- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-05-2016 08:13 PM
Hi,
If I have 100 Mbps internet download speed ,
If I want to shape like below
Class 1 , 10
Class 2, 5
Class 3, 5
Class 5 , 10
Class 6, 5
Class 7 , 5
Class 8, 5
Do i need to assign Reamining 45 to (default class(4))
The interface is 1Gbps
So what would be the value of default class
Thanks
09-06-2016 01:40 AM
are those limits or guarantees ?
if they're limits, class 4 will consume the remaining 45 and more if more is available, it will then share bandwidth based on priority (typically class 1-3 are higher priority than 4, 5-8 are lower priority, slightly influencing IO) so unless you want to add guarantees to the remaining (or some of the) classes, it would be a good idea to set a limit for class 4 as well so you don't deprive your 'high priority' traffic of bandwidth
if those are guarantees, class 4 will not be able to consume more than 45 unless a class is not currently active in a session
if you set the profile 'Egress Max' to 100, the total bandwidth on the interface will not exceed 100Mbps
09-06-2016 06:31 AM
Can I get more info on this?
I was always told that the Palo can't "shape or rate-limit." That palo can only QoS mark or provide a total bandwidth quota. Is that not true?
I'd like to be able to, say for instance, only provide 100Mb for FB/YouTube on a given 1Gb interface. Is that possible?
09-06-2016 06:43 AM
yes, yes it is! 😉
check out a little article i wrote on the matter 🙂 Getting Started: Quality of Service
in short: in the security policy options you can do DSCP marking etc, for external BW shaping appliances, but the firewall comes with it's own QoS policies that can limit or guarantee bandwidth for a subnet/application/user/.. (it's not as fancy as true traffic shaping, but it does a pretty good job)
09-06-2016 06:53 AM
@reaper thanks! I see this article was written in 2015. Has PAN-OS always been able to rate-limit applications or how long has it been possible for?
09-06-2016 07:11 AM
@Brandon_Wertz it's been there for as long as i can remember.... 😉 (so PAN-OS 3.1.4 and after)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!