- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-11-2020 06:32 PM
Hi,
We have 400/400 up and down mbps connection, your ISP does not shape the traffic and have asked us to shape it.
Applying qos on the outside interface both ways, how would we achieve it?
if I only set the egress then i am only setting the speed for outbound traffic not inbound.
Also if I do QOS rules is this going to also QOS the Palo Alto VPN ? as the rules will only be applied to traffic crossing the firewall it wont see the VPN tunnels made by the clients being added to the bandwidth load on this interface as its not crossing the firewall to hit the QOS rules ??
pan - os 9.0.4
03-11-2020 10:15 PM
Hi Jatin,
QoS is always applied on the egress interface.
1. To limit upload, a QoS profile needs to be enabled on the untrust interface
2. To limit download, a QoS profile needs to be enabled on the trust interface.
3. In your case, to limit both download & upload traffic, QoS will have to be applied on both interfaces.
4. QoS Can also be applied to tunneled interfaces, please refer to https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEfCAK
Hope this helps,
Regards,
Ram
03-11-2020 10:15 PM
Hi Jatin,
QoS is always applied on the egress interface.
1. To limit upload, a QoS profile needs to be enabled on the untrust interface
2. To limit download, a QoS profile needs to be enabled on the trust interface.
3. In your case, to limit both download & upload traffic, QoS will have to be applied on both interfaces.
4. QoS Can also be applied to tunneled interfaces, please refer to https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEfCAK
Hope this helps,
Regards,
Ram
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!