<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Aggregate Interface Throughput limit - Multi VSYS - Shared Gateway. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226248#M65136</link>
    <description>&lt;P&gt;Would this also mean that I could not utilise the Shared Gateway? (I dont have many many interfaces to use on the firewall)&lt;/P&gt;&lt;P&gt;Would that also mean that all Inter - Vsys traffic would route via the upstream Router, not across the firewall shared gateway?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The whole point of my design is that the Shared Gateway means I dont have to have mulitple, VR's using dedicated seperate uplink interfaces to my Data centre?&lt;/P&gt;</description>
    <pubDate>Tue, 07 Aug 2018 09:33:31 GMT</pubDate>
    <dc:creator>mcnairi</dc:creator>
    <dc:date>2018-08-07T09:33:31Z</dc:date>
    <item>
      <title>Aggregate Interface Throughput limit - Multi VSYS - Shared Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/224973#M64588</link>
      <description>&lt;P&gt;Hi Community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have multiple VSYS setup that also uses Shared Gateway for collating access to my Data Centre to and from each VSYS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a PA5250 setup running OSPF with a 40G routed connection to my Data Cente (Northbound) - in the shared gateway area on a dedicated P2P 40G interface..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each VSYS has a secure zone and an unsecure zone. The Unsecure Zone is the shared gateway zone (standard SG setup) and the secure zone is a southbound facing interface within that VSYS that we apply policy on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Southbound the Secure Zone is serviced using an Aggregate Interface made up of 4 x 10G physical interfaces on the Firewall.&lt;/P&gt;&lt;P&gt;In this Aggregate Interface I have logical sub interfaces all using different layer 2 tags each "secure" network below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So for Example VSYS2 "Company A" has a secure area zone with sub interface AE4.101, and an interface in the unsecure zone using the Shared Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When sending traffic from AE4.101 to AE4.102 I hit a limit of 1.06Gbps and cannot exceed with any single TCP stream.&lt;/P&gt;&lt;P&gt;Further more, when I generate UDP traffic over 1.1Gbps, this destroys the OSPF adjacancies across the entire Firewall, even on interfaces that are not related to the flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems to me like some kind of logical limitation ( in built QOS, Ddos or control plane issue) with servicing traffic originating from and going to the same AE interface when using sub interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone heard of this or experienced any similar issues?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic going through the firewall either from the Shared Gateway to Sub interface or vice versa is fine at 10Gbps, its just sub interface to sub interface Im seeing the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks everyone in advance...:)&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 16:38:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/224973#M64588</guid>
      <dc:creator>mcnairi</dc:creator>
      <dc:date>2018-08-06T16:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Aggregate Interface Throughput limit - Multi VSYS - Shared Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/224990#M64589</link>
      <description>&lt;P&gt;That is because the inter vsys traffic is not process by the offload processor.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Differences-between-packets-in-slow-path-fast-path-and-offloaded/ta-p/58845" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Differences-between-packets-in-slow-path-fast-path-and-offloaded/ta-p/58845&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can also check while the traffic is passing the firewall, go to cli and show session id xxxx, you will see the traffic is not getting offload.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One way to work around this,&amp;nbsp;create multiple dedicated untrust interface and virtual router per vsys, and peer each of vsys directly to the upstream router(s).&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 19:23:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/224990#M64589</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2018-08-06T19:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: Aggregate Interface Throughput limit - Multi VSYS - Shared Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226232#M65133</link>
      <description>&lt;P&gt;Thanks Nextgenhappiness.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I just say that I have had a TAC case open for 3 weeks and your the only person that has confirmed my suspicion that the firewall is not handling the traffic as it should.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did not know that Inter-Vsys Traffic is not offloaded....WOW - major performance difference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really grateful for your input. The article is really interesting thank you:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very interested in your work around, - I dont really understand what you mean though, could you elaborate a little&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Took the caveat list from the web page you provided:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is also a type of traffic that will only be processed by CPU and will never be offloaded.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ARP (and all other non-IP traffic)&lt;/LI&gt;&lt;LI&gt;IPSec&lt;/LI&gt;&lt;LI&gt;Decrypted sessions&lt;/LI&gt;&lt;LI&gt;VPN sessions&lt;/LI&gt;&lt;LI&gt;non-TCP/UDP&lt;/LI&gt;&lt;LI&gt;Firewall bound session&lt;/LI&gt;&lt;LI&gt;Inter-vsys sessions&lt;/LI&gt;&lt;LI&gt;PBF session without next hop&lt;/LI&gt;&lt;LI&gt;NAT64&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 07 Aug 2018 09:06:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226232#M65133</guid>
      <dc:creator>mcnairi</dc:creator>
      <dc:date>2018-08-07T09:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Aggregate Interface Throughput limit - Multi VSYS - Shared Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226248#M65136</link>
      <description>&lt;P&gt;Would this also mean that I could not utilise the Shared Gateway? (I dont have many many interfaces to use on the firewall)&lt;/P&gt;&lt;P&gt;Would that also mean that all Inter - Vsys traffic would route via the upstream Router, not across the firewall shared gateway?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The whole point of my design is that the Shared Gateway means I dont have to have mulitple, VR's using dedicated seperate uplink interfaces to my Data centre?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 09:33:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226248#M65136</guid>
      <dc:creator>mcnairi</dc:creator>
      <dc:date>2018-08-07T09:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: Aggregate Interface Throughput limit - Multi VSYS - Shared Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226250#M65137</link>
      <description>&lt;P&gt;Hi Nextgen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is an output of an inter-vsys session that is using iperf3 reaching 1.06gbps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;where is the confirmation that its not being offloaded?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@GED-HRD-PA5250(active-secondary)&amp;gt; show session id 33591197&lt;/P&gt;&lt;P&gt;Session 33591197&lt;/P&gt;&lt;P&gt;c2s flow:&lt;BR /&gt;source: 10.64.3.20 [ECOM-LIVE-2-PROD-LIVE]&lt;BR /&gt;dst: 10.68.1.20&lt;BR /&gt;proto: 6&lt;BR /&gt;sport: 49715 dport: 5201&lt;BR /&gt;state: ACTIVE type: FLOW&lt;BR /&gt;src user: unknown&lt;BR /&gt;dst user: unknown&lt;BR /&gt;ecmp id: 8000&lt;/P&gt;&lt;P&gt;s2c flow:&lt;BR /&gt;source: 10.68.1.20 [VSYS-ECOM-ZONE-LIVE]&lt;BR /&gt;dst: 10.64.3.20&lt;BR /&gt;proto: 6&lt;BR /&gt;sport: 5201 dport: 49715&lt;BR /&gt;state: ACTIVE type: FLOW&lt;BR /&gt;src user: unknown&lt;BR /&gt;dst user: unknown&lt;BR /&gt;ecmp id: 8000&lt;/P&gt;&lt;P&gt;Slot : 1&lt;BR /&gt;DP : 1&lt;BR /&gt;index(local): : 36765&lt;BR /&gt;start time : Tue Aug 7 10:30:29 2018&lt;BR /&gt;timeout : 3600 sec&lt;BR /&gt;time to live : 3371 sec&lt;BR /&gt;total byte count(c2s) : 644&lt;BR /&gt;total byte count(s2c) : 390&lt;BR /&gt;layer7 packet count(c2s) : 8&lt;BR /&gt;layer7 packet count(s2c) : 6&lt;BR /&gt;vsys : vsys6&lt;BR /&gt;application : iperf&lt;BR /&gt;rule : ECOM-2-PROD-ANY&lt;BR /&gt;session to be logged at end : True&lt;BR /&gt;session in session ager : True&lt;BR /&gt;session updated by HA peer : False&lt;BR /&gt;session owner is HA A/A local device : True&lt;BR /&gt;session setup locally HA A/A : True&lt;BR /&gt;layer7 processing : completed&lt;BR /&gt;URL filtering enabled : False&lt;BR /&gt;session via syn-cookies : False&lt;BR /&gt;session terminated on host : False&lt;BR /&gt;session traverses tunnel : False&lt;BR /&gt;captive portal session : False&lt;BR /&gt;ingress interface : ae4.201&lt;BR /&gt;egress interface : ae4.205&lt;BR /&gt;session QoS rule : N/A (class 4)&lt;BR /&gt;tracker stage l7proc : ctd decoder bypass&lt;BR /&gt;end-reason : unknown&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 09:37:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226250#M65137</guid>
      <dc:creator>mcnairi</dc:creator>
      <dc:date>2018-08-07T09:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Aggregate Interface Throughput limit - Multi VSYS - Shared Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226294#M65150</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10932"&gt;@mcnairi&lt;/a&gt;It will depend on how many vsys you have. You can keep the shared gateway design, only those vsys that has performance issue, remove those vsys from the shared gateway and create their own untrust interface/zone and dedicated VR.&amp;nbsp; You could use sub interface as your uplink interfaces to your data center.&amp;nbsp; You will need to burn more IP addresses and few more vlans&lt;BR /&gt;&lt;BR /&gt;If the session is being process by the offloader, in the session id output "offload: yes" under c2s flow and s2c flow after the dst user:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 13:37:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226294#M65150</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2018-08-07T13:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Aggregate Interface Throughput limit - Multi VSYS - Shared Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226409#M65184</link>
      <description>&lt;P&gt;Hi Nextgen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate your help on this, have advised TAC of your findings, amd waiting for an answer from them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However I found the above link which talks about how you identity if traffic is offloaded:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Firewall-offloading-traffic-how-to-disable/ta-p/61278" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Firewall-offloading-traffic-how-to-disable/ta-p/61278&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically if the output says ctd decoder bypass - it is being offloaded.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my session output further up the thread, the session is inter-vsys and it is being offloaded:&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;ctd decoder bypass&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;P&gt;So, if Inter-Vysys traffic is being accelerated, does that mean its a different issue casuing the throuughput limitation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ps, I tried Interface 1 to Interface 2 on the same Vysys and got way above 1Gbps using iperf.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 13:05:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226409#M65184</guid>
      <dc:creator>mcnairi</dc:creator>
      <dc:date>2018-08-08T13:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Aggregate Interface Throughput limit - Multi VSYS - Shared Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226505#M65208</link>
      <description>&lt;P&gt;Looking for application SSL that goes from your trust zone to untrust zone ( to the Internet) and show session id xxxxx you should see the offload: yes there..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All the sessions between intervsys using shared gateway will not get process by the offloader.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 17:44:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226505#M65208</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2018-08-08T17:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: Aggregate Interface Throughput limit - Multi VSYS - Shared Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226584#M65219</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with you, however whats confusing me is that the traffic output i posted above - is - Inter-Vsys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface AE4.101 is in a different Vsys to AE4.105 (different sec zones too)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the ouput says it is offloaded.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So does this mean its not actually offloaded - because performance indications Im getting 1.06bgps, but the session output says it is offloaded....&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 08:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226584#M65219</guid>
      <dc:creator>mcnairi</dc:creator>
      <dc:date>2018-08-09T08:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Aggregate Interface Throughput limit - Multi VSYS - Shared Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226702#M65260</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that session you posted is not offloaded. &amp;nbsp;before you start the inter vsys iperf test, check your dp usage, show running resources min last 5 &amp;nbsp;start your iperf test for at 5 minutes or longer, while the iperf test is running , check the dp usage again, if you see all the dp cores usage goes up and verify which dp is running high, if that match your iperf session. &amp;nbsp;that tells you if the session is offloaded or not. &amp;nbsp;you can repeat the same iperf test behind the firewall and behind the upstream router and check the session log and dp usage while iperf test is running. &amp;nbsp;in the session id outout, you should see offload: yes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps.,&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 10:27:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-interface-throughput-limit-multi-vsys-shared-gateway/m-p/226702#M65260</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2018-08-10T10:27:14Z</dc:date>
    </item>
  </channel>
</rss>

