I would like to share issues with GlobalProtect, and what was done to fix it.
QoS with loopback interface
Due to high network load on the Internet line, we wanted to priorize (or limit) some traffic. It took several hours (testing, reading documents, having a PA supporter analyzing the issue, ...) until the root cause was identified. Applying QoS on a loopback interface is simply not supported. So we had to migrate the GP gateway from a loopback to a secondary IP (you can have more than one secondary IP) on the physical interface. The secondary IP was added with netmask /32. We had to update our security policy due to the interface of the gateway is now part of a different zone.
Limit bandwidth of SMB traffic
A good amount of traffic sent to the clients is caused by our software deployment (and patch management). The files/packages are provided on SMB-fileshares. By limiting this traffic (QoS policy based on the servers, regardless of the application) we ran into unexpected side effects with our fileservices (which is served by other servers, not related to the ones limited). There is only one "SMB-process" on the client machine. If a SMB connection to server A (our software deployment server), then this process chokes on SMB connections with server B. Luckily we are able to shift software deployment from SMB to http(s).
Maybe a dumb question, but are the "more specific" rules for your app deployment servers higher in your QoS ruleset? Those are processed in order and exit on first match.
Also, are your rules configured bi-directional? I found that I had to list source and destination zones and IP's in both the source and destination field for it to catch the traffic. I'm guessing since it's the clients that initiate the transfer after the server instructs the client to do so.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!