<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic on untrust interface - problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-on-untrust-interface-problem/m-p/9603#M7037</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the primary requirement that you would like to see the real internet traffic and not see the traffic when backup takes place as this is causing to consume a lot of bandwidth.&lt;/P&gt;&lt;P&gt;&amp;gt; One method is to have a security rule for backup traffic for servers but do not log them( Each security policy has log at session end which can be disabled). This makes sure that the PA 200 inline will have logs only for real internet traffic and you can monitor it. But the fact is backup server traffic is flowing through the same untrust interface. If the monitoring is done by external device other than PAN then we have to make changes on that device not to see back up traffic.&lt;/P&gt;&lt;P&gt;Hope this makes sense.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Oct 2012 12:47:50 GMT</pubDate>
    <dc:creator>Phoenix</dc:creator>
    <dc:date>2012-10-16T12:47:50Z</dc:date>
    <item>
      <title>Traffic on untrust interface - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-on-untrust-interface-problem/m-p/9600#M7034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a problem. I have 8Mb internet connections some of my servers are directly connected to internet (I have a switch connected to servers and PA200).&lt;/P&gt;&lt;P&gt;Every day throught untrust interface are made backups of this servers. So the traffic on untrust interface dramatically rise from few Mb to about 100Mbit during the time where backups are made.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im looking for ability to exclude traffic from policy thats allow traffic from backup servers to servers thats are on untrust interface.&lt;/P&gt;&lt;P&gt;I made diagrams of traffic using PRTG tools using SNMP protocol.&lt;/P&gt;&lt;P&gt;Any other idea to solve my problem are also welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2012 13:31:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-on-untrust-interface-problem/m-p/9600#M7034</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2012-10-12T13:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic on untrust interface - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-on-untrust-interface-problem/m-p/9601#M7035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you mean by that you want to exclude traffic from policy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What comes to mind is to setup QoS on your PA box to lower the priority of your backup traffic so production traffic will have it easier to function when the backups are being transmitted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 03:12:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-on-untrust-interface-problem/m-p/9601#M7035</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-16T03:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic on untrust interface - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-on-untrust-interface-problem/m-p/9602#M7036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My traffic (during the day) looks like this.&lt;/P&gt;&lt;P&gt; &lt;IMG alt="2012-10-16_125546.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4511_2012-10-16_125546.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;But at night because of backup traffic the scale of vertical changing to 100Mbit and my traffic looks:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2012-10-16_125603.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4513_2012-10-16_125603.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;and I cant&amp;nbsp; see details of my real internet traffic.&lt;/P&gt;&lt;P&gt;I wouldn't count backup traffic on untrust interface- is it possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;p.s. sorry for my bad english ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 11:04:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-on-untrust-interface-problem/m-p/9602#M7036</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2012-10-16T11:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic on untrust interface - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-on-untrust-interface-problem/m-p/9603#M7037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the primary requirement that you would like to see the real internet traffic and not see the traffic when backup takes place as this is causing to consume a lot of bandwidth.&lt;/P&gt;&lt;P&gt;&amp;gt; One method is to have a security rule for backup traffic for servers but do not log them( Each security policy has log at session end which can be disabled). This makes sure that the PA 200 inline will have logs only for real internet traffic and you can monitor it. But the fact is backup server traffic is flowing through the same untrust interface. If the monitoring is done by external device other than PAN then we have to make changes on that device not to see back up traffic.&lt;/P&gt;&lt;P&gt;Hope this makes sense.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 12:47:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-on-untrust-interface-problem/m-p/9603#M7037</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2012-10-16T12:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic on untrust interface - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-on-untrust-interface-problem/m-p/9604#M7038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As You sugested I unchecked Log on session start and log on session end - but it doesn't help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure that traffic counting on interface is depended on logging by policy?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2012 10:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-on-untrust-interface-problem/m-p/9604#M7038</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2012-11-12T10:12:54Z</dc:date>
    </item>
  </channel>
</rss>

