QOS on the palo alto device is applied only on the egress interfaces, however you can apply Qos profiles for traffic ingressing from a specific source subnet. So for example if you want to rate limit upload traffic from your guest/office network: Guest/office---ingress--->PAN---egress--->Untrust Here QOS is enabled on the Untrust (egress)interface, but you can configure multiple QOS profiles for traffic egressing Untrust, based on the source interface/subnet as well. I'm guessing this may answer your original question partially unless you want to rate limit traffic ingressing Untrust interface like downloads, hope it helps. Aditi
... View more