<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Communication performance issues between zones in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/communication-performance-issues-between-zones/m-p/291089#M77245</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have a firewall configured with different zones (users, servers-prod, servers-dev). At network configuration level, 4 network interfaces are linked to 1 aggregate&amp;nbsp; group and under this aggreate group, I have on subinterface linked with each secuirty zone (ae1.1 for users, ae1.2 for servers-prod, ae1.3 for servers-dev). The 4 interfaces of the Palo Alto are connected on a Cisco stack with aggregate configuration on the Cisco.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem is : when I start a copy between 2 servers hosted in servers-prod zone, 1 have a good speed for the copy but when I try to copy the same file between users to servers-prod, the speed of the copy is bad. Do you have an idea about this performance issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Oct 2019 13:36:16 GMT</pubDate>
    <dc:creator>CARRIERJerome</dc:creator>
    <dc:date>2019-10-03T13:36:16Z</dc:date>
    <item>
      <title>Communication performance issues between zones</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-performance-issues-between-zones/m-p/291089#M77245</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have a firewall configured with different zones (users, servers-prod, servers-dev). At network configuration level, 4 network interfaces are linked to 1 aggregate&amp;nbsp; group and under this aggreate group, I have on subinterface linked with each secuirty zone (ae1.1 for users, ae1.2 for servers-prod, ae1.3 for servers-dev). The 4 interfaces of the Palo Alto are connected on a Cisco stack with aggregate configuration on the Cisco.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem is : when I start a copy between 2 servers hosted in servers-prod zone, 1 have a good speed for the copy but when I try to copy the same file between users to servers-prod, the speed of the copy is bad. Do you have an idea about this performance issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2019 13:36:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-performance-issues-between-zones/m-p/291089#M77245</guid>
      <dc:creator>CARRIERJerome</dc:creator>
      <dc:date>2019-10-03T13:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Communication performance issues between zones</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-performance-issues-between-zones/m-p/291135#M77251</link>
      <description>&lt;P&gt;Have you tried setting an app override to see if that speeds up the transfer?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2019 16:57:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-performance-issues-between-zones/m-p/291135#M77251</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-10-03T16:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Communication performance issues between zones</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-performance-issues-between-zones/m-p/291149#M77254</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84878"&gt;@CARRIERJerome&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;There's a few things you can do:&lt;/P&gt;&lt;P&gt;1) You can do what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;suggested and utilize an application-override policy, although this will disable content inspection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) You can disable server response inspection, which will still allow content inspection and proper application inspection to take place while still giving you increased speeds.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which method you go with really depends on your needs and how secure you actually want to make the traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2019 18:39:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-performance-issues-between-zones/m-p/291149#M77254</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-10-03T18:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Communication performance issues between zones</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-performance-issues-between-zones/m-p/291290#M77267</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I desactivated the server response on the Policy Rule (policy rule to allow SMB access) but without any change about the performance. When I copy a file between 2 servers under the same zone (prod-servers), there is no bad performance but when I copy the same file between to differents zones (users to servers-prod), the speed for the copy is very poor.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 06:47:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-performance-issues-between-zones/m-p/291290#M77267</guid>
      <dc:creator>CARRIERJerome</dc:creator>
      <dc:date>2019-10-04T06:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: Communication performance issues between zones</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-performance-issues-between-zones/m-p/291364#M77270</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84878"&gt;@CARRIERJerome&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Okay, so next step would be to create an application-override policy for the traffic. By default, the traffic entering and leaving from the same zone would hit your intrazone-default policy. That policy doesn't actually perform any content inspection and simply does application identification. The application-override policy will prevent content inspection from taking place, but the trade-off is much faster SMB transfers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 13:18:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-performance-issues-between-zones/m-p/291364#M77270</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-10-04T13:18:04Z</dc:date>
    </item>
  </channel>
</rss>

