traffic shaping/qos on palo alto

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

traffic shaping/qos on palo alto

L3 Networker

Hi,

We have 400/400 up and down mbps connection, your ISP does not shape the traffic and have asked us to shape it.

Applying qos on the outside interface both ways, how would we achieve it?

 

if I only set the egress then i am only setting the speed for outbound traffic not inbound.

 

Also if I do QOS rules is this going to also QOS the Palo Alto VPN ? as the rules will only be applied to traffic crossing the firewall it wont see the VPN tunnels made by the clients being added to the bandwidth load on this interface as its not crossing the firewall to hit the QOS rules ??

 

pan - os 9.0.4

1 accepted solution

Accepted Solutions

Hi Jatin,

 

QoS is always applied on the egress interface.

 

1. To limit upload, a QoS profile needs to be enabled on the untrust interface

2. To limit download, a QoS profile needs to be enabled on the trust interface.

3. In your case, to limit both download & upload traffic, QoS will have to be applied on both interfaces.

4. QoS Can also be applied to tunneled interfaces, please refer to https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEfCAK

 

Hope this helps,

 

Regards,

Ram

View solution in original post

1 REPLY 1

Hi Jatin,

 

QoS is always applied on the egress interface.

 

1. To limit upload, a QoS profile needs to be enabled on the untrust interface

2. To limit download, a QoS profile needs to be enabled on the trust interface.

3. In your case, to limit both download & upload traffic, QoS will have to be applied on both interfaces.

4. QoS Can also be applied to tunneled interfaces, please refer to https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEfCAK

 

Hope this helps,

 

Regards,

Ram

  • 1 accepted solution
  • 15480 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!