Applying QOS bandwidth restriction

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Applying QOS bandwidth restriction

L0 Member

Hi,

 

I would like to understand if my FW is capable of the below using QOS:

- I am using PA-1410 in HA pair

- I have 1 ISP internet link with 50Mbps bandwidth connected to eth1/1

- I have a requirement to create a guest network using the same ISP link and assign 10Mbps out of 50Mbps.

 

So. using the same outside interface (eth1/1) I want to reserve 10Mbps only for a sub-interface dedicated to guest network. Is that doable with Qos?

 

Many thanks 

 

 

4 REPLIES 4

Community Team Member

Hi @Ahmed_94 ,

 

You won’t be able to apply QoS directly on a subinterface on the PA-1410, but you can classify the guest VLAN traffic on the physical interface (eth1/1) and put it into a lower-priority or max-bandwidth QoS class. This won’t guarantee a strict 10 Mbps slice, but it will prevent the guest VLAN from saturating your 50 Mbps link.

 

 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Cyber Elite
Cyber Elite

Hello @Ahmed_94

 

only to add to what Jay mentioned, this KB: Why is QoS Setting Not Available Under subinterface? explains what Firewall models are supporting QoS in sub-interface.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi Jay, thank you for your response.

 

Just want to clarify what you meant by "put it into a lower-priority or max-bandwidth QoS class", so in the default profile I assign a low-priority class like 6 and also assign the max bandwidth allowed as 10Mbps, as below. is that what you meant?

 

And then in the policy I put the guest vlan into class 6 and the profile assigned to interface eth1/1.

 

 

 

Ahmed_94_0-1764564444823.png

 

 

Thanks

Cyber Elite
Cyber Elite

QoS profile needs to be applied to egress interface.

If you apply it to eth1/1 then you effectively throttle/prioritize upload bandwidth and not download.

 

Assign profile to internal interface.

With policy assign guest traffic to a specific class.

In QoS profile give this class 10Mbit/s.

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 134 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!