Qos question

Reply
Highlighted
L4 Transporter

Qos question

PA-DEL-1.png

Hi,

I have traffic shaping enabled on FG and at the same time PA also.

traffic flow is as below 

client  goes through  FG then PA then go to internet or wan 

traffic shaping  policy running on  fortigate  , and qos policy is there on PA also 

Let's say if i set bandwidth for client A ON fortigate 10 Mbps and   20 Mbps on PA , Speedtest Showing 10 Mbps 

My expectation is  client should get 20 Mbps

PA in vwire mode  (qos enabled on LAn interface ) 

 

What could be the reason , How can I solve the issue 

Thanks

 

 

 

 

 

 

 

 

 

 

Highlighted
Cyber Elite

hi @simsim 

I don't see an issue here. I sounds like everything works as it is configured. To "solve" the issue you need to configure the fortinet also to 20 mbps.

Highlighted
Community Team Member

Hi @simsim ,

 

Agreed with @vsys_remo .

If you throttle one side of a pipe you can't expect a bigger throughput on the other side.

 

Cheers,

-Kiwi.

 
Highlighted
L4 Transporter

Hi,

"

Let's say if i set bandwidth for client A ON fortigate 10 Mbps and   20 Mbps on PA , Speedtest Showing 10 Mbps 

My expectation is  client should get 20 Mbps"

 

My question is  PALO ALTO won't override the QOS value set by the fortigate ?

 

Thanks

Highlighted
L4 Transporter

Hi @kiwi 

What if it is the other way around ? 

Let's say on FORTIGATE if I set 20Mbps and on PA set 10Mbps ?

Shall the client   get  20 Mbps ?

Thanks

Highlighted
Community Team Member

Hi @simsim ,

 

No, in that scenario the bottleneck will be the Palo Alto Device.  Your device will have 20Mbps through the Fortigate but once you reach the PA you will get 10Mbps.

 

In your first scenario you will have 10Mbps through the Fortigate to begin with ... the PA can't make 20Mbps out of the 10Mbps it's getting from the Fortigate.

 

If the devices are inline then the device with the most restricted speed will be the maximum speed for that pipe. 

 

Cheers,

Kiwi.

Tags (1)
Highlighted
L4 Transporter

Hi,

"If the devices are inline then the device with the most restricted speed will be the maximum speed for that pipe. "

 

Why palo alto not overriding the  qos value which is set by fortigate in this scenario 

Thanks

 

 

 

 

 

Highlighted
L2 Linker

Hi @simsim 

 

No , Paloalto cannot override the QOS tweak done by fortinet. In this scenario it would be better to maintain QOS policies in only a single device ( FG or PA).

Thanks,

Ram 

Highlighted
L4 Transporter

Hi,

Paloalto cannot override the QOS tweak done by fortinet

Any reason for that  paloalto cannot overwrite /override . 

Or all the network devices behavior is same (eg : cisco router ) 

Thanks

Highlighted
L2 Linker

HI @simsim ,

Assume we have ISP of 10 mbps , can we get 20 mbps using any device . The answer is certainly "NO".  in such a way pa is receiving only 10 mbps so it cant be increased . Any device cannot increase the bandwidth more than it recieved.

Hope it helps

Thanks,

Ram

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!