Per Security Policy-Based Express Forwarding
Focus
Focus
Network Security

Per Security Policy-Based Express Forwarding

Table of Contents

Per Security Policy-Based Express Forwarding

Per Security Policy-Based Express Forwarding provides ultra-low latency traffic forwarding for time-sensitive applications such as high-frequency trading networks.
Per Security Policy-Based Express Forwarding provides ultra-low latency traffic forwarding for time-sensitive applications. This feature addresses the need for forwarding delays below 5 microseconds.
Traditional hardware offload capabilities introduce 10-11 microsecond delays, which is insufficient for environments demanding extreme low latency, such as high-frequency trading networks. This feature significantly reduces that delay, meeting stringent performance requirements.
Configuration of this feature is not supported via Strata™ Cloud Manager (SCM) in this release; you must manage it directly on your NGFW or through Panorama. A direct consequence of bypassing the TM module is that features dependent on TM functionality, such as Quality of Service (QoS) and Multicast, are not supported for traffic using express forwarding.

Supported Hardware Platforms and Deployment Scenarios

This feature is available only on certain NGFW models equipped with the FE400 Flow Engine ASIC:
  • PA-75xx Series (for example, Blackbird)
  • PA-55xx Series (PA-5540, PA-5550, PA-5560, PA-5570, and PA-5580; for example, Spring Ranch, Ocean Ranch)
The architecture supports the deployment of this feature in both clustering and non-clustering scenarios, ensuring high availability and scalability.

Prerequisites

  • Palo Alto Networks NGFW platforms with FE400 Flow Engine ASIC: PA-75xx (Blackbird) series and PA-55xx (Spring Ranch, Ocean Ranch) series, including PA-5540, PA-5550, PA-5560, PA-5570, and PA-5580.
  • Direct management of your NGFW device using Panorama or the CLI. Strata Cloud Manager (SCM) does not support this feature in this release.

Best Practices and Recommendations

Use these best practices to effectively implement Per Security Policy-Based Express Forwarding in your environment:
  • Understand Feature Limitations—When you enable express forwarding, it bypasses the Traffic Manager (TM) module. This means features like Quality of Service (QoS) and Multicast are not supported for traffic matching these policies.
  • Select Policies Carefully—Apply express forwarding only to security policies that require ultra-low latency. Carefully consider the trade-offs. Avoid enabling this feature where QoS or Multicast functionality is essential for your traffic.
  • Prioritize Time-Sensitive Applications—Reserve express forwarding for critical applications demanding minimal latency, such as high-frequency trading networks. This ensures optimal performance where it matters most for your time-sensitive traffic.
  • Avoid Unnecessary Bypass—Do not enable express forwarding on policies if the bypassed TM module features are required. Misconfiguration can degrade network functionality for other traffic.