<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Marking non voice traffic as EF in PA-220 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/marking-non-voice-traffic-as-ef-in-pa-220/m-p/258818#M73402</link>
    <description>&lt;P&gt;I have a vpn tunnel &amp;amp; clients on the internal network need to initiate connections to a server on the other side (egress traffic).&amp;nbsp; The max upload speed of the broadband circuit is 5 megs which is always at max utilization.&amp;nbsp; Is there a way to mark traffic that is only best effort DSCP and change the value to EF 46 when crosses the Egress interface?&amp;nbsp; I set up a QoS profile using EF for all traffic to one destination but when I look at the captures the DSCP is still best effort/default.&amp;nbsp; I am trying to get this traffic to have the highest priority when going to the Egress interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 683px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19719i68953098DA5A0EA4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Apr 2019 20:12:17 GMT</pubDate>
    <dc:creator>MarioMarquez</dc:creator>
    <dc:date>2019-04-25T20:12:17Z</dc:date>
    <item>
      <title>Marking non voice traffic as EF in PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/marking-non-voice-traffic-as-ef-in-pa-220/m-p/258818#M73402</link>
      <description>&lt;P&gt;I have a vpn tunnel &amp;amp; clients on the internal network need to initiate connections to a server on the other side (egress traffic).&amp;nbsp; The max upload speed of the broadband circuit is 5 megs which is always at max utilization.&amp;nbsp; Is there a way to mark traffic that is only best effort DSCP and change the value to EF 46 when crosses the Egress interface?&amp;nbsp; I set up a QoS profile using EF for all traffic to one destination but when I look at the captures the DSCP is still best effort/default.&amp;nbsp; I am trying to get this traffic to have the highest priority when going to the Egress interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 683px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19719i68953098DA5A0EA4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2019 20:12:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/marking-non-voice-traffic-as-ef-in-pa-220/m-p/258818#M73402</guid>
      <dc:creator>MarioMarquez</dc:creator>
      <dc:date>2019-04-25T20:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Marking non voice traffic as EF in PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/marking-non-voice-traffic-as-ef-in-pa-220/m-p/258834#M73405</link>
      <description>&lt;P&gt;There are a couple options:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. If you want to set it on a specific type of traffic regardless of security rules, you can add a QoS policy for it to add the DSCP/ToS values.&lt;/P&gt;&lt;P&gt;Policies &amp;gt; QoS &amp;gt; Add &amp;gt; DSCP/ToS tab &amp;gt; Add.&lt;/P&gt;&lt;P&gt;Name: your choice&lt;/P&gt;&lt;P&gt;Type: EF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you don't want just EF, you can select others or even write a custom value (in binary).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. If you want to base it on specific security policies instead, you can open your security policy for this traffic and add a QoS marking:&lt;/P&gt;&lt;P&gt;Policies &amp;gt; Security &amp;gt; &lt;EM&gt;your_rule&lt;/EM&gt; &amp;gt; Actions tab &amp;gt; Other Settings section &amp;gt; QoS Marking. Chose IP DSCP and a new drop-down appears.&lt;/P&gt;&lt;P&gt;EF should be there, and should be 101110 in binary.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2019 22:43:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/marking-non-voice-traffic-as-ef-in-pa-220/m-p/258834#M73405</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-04-25T22:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Marking non voice traffic as EF in PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/marking-non-voice-traffic-as-ef-in-pa-220/m-p/258836#M73406</link>
      <description>Thanks! Do these options actually change the DSCP value from best effort to EF? If I look in the header I should see EF afterwards without needing to change the DSCP on the internal client app machines is that correct?</description>
      <pubDate>Fri, 26 Apr 2019 01:58:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/marking-non-voice-traffic-as-ef-in-pa-220/m-p/258836#M73406</guid>
      <dc:creator>MarioMarquez</dc:creator>
      <dc:date>2019-04-26T01:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Marking non voice traffic as EF in PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/marking-non-voice-traffic-as-ef-in-pa-220/m-p/258916#M73429</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;Do these options actually change the DSCP value from best effort to EF? If I look in the header I should see EF afterwards without needing to change the DSCP on the internal client app machines is that correct?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yep! It modifies it prior to egress:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKrCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKrCAK&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 17:20:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/marking-non-voice-traffic-as-ef-in-pa-220/m-p/258916#M73429</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-04-26T17:20:32Z</dc:date>
    </item>
  </channel>
</rss>

