Clear Text and Tunnel traffic same physical interface QoS

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Clear Text and Tunnel traffic same physical interface QoS

L2 Linker



I have a scenario in mind, for example: 


1. We have physical interface for Internet link with a bandwidth of 50 Mbits/s, which is used to peer with our ISP and send internet-bound traffic through;

2. We have regular internet for users and VPN tunnel (to Prisma) using same link concurrently;

3. We have Subinterface configured on Physical interface for internet as upstream device expects tagged traffic. 


Currently our setup in regards to QoS looks like following:


a. We set 50 Mbit/s as MAX Egress for Physical interface;

b. We set 0 as MAX Egress and 0 as MAX Guaranteed as Clear Text traffic on that interface;

c. We set 0 Mbit/s as MAX Egress and 0 Mbit/s for tunneled traffic, but within profile assigned here we set different percentages based on class for Guaranteed traffic


Overall it looks like this:



The main problem here is as you can see although same physical interface is restricted to 50 Mbit/s, EACH TYPE OF TRAFFIC gets 50 Mbit/s, while we want to have both types of traffic combined use same link up to 50 Mbit/s on that link and use it concurrently. In case of the congestion we would like tunneled traffic to be preferred, hence we are setting guaranteed percentage only for this. 


Is such design actually possible to achieve in Palo?


Cyber Elite
Cyber Elite


Check out this article, I think it might help.



Thanks, but it doesn't help. 

Cyber Elite
Cyber Elite

OK I might have misunderstood the question. Since the physical interface is the egress, that is where you want to set your policy, try making the changes there as QoS is applied at the egress interface.

Well, my general question was - is it possible to have Clear Text and Tunneled traffic on a same interface to share shame MAX Egress Value? So if you have MAX Egress on interface of 50 Mbit/s, current Internet usage is at 30 Mbit/s, so Tunneled can use only its Guranateed 20 Mbit/s only and overall bandwith usage of Internet link not going higher than 50 Mbits? Without using MAX Egress on Clear Traffic and Tunnel Traffic profiles, as at one time we might have 10 Mbit/s for Internet and 40 Mbit/s for Tunneled and other time - 35 Mbit/s for Internet and 15 Mbit/s for Tunneled. 

Cyber Elite
Cyber Elite

As QoS applies to egress interface your screenshot shows upload throttling not download throttling.

To apply how much users can download from internet you need to apply QoS to INSIDE interface.

On Clear Text Traffic and Tunneled Traffic tabs you can choose source interface and apply different QoS profiles to them.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Given that we have a PE and CPE provider's eiupement where bandwith is already policed at 50 Mbit/s both ways there's no point for me to do anything with dowload. Hence I am talking here ONLY about traffic leaving from firewall towards internet - Clear and Tunneled. 

  • 6 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!