI&gt;Source: Trusted&lt;/LI&gt;&lt;LI&gt;Destination:Untrusted&lt;/LI&gt;&lt;LI&gt;Application: [youtube]&lt;/LI&gt;&lt;LI&gt;Class:&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Quality-of-Service/ta-p/68633&amp;nbsp;" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Quality-of-Service/ta-p/68633&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 22 May 2017 18:04:03 GMT</pubDate>
    <dc:creator>jbhoorasingh</dc:creator>
    <dc:date>2017-05-22T18:04:03Z</dc:date>
    <item>
      <title>Qos question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/157676#M51692</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Let's say user wathing youtube , to limit the user's traffic ,&lt;BR /&gt;do we need to create qos profile for upload and download ?&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2017 17:52:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/157676#M51692</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-22T17:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: Qos question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/157698#M51694</link>
      <description>&lt;OL&gt;&lt;LI&gt;Policy -&amp;gt; QoS&lt;/LI&gt;&lt;LI&gt;Add&lt;UL&gt;&lt;LI&gt;Name: Youtube&lt;/LI&gt;&lt;LI&gt;Source: Trusted&lt;/LI&gt;&lt;LI&gt;Destination:Untrusted&lt;/LI&gt;&lt;LI&gt;Application: [youtube]&lt;/LI&gt;&lt;LI&gt;Class:&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Quality-of-Service/ta-p/68633&amp;nbsp;" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Quality-of-Service/ta-p/68633&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2017 18:04:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/157698#M51694</guid>
      <dc:creator>jbhoorasingh</dc:creator>
      <dc:date>2017-05-22T18:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Qos question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/157711#M51701</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am not talking about the qos policy rule , I am talking about the &amp;nbsp;profile &amp;nbsp;.&lt;/P&gt;&lt;P&gt;I just to mentioned 'youtube ' for easy understanding .&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I rephrase my question , &amp;nbsp;It would be like below&amp;nbsp;&lt;/P&gt;&lt;P&gt;If a user browsing internet &amp;nbsp;, Do &amp;nbsp;I need to set &amp;nbsp;download and upload profile (egress and ingress)&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2017 19:25:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/157711#M51701</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-22T19:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Qos question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/157790#M51711</link>
      <description>&lt;P&gt;To get best results you should decrypt traffic.&lt;/P&gt;&lt;P&gt;I have seen cases when Youtube was identified as SSL without decyption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As traffic comes from outside and heading inside you can't apply QoS to outside interface because at that point you don't know yet what this traffic is.&lt;/P&gt;&lt;P&gt;You need to let it into firewall to be analyzed and apply QoS profile to internal interface where traffic exits the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand if you want to QoS Youtube upload then you apply QoS to outside interface as traffic egress point is outside interface.&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 02:33:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/157790#M51711</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-23T02:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: Qos question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/157817#M51714</link>
      <description>&lt;P&gt;QoS shaping is applied the moment a packet is about to leave the firewall (on the egress interface):&lt;/P&gt;
&lt;P&gt;- to limit downloads the QoS profile on the internal interface is used (packets flowing from the internet and exiting onto your local network)&lt;/P&gt;
&lt;P&gt;- to limit uploads, the QoS profile of the untrust interface is applied (packet flowing from the lan and exiting onto the internet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in a single session 2 different QoS profiles can be hit (outbound and inbound packets)&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 07:07:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/157817#M51714</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-05-23T07:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: Qos question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/158022#M51743</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;A user just browsing cnn.com ,that means useer downloads and uploads the same time . Is there any issue If we just applied profile for limiting download only . What I mean does this effect CIR which is committed by ISP&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 07:12:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/158022#M51743</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-24T07:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: Qos question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/158036#M51749</link>
      <description>&lt;P&gt;its perfectly possible to only create a profile to linit downloads and not interfere with uploads at all (QoS does not even need to be enabled on the upstream interface)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 09:29:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/158036#M51749</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-05-24T09:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Qos question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/158194#M51788</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply . You are always &amp;nbsp;great help ! .&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just want rearrange my &amp;nbsp;very basic &amp;nbsp;and general qos question &amp;nbsp; , Let's say we have a &amp;nbsp;10 Mb download &amp;nbsp; commitement &amp;nbsp;with &amp;nbsp;ISP .And we have not yet applied &amp;nbsp;any qos profile ,so the user will be able to take all the bandwidth &amp;nbsp;which is 10 Mb .&lt;/P&gt;&lt;P&gt;Now we &amp;nbsp;have created a profile and applied on egress &amp;nbsp;with 5 classes &amp;nbsp;and each class &amp;nbsp;is 2 Mb limit &amp;nbsp;with same priority &amp;nbsp;and the user is in class 1 .What will happen in this case ? .How the qos will help us&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) &amp;nbsp;How this help us ISP's dropping the traffic &amp;nbsp;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a million&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 22:26:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/158194#M51788</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-24T22:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Qos question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/158205#M51791</link>
      <description>&lt;P&gt;I don't think it makes sense to set up 5 classes with 2Mbit each as if other classes are not in use then you don't use your full capability.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Few things that make sense to throttle are Dropbox application, Update applications using Application filter, Update URLs (for example create custom URL category and add MS update URL into it) etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you explain your issue?&lt;/P&gt;&lt;P&gt;ISP is dropping packets?&lt;/P&gt;&lt;P&gt;So what? If you enable QoS then it will be Palo who will drop packets to throttle traffic. Palo has to throw away packet from here and packet from there but TCP is smart and "tcp flow control" will keep traffic around the range you set with QoS.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 23:20:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/158205#M51791</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-24T23:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: Qos question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/158262#M51796</link>
      <description>I agree with &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt; , if you only have 10mbit it doesn't make much sense to limit all your classes to 2mb as this will limit the sessions every step of the way and will not change the fact packets need to get discarded to limit the bandwidth usage (if it's not the ISP, it's the firewall)&lt;BR /&gt;&lt;BR /&gt;You could work with one or a few classes that do have a guarantee for business critical apps, so that when your users are using your full bandwidth, your business critical applications will still function normally (while everything else will be dreadfully slow)&lt;BR /&gt;And a class (or a few) for bad applications you really want to limit (like streaming or online storage, ...) Set to 1mb limit for example&lt;BR /&gt;And finally a class that you use for your generic browsing with no limit or guarantee. It will be able to use all bandwidth unless one of your guarantee classes is active at which time it will surrender the bandwidth to those classes (make sure to set the profile limit to 10mb)&lt;BR /&gt;&lt;BR /&gt;(Class priority should not be a factor as that relates to platform IO and 10mb should not be an issue, but you can put the business critical class on real-time just to make sure it gets priority queueing if it's ever needed)&lt;BR /&gt;&lt;BR /&gt;Hope this helps! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Thu, 25 May 2017 07:54:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/158262#M51796</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-05-25T07:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: Qos question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/158290#M51804</link>
      <description>&lt;P&gt;Just be sure that you create class 4 in your profile.&lt;/P&gt;&lt;P&gt;Class 4 is default class for traffic that is does not match to any QoS policy.&lt;/P&gt;&lt;P&gt;If class 4 is missing from profile it can cause big issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: So I went to look up article about issue if class 4 is not set and here it is.&lt;/P&gt;&lt;P&gt;&lt;A title="https://live.paloaltonetworks.com/t5/Management-Articles/Firewall-Slows-Down-and-Stops-Forwarding-Traffic-after-Applying/ta-p/59213" href="https://live.paloaltonetworks.com/t5/Management-Articles/Firewall-Slows-Down-and-Stops-Forwarding-Traffic-after-Applying/ta-p/59213" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Firewall-Slows-Down-and-Stops-Forwarding-Traffic-after-Applying/ta-p/59213&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue is that there are other guidelines that suggest not to set class 4.&lt;/P&gt;&lt;P&gt;Final note says "&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;SPAN&gt; Only desired classes can be defined in the QoS profile. The rest of the traffic would default to class 4."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A title="https://live.paloaltonetworks.com/t5/Configuration-Articles/Incorrect-QoS-Configuration-Caused-Network-Traffic-Outage/ta-p/62576" href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Incorrect-QoS-Configuration-Caused-Network-Traffic-Outage/ta-p/62576" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Incorrect-QoS-Configuration-Caused-Network-Traffic-Outage/ta-p/62576&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;or&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A title="https://live.paloaltonetworks.com/t5/tkb/articleprintpage/tkb-id/ConfigurationArticles/article-id/1128" href="https://live.paloaltonetworks.com/t5/tkb/articleprintpage/tkb-id/ConfigurationArticles/article-id/1128" target="_blank"&gt;https://live.paloaltonetworks.com/t5/tkb/articleprintpage/tkb-id/ConfigurationArticles/article-id/1128&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;as those articles are quite old can you check internally what is current suggestion. And it is a bit unclear if policy needs to exist for class 4 or both policy and class in profile.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 13:05:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-question/m-p/158290#M51804</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-25T13:05:34Z</dc:date>
    </item>
  </channel>
</rss>

