QOS and internet traffic

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

QOS and internet traffic

L4 Transporter

Can PANOS controll / rate limit  internet downloads ?

 

On my squid boxes I can ratelimit and it does this by delaying acks.

 

Can the PA QOS do this work as well ?

 

1 ACCEPTED SOLUTION

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @Alex_Samad

 

yes, the Palo Alto Networks firewall can also perform Quality of Service, please check out this article: Getting Started: Quality of Service

Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy

View solution in original post

9 REPLIES 9

Cyber Elite
Cyber Elite

Hi @Alex_Samad

 

yes, the Palo Alto Networks firewall can also perform Quality of Service, please check out this article: Getting Started: Quality of Service

Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy

Thought I would come back to this.

 

So it can only apply QOS to the egress interface.

 

so if you have a PA with eth1 -> internet and eth2 -> proxy server.

 

you apply QOS for internet download traffic to eth2

 

you can't apply QOS on eth1 for inbound.

 

Not exactly what I wanted but atleast now I know

 

The advantage of applying QoS on the egress interface is that at that time paloalto already knows a lot about the traffic that it is processing (specially the app) so it gives you the possibility for very granular bandwidth limitations per app/app group/app filter group...

The problem is QOS doesn't just work on sub interfaces it works on the whole interface.

 

I have a 80G LACP ae and QOS only works up to 40G from memory, so to turn on QOS I have seperarte out interface. I prefer a single trunk with sub int on it.

 

it would be nice if it slowed ACK's back to the web site for web site downloads.. like squid does

 

A

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!