<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-820 - Am I asking too much! in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-820-am-i-asking-too-much/m-p/191543#M57680</link>
    <description>&lt;P&gt;Thanks Reaper.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thats the same advise as I was given yesterday re-intra-zone policies to acheive what I want so I appreciate your input and I'll rework the design.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue of how to allocate bandwidth per client/subnet is indeed a bit harder. Based on what I've looked at and your feedback I think I need to look for another solution to manage this aspect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2017 15:32:33 GMT</pubDate>
    <dc:creator>TimWarren-Oxygen</dc:creator>
    <dc:date>2017-12-13T15:32:33Z</dc:date>
    <item>
      <title>PA-820 - Am I asking too much!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-820-am-i-asking-too-much/m-p/191242#M57635</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've been asked to assess if PA-820s could be used to support a smallish MSP environment and as I'm new to the PA world (and indeed MSP network design) I'm hopeful some of you can point me in the right direction. I may be going about the design wrong so do say if you think there are better/relatively cost free ways to acheive the desired outcome (i.e. utilizing existing Cisco routers for QoS).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Requirements:-&lt;/P&gt;&lt;P&gt;Support 10-20 clients. Each client could potentially have 3 security zones. So we naturally hit a limitation as the 820 only supports 30 zones.&lt;/P&gt;&lt;P&gt;Apply QoS per client AND combine QoS across each of the clients security zones, primarily for bandwidth limits per customer. The issue here is that the 820 only supports QoS applied to physcial interface and not the subs. i.e client would purchase x Mbps of bandwidth to be shared by all zones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Initial idea:&lt;/P&gt;&lt;P&gt;PA has 4 ports and the zone outline would be:&lt;/P&gt;&lt;P&gt;1. Internet (Untrusted)&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;Internal zones (with each client having a tagged sub-int and associated security zone). This would connected to virtualisation platform.&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. DMZ zones (with each client having a tagged sub-int and associated security zone).&lt;/P&gt;&lt;P&gt;3. WAN zones (as above leading to customer site)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issues with 820s as I initally look at it:&lt;/P&gt;&lt;P&gt;Security zone limit&lt;/P&gt;&lt;P&gt;No QoS on sub-interfaces&lt;/P&gt;&lt;P&gt;I could live with not having a combined QoS as customers would generally fall into two categories.&lt;/P&gt;&lt;P&gt;a. Those only needing a WAN zone&lt;/P&gt;&lt;P&gt;b. Those that have hosted environment typically utilise a terminal server solution so with management most traffci to/from internet can pass either through the Internal zone and/or web gateway within DMZ zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've attached a high level overview of what I envisage a single customer would look like.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Generic Customer Network" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12953i45A082F7910BD0D9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Generic Customer.png" alt="Generic Customer Network" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Generic Customer Network&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I know I'm asking a lot of you!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 02:33:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-820-am-i-asking-too-much/m-p/191242#M57635</guid>
      <dc:creator>TimWarren-Oxygen</dc:creator>
      <dc:date>2017-12-12T02:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: PA-820 - Am I asking too much!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-820-am-i-asking-too-much/m-p/191541#M57679</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77495"&gt;@TimWarren-Oxygen&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interesting design. Why are you placing each client in it's own subinterface? To save on zones, you can also set all (or most) the subinterfaces on one physical to the same zone and then create an intra-zone policy to block/allow or simply scan. This woiuld spare you a bunch of zones as these 20*3 clients/zones could be served by 3 distinct zones.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;QoS may not scale as there's only 8 classes (QoS is mostly geared toward controlling groups of applications rather than unique sources) but I guess you could if you wanted to by applying a profile to source interface or subnet:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sourced QoS.png" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12986i5C80C31EF22AAD95/image-size/large?v=v2&amp;amp;px=999" role="button" title="sourced QoS.png" alt="sourced QoS.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 15:21:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-820-am-i-asking-too-much/m-p/191541#M57679</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-13T15:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: PA-820 - Am I asking too much!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-820-am-i-asking-too-much/m-p/191543#M57680</link>
      <description>&lt;P&gt;Thanks Reaper.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thats the same advise as I was given yesterday re-intra-zone policies to acheive what I want so I appreciate your input and I'll rework the design.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue of how to allocate bandwidth per client/subnet is indeed a bit harder. Based on what I've looked at and your feedback I think I need to look for another solution to manage this aspect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 15:32:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-820-am-i-asking-too-much/m-p/191543#M57680</guid>
      <dc:creator>TimWarren-Oxygen</dc:creator>
      <dc:date>2017-12-13T15:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: PA-820 - Am I asking too much!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-820-am-i-asking-too-much/m-p/192265#M57773</link>
      <description>&lt;P&gt;I wonder if you might not be better off scaling with a VM host server setup and just spinning up virtual PA per client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 13:30:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-820-am-i-asking-too-much/m-p/192265#M57773</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-12-19T13:30:05Z</dc:date>
    </item>
  </channel>
</rss>

