<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo alto traffic shaping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195077#M58308</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the reply . The internet router which I mentioned in the diagram is located in premise.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I do classification&amp;nbsp; on the router , atleast can I control the congestion happening on the&amp;nbsp; interface which is connected to the ISP ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe a dumb question &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sat, 13 Jan 2018 15:30:35 GMT</pubDate>
    <dc:creator>simsim</dc:creator>
    <dc:date>2018-01-13T15:30:35Z</dc:date>
    <item>
      <title>Palo alto traffic shaping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195054#M58303</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the below topology .&amp;nbsp; &amp;nbsp;video conference device is connected in distribution .&lt;/P&gt;&lt;P&gt;All the devices are cisco . Actually I want to prioritize and&amp;nbsp; reserve&amp;nbsp; 10 mb for&amp;nbsp; the vc .&lt;/P&gt;&lt;P&gt;Marking&amp;nbsp;&amp;nbsp;the vc network as real time will help . I have never seen the dataplane&amp;nbsp; going high in palo alto .&amp;nbsp;&lt;/P&gt;&lt;P&gt;The real congestion is facing at internet router .In that case what I can do ?&lt;/P&gt;&lt;P&gt;Please help&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Traffic Shapping.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13218i7848A8207BBBF664/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Traffic Shapping.png" alt="Traffic Shapping.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 14:56:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195054#M58303</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2018-01-13T14:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto traffic shaping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195067#M58304</link>
      <description>&lt;P&gt;Based on your description, I think setting up QoS egress bandwidth guarantee would help on the PA side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;naturally once the traffic hits the internet no one can help further, but at least the PA bandwidth would be reserved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/quality-of-service/qos-concepts/qos-bandwidth-management" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/quality-of-service/qos-concepts/qos-bandwidth-management&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 15:08:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195067#M58304</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-01-13T15:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto traffic shaping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195068#M58305</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the reply .&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I classify the&amp;nbsp; traffic&amp;nbsp; on the internet router based on the PA marking (Like cisco )&amp;nbsp; &amp;nbsp;, would it be helpful ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or it's not possible ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 15:13:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195068#M58305</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2018-01-13T15:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto traffic shaping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195075#M58306</link>
      <description>&lt;P&gt;Generally classification is not read or honored on internet path routers.&amp;nbsp; So there is not real advantage to marking traffic as it enters the internet.&amp;nbsp; Really does not matter what brand you have.&amp;nbsp; On the public internet we don't honor client traffic markings at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This QoS bandwidth reservation will keep your own internal traffic from crowding out the traffic type.&amp;nbsp; This you can control.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 15:22:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195075#M58306</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-01-13T15:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto traffic shaping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195077#M58308</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the reply . The internet router which I mentioned in the diagram is located in premise.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I do classification&amp;nbsp; on the router , atleast can I control the congestion happening on the&amp;nbsp; interface which is connected to the ISP ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe a dumb question &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 15:30:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195077#M58308</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2018-01-13T15:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto traffic shaping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195078#M58309</link>
      <description>&lt;P&gt;Yes, that all will work as per the standards for both the PA and the routers you control.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 15:31:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195078#M58309</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-01-13T15:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto traffic shaping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195081#M58311</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;In that case , To classify on internet facing router , Can i get the required marking from the PA or it hast be done on the distribution ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 15:44:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195081#M58311</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2018-01-13T15:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto traffic shaping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195082#M58312</link>
      <description>&lt;P&gt;Best practice is to mark the dscp code as close to ingress as practical then have all devices in the path honor the classifications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a practical matter of course it only comes into play when you have congested links.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 15:47:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195082#M58312</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-01-13T15:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto traffic shaping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195212#M58346</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In between internet router , there is cisco firewall and switch between .&amp;nbsp;&lt;/P&gt;&lt;P&gt;What actually I found switch cpu is going very high and found some drops on the interface ,&lt;/P&gt;&lt;P&gt;In that case do I need to apply qos on the switch also ?&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 03:31:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195212#M58346</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2018-01-16T03:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto traffic shaping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195304#M58357</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59972"&gt;@simsim&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;High CPU on a switch isn't necissary an issue. If you run 'show processes cpu history' in EXEC and see what your CPU utilization history is. Is the CPU constantly busy or is it just spiking? Are the spikes lining up with a known event or activity pattern? Are you having any larger issues within Layer2 that could be causing higher CPU utilization across the board? If your substained CPU baseline is higher than 60% I would say this could be causing issues on a broader scope.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as the drops go, QoS helps with conjested links. So you won't get rid of the interface drops, you'll simply ensure that traffic you care about has a higher chance of getting processed through the queue before a drop takes place. If you have a highly conjested link on a switch struggling to process traffic in a timely manner you could still see drops with QoS in place if it can't process the traffic in the queue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas&lt;/a&gt;&amp;nbsp;already pointed out; if you are applying QoS it should be applied across the entire path.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 14:06:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-traffic-shaping/m-p/195304#M58357</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-16T14:06:33Z</dc:date>
    </item>
  </channel>
</rss>

