Configure QoS for a virtual system to prioritize and shape traffic independently
within that isolated firewall environment.
| Where Can I Use This? | What Do I Need? |
|
|
- No separate license required for QoS when using NGFWs
|
QoS can be configured for a single or several
virtual systems configured on a Palo Alto Networks firewall. Because
a virtual system is an independent firewall, QoS must be configured
independently for a single virtual system.
Configuring QoS
for a virtual system is similar to configuring QoS on a physical
firewall, with the exception that configuring QoS for a virtual
system requires specifying the source and destination of traffic.
Because a virtual system exists without set physical boundaries
and because traffic in a virtual environment spans more than one
virtual system, specifying source and destination zones and interfaces
for traffic is necessary to control and shape traffic for a single
virtual system.
The example below shows two virtual systems configured on firewall. VSYS 1 (purple) and VSYS 2
(red) each have QoS configured to prioritize or limit two distinct traffic flows,
indicated by their corresponding purple (VSYS 1) and red (VSYS 2) lines. The QoS
nodes indicate the points at which traffic is matched to a QoS policy and assigned a
QoS class of service, and then later indicate the point at which traffic is shaped
as it egresses the firewall.
Refer to
virtual systems for information on virtual
systems and how to configure them.