<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: QoS_Rate-Limit_Guest Network_NAT query_Configuration example in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/qos-rate-limit-guest-network-nat-query-configuration-example/m-p/341627#M85684</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;QOS policy is evalauted before the NAT, so always it should be for&amp;nbsp; Pre-NAT ip.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;</description>
    <pubDate>Fri, 31 Jul 2020 16:39:19 GMT</pubDate>
    <dc:creator>RamprakashRT</dc:creator>
    <dc:date>2020-07-31T16:39:19Z</dc:date>
    <item>
      <title>QoS_Rate-Limit_Guest Network_NAT query_Configuration example</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-rate-limit-guest-network-nat-query-configuration-example/m-p/334123#M84326</link>
      <description>&lt;P&gt;could someone advise me to set rate-limit for guest(10.1.10.0/24) traffic in this topology&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNARNI_3-1592498823681.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26260i836B0F7ECAF51034/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DNARNI_3-1592498823681.png" alt="DNARNI_3-1592498823681.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read the article that We need to apply policy on egress interface always. Hence, for upload, it's on outside interface connected to Internet and for download it is on inside interface (ae) connected to SW&lt;/P&gt;&lt;P&gt;(1) Internet Speed 500 Mbps&lt;/P&gt;&lt;P&gt;(2) Rate-limit for Guest traffic (10.1.10.0/24 GW is on Firewall ae.10 ) to any traffic both download and upload -100 Mbps&lt;/P&gt;&lt;P&gt;(3) All internal IP addresses both Guest and Enterprise Networks are translated to same Public IP&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if I want to achieve it,&amp;nbsp;&lt;/P&gt;&lt;P&gt;(1) Create QoS Profile " MyQos" with Egress max -100 Mbps and I don't add any classes as I know there is no Voice or video from Guest Network Range like below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNARNI_5-1592498893400.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26262iC480B01F165D0B1D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DNARNI_5-1592498893400.png" alt="DNARNI_5-1592498893400.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(2) apply this to outside interface connected to internet and also to aggregate interface "ae.10 "&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNARNI_4-1592498856246.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26261i56E445EC2DC004FA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DNARNI_4-1592498856246.png" alt="DNARNI_4-1592498856246.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(3)Create QoS Policy - Here do I need two policies - one from Trust --&amp;gt;untrust zone&amp;nbsp;&lt;/P&gt;&lt;P&gt;and for download , Untrust --&amp;gt; to Trust&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also, what IP ranges I need to select in source selection, is it before NAT or post NAT&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 16:49:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-rate-limit-guest-network-nat-query-configuration-example/m-p/334123#M84326</guid>
      <dc:creator>DNARNI</dc:creator>
      <dc:date>2020-06-18T16:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: QoS_Rate-Limit_Guest Network_NAT query_Configuration example</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-rate-limit-guest-network-nat-query-configuration-example/m-p/341627#M85684</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;QOS policy is evalauted before the NAT, so always it should be for&amp;nbsp; Pre-NAT ip.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 16:39:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-rate-limit-guest-network-nat-query-configuration-example/m-p/341627#M85684</guid>
      <dc:creator>RamprakashRT</dc:creator>
      <dc:date>2020-07-31T16:39:19Z</dc:date>
    </item>
  </channel>
</rss>

