<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Fail to configure download limitation on my pa firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/181729#M56072</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to limit download for our subnets. I configured a qos policy and&amp;nbsp;a traffic class profile,&amp;nbsp; next apply on trust zone interface.&amp;nbsp; Then I saw in the statistic, there was&amp;nbsp; runtime bandwidth&amp;nbsp; in class 4,&amp;nbsp; it seemed that all traffic was defined as class 4,&amp;nbsp; there was not runtime in any other class.&amp;nbsp; Could you tell me where I wrongly configured ? Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11927iC602F7C935AF6CF5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 660px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11928i73FC51DA2244298A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 572px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11929i088062AEF05B7F9B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2017 13:41:56 GMT</pubDate>
    <dc:creator>qq736401987</dc:creator>
    <dc:date>2017-10-13T13:41:56Z</dc:date>
    <item>
      <title>Fail to configure download limitation on my pa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/181729#M56072</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to limit download for our subnets. I configured a qos policy and&amp;nbsp;a traffic class profile,&amp;nbsp; next apply on trust zone interface.&amp;nbsp; Then I saw in the statistic, there was&amp;nbsp; runtime bandwidth&amp;nbsp; in class 4,&amp;nbsp; it seemed that all traffic was defined as class 4,&amp;nbsp; there was not runtime in any other class.&amp;nbsp; Could you tell me where I wrongly configured ? Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11927iC602F7C935AF6CF5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 660px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11928i73FC51DA2244298A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 572px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11929i088062AEF05B7F9B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 13:41:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/181729#M56072</guid>
      <dc:creator>qq736401987</dc:creator>
      <dc:date>2017-10-13T13:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Fail to configure download limitation on my pa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/181778#M56080</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please take a look into &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Apply-QoS-for-Youtube-or-Streaming-Media/ta-p/66036" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Apply-QoS-for-Youtube-or-Streaming-Media/ta-p/66036&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This is simple but should be a good start for You, as always please use "search" using QoS as a pattern there is a lot of topics with that&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 15:45:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/181778#M56080</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2017-10-13T15:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: Fail to configure download limitation on my pa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/182014#M56128</link>
      <description>&lt;P&gt;also check out the &lt;A title=" Getting Started: Quality of Service" href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Quality-of-Service/ta-p/68633" target="_blank"&gt; Getting Started: Quality of Service&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are you using NAT in your environment and are those hosts known to the outside as a public IP? you may need to set the pre-NAT IPs in the destination&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 08:43:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/182014#M56128</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-10-16T08:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: Fail to configure download limitation on my pa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/182160#M56147</link>
      <description>&lt;P&gt;My firewall outside interface connects to a router, the router translates all our private subnets into a public IP. Do you mean I need to define specified IP addresses insteaof&amp;nbsp;any&amp;nbsp;in the Qos of the policy ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 676px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11977i363C2E87A6C30323/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 05:40:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/182160#M56147</guid>
      <dc:creator>qq736401987</dc:creator>
      <dc:date>2017-10-17T05:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: Fail to configure download limitation on my pa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/182161#M56148</link>
      <description>&lt;P&gt;My failed configuration is referred from&amp;nbsp;the link you mentioned. I want to limit all download traffic for my subnets, not for a special application.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 05:44:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/182161#M56148</guid>
      <dc:creator>qq736401987</dc:creator>
      <dc:date>2017-10-17T05:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Fail to configure download limitation on my pa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/182168#M56149</link>
      <description>&lt;P&gt;Let's make sure we have the concepts right:&lt;/P&gt;
&lt;P&gt;You're trying to limit downloads, but in your first screenshot your policies have destination IP addresses, which would actually mean 'upload' (from the internet destined to the ip addresses)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The QoS policies first need to match the direction of a session:&lt;/P&gt;
&lt;P&gt;You first need to determine in which direction your session is going to be initiated: will the session start from a client on your network, or from the internet.&lt;/P&gt;
&lt;P&gt;You then create a QoS policy that matches that direction (don't mind up/down load just yet, we'll get to that in a second).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if you want to apply policy to your internal client, you make a QoS policy from trust to untrust and apply a class.&lt;/P&gt;
&lt;P&gt;If you want to limit what a client on the internet can do, create a policy from untrust to trust and apply a class.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Next step is to determine _what_ you want to limit: upload or download.&lt;/P&gt;
&lt;P&gt;This is where it gets interesting: up- or download depends on the direction of your session; a download for your LAN clients flows in the exact opposite direction as a download for an internet based client (in this case he/she is "downloading" from your server, which in regards to your network is an upload but in regards of the session direction is a download).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To prevent all the confusion above QoS is set up this way.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You already created a policy based on the direction of the flow.&lt;/P&gt;
&lt;P&gt;Now you need to add QoS profiles to your interfaces: QoS is applied on the &lt;STRONG&gt;egress&lt;/STRONG&gt; interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, if you add a QoS profile on your untrust interface, you can limit everything going TO the internet (regardless if it's up- or download) and if you apply a QoS profile to your trust you can control everything going TO your LAN network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any sessions that previosuly hit a QoS policy will now be categorized as a certain class and an appropriate QoS action will be applied.&lt;/P&gt;
&lt;P&gt;This also means that each flow can be controlled by 2 separate QoS profiles: one for the outgoing packets and one for incoming packets (eg you could limit outgoing packets to internet to 1mbps and limit returning packets to LAN to 5mbps)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tl;dr you probably need to switch your QoS policy to "trust to untrust"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps&lt;/P&gt;
&lt;P&gt;T&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 07:25:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/182168#M56149</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-10-17T07:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Fail to configure download limitation on my pa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/186453#M56876</link>
      <description>&lt;P&gt;Thanks. It&amp;nbsp;works. By&amp;nbsp;the&amp;nbsp;way, how can I limit download bandwidth base on per-IP instead of per-subnet?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 13:09:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/186453#M56876</guid>
      <dc:creator>qq736401987</dc:creator>
      <dc:date>2017-11-10T13:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: Fail to configure download limitation on my pa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/186455#M56877</link>
      <description>&lt;P&gt;you can use the /32 subnet but i would advise against this as this will most likely not&amp;nbsp;produce the desired result and make things very complex&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 13:37:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fail-to-configure-download-limitation-on-my-pa-firewall/m-p/186455#M56877</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-11-10T13:37:25Z</dc:date>
    </item>
  </channel>
</rss>

