Ingress-slot (default
on PA-7000 Series firewalls) | (PA-7000 Series firewalls
only) New sessions are assigned to a DP on the same NPC on which
the first packet of the session arrived. The selection of the DP
is based on the session-load algorithm but, in this case, sessions
are limited to the DPs on the ingress NPC. Depending on the
traffic and network topology, this policy generally decreases the
odds that traffic will need to traverse the switch fabric. Use
this policy to reduce latency if both ingress and egress are on
the same NPC. If the firewall has a mix of NPCs (PA-7000 20G and
PA-7000 20GXM for example), this policy can isolate the increased
capacity to the corresponding NPCs and help to isolate the impact
of NPC failures. |