How To Configure and Test QoS
How To Configure and Test QoS
0
This document walks through the steps needed for a simple test of the QoS feature. In particular,
these steps will rate-limit applications such as youtube, hulu, and web browsing.
Preparation steps:
Place a Palo Alto Networks firewall inline in your network. The firewall must be running
PANOS 3.0.0 or higher. The firewall interfaces can be in virtual wire mode, or layer 3
mode.
The external interface needs to have network access to the Internet.
You will be performing the throughput tests on a PC located in your trust zone.
Configure routing and policies on the firewall to allow traffic to flow from the trust zone
to untrust zone.
3. Go to the Network tab -> Network Profiles -> QoS Profiles screen. Create a new QoS
profile. Define a QoS profile that will assign a maximum egress limit for class 5 traffic.
Set the maximum rate to be 50% or less than download rate you determined step 1. (This
example will use 5 Mbps.) Note that you must click in the empty space in the appropriate
column, and then type a value.
PANOS 3.0.0
4. Go to Network tab -> QoS screen. Click New to assign the QoS profile to a specific
interface. Note that rate limiting is performed on the EGRESS interface. In this first test,
we want to rate limit files being downloaded via web browsing, therefore assign the
profile to the INTERNAL interface. Next to Clear Text Default Profile, select the
profile you created in the previous step.
PANOS 3.0.0
8. Go to Network tab -> QoS screen. Click New to add another interface that will be rate
limited. Select the EXTERNAL interface, and select the profile you just created.
PANOS 3.0.0
PANOS 3.0.0
13. Go to the Network tab -> Network Profiles -> QoS Profiles screen. Create a new
profile that matches the following:
This profile will still rate-limit class 5 traffic to 5 Mbps, but it will also rate-limit class 8
traffic to a very small amount of bandwidth: .1 Mbps.
14. Go to Network tab -> QoS screen. Since you will be downloading videos, you should
edit your INTERNAL interface, and select the profile you just created.
15. Commit the changes.
16. Go to the video sites you tested previously, and attempt to watch videos. You should find
that the videos will stop and start, or not even be able to be viewed, due to the decrease in
bandwidth.
17. Also go to the throughput testing web site, and test downloading throughput. That should
be rate-limited as well, as defined in the profile.
At this point you can continue testing by adding additional QoS policies, and creating
new QoS profiles. For further information, refer to PANOS 3.0 Administrators Guide,
found on http://support.paloaltonetworks.com
PANOS 3.0.0