Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Prisma Access Internet Break-out in prisma / aggregate bandwith.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Prisma Access Internet Break-out in prisma / aggregate bandwith.

L3 Networker

Hi,

 

My first question regarding the aggregate bandwith feature. 

For example on computer location i will assing 100 Mbit of traffic. 

At the Guaranteed bandwith ratio I will put in 100% and reserved for Guaranteed bandwidth i also put in 100.

So if i have 5 sites they will all receive a guaranteed 20 Mbps.  

Suppose all sites together are only consuming 20 Mbps will they still be able to peak to 100Mbps and use what others have not consumed?

zGomez_0-1684333784284.png

My QOS profiles are still on Mbps due to migration and should be migrated to percentage.

 

When I want those 5 sites to break out to the internet on Prisma Access computer location how is this reflected in the QOS.

Or does the QOS not apply to internet traffic only between remote sites?

What is the internet break out speed on a computer location?

 

When I run a speedtest to the internet with above settings I can reach around 170 Mbps down and 20 Mbps up this doesn't seem to match the conigured QOS.  (when i turn to overal bandwith to 50 Mbps for example i can still reach the same speed to internet).

Also when running iperf between a server in a remote location and a server in our service connection i doesn't seem to reflect the settings.

 

Any help on explaining this would be appreciated.


 

 

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Any guarantees can be surpassed whenever 'excess' is available from other sites not using their capacity

The RN-SPN "internet speed" is physically much higher than the capacity you assign to the node, and will generally be able to surpass your allocation by 10% according to the documentation but in reality i've also seen higher results. I'd not 'trust' on the bonus to go unnoticed if you start bursting all the time, a sales person might come knocking to sell you more capacity 😉

 

QoS is applied on egress ('from' the RN), but you need to create a QoS profile to define classes and then define what those classes include via policy

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/configure-qualit...

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Any guarantees can be surpassed whenever 'excess' is available from other sites not using their capacity

The RN-SPN "internet speed" is physically much higher than the capacity you assign to the node, and will generally be able to surpass your allocation by 10% according to the documentation but in reality i've also seen higher results. I'd not 'trust' on the bonus to go unnoticed if you start bursting all the time, a sales person might come knocking to sell you more capacity 😉

 

QoS is applied on egress ('from' the RN), but you need to create a QoS profile to define classes and then define what those classes include via policy

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/configure-qualit...

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi Tom,

 

I forgot to reply to your mail , this is also the feedback I received from our Palo representative.  

For the compute locations indeed the RN-SPN node can handle op to 500 Mbps and the speed you define in panorama is not a hard limit just something for sales and to determine how many RN-SPN nodes you need.

I will mark your reply as solution.

  • 1 accepted solution
  • 2379 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!