- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-24-2023 07:14 AM - edited 02-24-2023 07:16 AM
Hi,
I have a scenario in mind, for example:
1. We have physical interface for Internet link with a bandwidth of 50 Mbits/s, which is used to peer with our ISP and send internet-bound traffic through;
2. We have regular internet for users and VPN tunnel (to Prisma) using same link concurrently;
3. We have Subinterface configured on Physical interface for internet as upstream device expects tagged traffic.
Currently our setup in regards to QoS looks like following:
a. We set 50 Mbit/s as MAX Egress for Physical interface;
b. We set 0 as MAX Egress and 0 as MAX Guaranteed as Clear Text traffic on that interface;
c. We set 0 Mbit/s as MAX Egress and 0 Mbit/s for tunneled traffic, but within profile assigned here we set different percentages based on class for Guaranteed traffic
Overall it looks like this:
The main problem here is as you can see although same physical interface is restricted to 50 Mbit/s, EACH TYPE OF TRAFFIC gets 50 Mbit/s, while we want to have both types of traffic combined use same link up to 50 Mbit/s on that link and use it concurrently. In case of the congestion we would like tunneled traffic to be preferred, hence we are setting guaranteed percentage only for this.
Is such design actually possible to achieve in Palo?
02-24-2023 09:57 AM
Hello,
Check out this article, I think it might help.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS0CAK
Regards,
02-24-2023 10:01 AM
Thanks, but it doesn't help.
02-24-2023 10:10 AM
OK I might have misunderstood the question. Since the physical interface is the egress, that is where you want to set your policy, try making the changes there as QoS is applied at the egress interface.
02-24-2023 10:14 AM - edited 02-24-2023 10:16 AM
Well, my general question was - is it possible to have Clear Text and Tunneled traffic on a same interface to share shame MAX Egress Value? So if you have MAX Egress on interface of 50 Mbit/s, current Internet usage is at 30 Mbit/s, so Tunneled can use only its Guranateed 20 Mbit/s only and overall bandwith usage of Internet link not going higher than 50 Mbits? Without using MAX Egress on Clear Traffic and Tunnel Traffic profiles, as at one time we might have 10 Mbit/s for Internet and 40 Mbit/s for Tunneled and other time - 35 Mbit/s for Internet and 15 Mbit/s for Tunneled.
02-24-2023 10:19 AM
As QoS applies to egress interface your screenshot shows upload throttling not download throttling.
To apply how much users can download from internet you need to apply QoS to INSIDE interface.
On Clear Text Traffic and Tunneled Traffic tabs you can choose source interface and apply different QoS profiles to them.
02-24-2023 10:22 AM
Given that we have a PE and CPE provider's eiupement where bandwith is already policed at 50 Mbit/s both ways there's no point for me to do anything with dowload. Hence I am talking here ONLY about traffic leaving from firewall towards internet - Clear and Tunneled.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!