Per Security Policy-Based Express Forwarding
Per Security Policy-Based Express Forwarding provides ultra-low latency traffic
forwarding for time-sensitive applications such as high-frequency trading
networks.
Per Security Policy-Based Express Forwarding provides ultra-low latency traffic
forwarding for time-sensitive applications. This feature addresses the need for
forwarding delays below 5 microseconds.
Traditional hardware offload capabilities introduce 10-11 microsecond delays, which is
insufficient for environments demanding extreme low latency, such as high-frequency
trading networks. This feature significantly reduces that delay, meeting stringent
performance requirements.
Configuration of this feature is not supported via Strata™ Cloud Manager (SCM) in this
release; you must manage it directly on your NGFW or through Panorama. A direct
consequence of bypassing the TM module is that features dependent on TM functionality,
such as Quality of Service (QoS) and Multicast, are not supported for traffic using
express forwarding.
Supported Hardware Platforms and Deployment Scenarios
This feature is available only on certain NGFW models equipped with the FE400 Flow
Engine ASIC:
PA-75xx Series (for example, Blackbird)
PA-55xx Series (PA-5540, PA-5550, PA-5560, PA-5570, and PA-5580; for
example, Spring Ranch, Ocean Ranch)
The architecture supports the deployment of this feature in both clustering and
non-clustering scenarios, ensuring high availability and scalability.
Prerequisites
Palo Alto Networks NGFW platforms with FE400 Flow Engine ASIC: PA-75xx
(Blackbird) series and PA-55xx (Spring Ranch, Ocean Ranch) series,
including PA-5540, PA-5550, PA-5560, PA-5570, and PA-5580.
Direct management of your NGFW device using Panorama or the CLI. Strata
Cloud Manager (SCM) does not support this feature in this release.
Best Practices and Recommendations
Use these best practices to effectively implement Per Security Policy-Based Express
Forwarding in your environment:
Understand Feature Limitations—When you enable express forwarding, it
bypasses the Traffic Manager (TM) module. This means features like Quality
of Service (QoS) and Multicast are not supported for traffic matching these
policies.
Select Policies Carefully—Apply express forwarding only to security
policies that require ultra-low latency. Carefully consider the trade-offs.
Avoid enabling this feature where QoS or Multicast functionality is
essential for your traffic.
Prioritize Time-Sensitive Applications—Reserve express forwarding for
critical applications demanding minimal latency, such as high-frequency
trading networks. This ensures optimal performance where it matters most for
your time-sensitive traffic.
Avoid Unnecessary Bypass—Do not enable express forwarding on policies
if the bypassed TM module features are required. Misconfiguration can
degrade network functionality for other traffic.