Prisma SD-WAN Performance Policy
Table of Contents
Expand All
|
Collapse All
Prisma SD-WAN Docs
-
-
-
-
- AWS Transit Gateway
- Azure vWAN
- Azure vWAN with vION
- ChatBot for MS Teams
- ChatBot for Slack
- CloudBlades Integration with Prisma Access
- GCP NCC
- Service Now
- Zoom QSS
- Zscaler Internet Access
-
-
- ION 5.2
- ION 5.3
- ION 5.4
- ION 5.5
- ION 5.6
- ION 6.0
- ION 6.1
- ION 6.2
- ION 6.3
- ION 6.4
- New Features Guide
- On-Premises Controller
- Prisma Access CloudBlade Cloud Managed
- Prisma Access CloudBlade Panorama Managed
- Prisma SD-WAN CloudBlades
Prisma SD-WAN Performance Policy
Performance policy utilizes link quality metrics such as Latency, Loss, and Jitter
and application performance metrics such as Application RTT and Init failure % as SLA
metrics.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
Measuring application performance and delivering App SLAs is a core component of Prisma
SD-WAN. Performance Policy builds upon the existing App SLA configuration to deliver a
policy framework for the measurement, enforcement, and alerting for application SLAs.
Performance Policy utilizes link quality metrics such as Latency, Loss, and
Jitter as well as application performance metrics such as Application RTT and Init
failure % as SLA metrics. If the SLA metrics are violated, the system takes action to
ensure that the SLA is enforced including moving flows to a compliant path (if
available) and invoking line conditioning such as Forward Error Correction (FEC)
to ensure the SLA is met. Optionally, an incident can be generated for critical
applications when an SLA is violated. Although default policies work well for most
environments, policies can be granularly tuned per application, path type, DC group, and
circuit category to align to the performance needs of the business.
The system automatically assigns a default policy stack to a site as part of the default
policy configuration. You can't remove the default set from the default stack, default
rules from the set, or the default threshold profile from rules. Your ability to make
changes is limited to editing the actions and thresholds for default policy rules. After
you configure a rule, it takes precedence over the default rules based on the order of
rules. The default values for Media Apps are set at latency = 150ms, packet loss = 2%,
and jitter = 40ms. For all other Apps, default values are latency = 500ms, packet loss =
5%, and jitter = 100ms.
The following are the Performance Policy functions and supported device software
versions:
Function | Software Version |
---|---|
Action: Move Flows, Visibility, Incident | 6.3.1 and later |
Action: Forward Error Correction (FEC) | 6.3.1 and later / 6.3.2 recommended |
Match Criteria: Application, Transfer Type, Circuit Category, Path Type, Service & DC Group | 6.3.1 and later |
SLA: Application Metrics, Link Quality Metrics | 6.3.1 and later |
Action: Packet Duplication | 6.4.1 and later |
SLA: Service Health Probes | 6.4.1 and later |
SLA: Incident action for System Metrics; CPU, Memory, Disk, Concurrent Flows, Circuit Utilization | 6.4.1 and later |
SLA: Application UDP-TRT for DNS, Link Quality MOS | 6.4.1 and later |
To prevent the need for policy migrations,
configuration of a function that is not supported by a specific device version where
the policy rule is bound is permitted. However, the device will ignore the
configuration for the entire rule if any function is not supported
Performance Policy Function Matrix
Refer to the following function matrix to understand the performance policy
feature:
Function | Action | |||||
---|---|---|---|---|---|---|
Move Flows | Visibility | Incident | FEC | Packet Duplication | ||
Action | Move Flows | -- | Combination Supported | Combination Supported | Required | Required |
Visibility | -- | -- | Combination Supported | Combination Supported | Combination Supported | |
Incident | -- | -- | -- | Combination Supported | Combination Supported | |
FEC | -- | -- | -- | -- | Mutually Exclusive | |
Packet Duplication | -- | -- | -- | -- | -- | |
Match Criteria | Application ID, Transfer Type | -- | -- | -- | -- | -- |
Circuit Category, Path Type | -- | -- | -- | -- | -- | |
Service & DC Groups | -- | -- | -- | -- | -- | |
SLA | Application Metrics | -- | -- | -- | -- | -- |
Link Quality Metrics | -- | -- | -- | -- | -- | |
Service Health Probes | -- | -- | -- | -- | -- | |
System Metrics | -- | -- | -- | -- | -- |
Function | Match Criteria | |||
---|---|---|---|---|
App ID, Transfer Type | Circuit Category, Path Type | Service & DC Group | ||
Action | Move Flows | Supported | Supported | Supported |
Visibility | Not Supported | Supported | Supported | |
Incident | Supported | Supported | Supported | |
FEC | Supported | Supported | Supported | |
Packet Duplication | Supported | Required | Supported | |
Match Criteria | Application ID, Transfer Type | -- | Combination Supported | Combination Supported |
Circuit Category, Path Type | -- | -- | Combination Supported | |
Service & DC Groups | -- | -- | -- | |
SLA | Application Metrics | -- | -- | -- |
Link Quality Metrics | -- | -- | -- | |
Service Health Probes | -- | -- | -- | |
System Metrics | -- | -- | -- |
Function | SLA | ||||
---|---|---|---|---|---|
Application Metrics | Link Quality Metrics | Service Health Probes | System Metrics | ||
Action | Move Flows | Support for new flows only | Support for new and existing Fabric VPN flows within the same NAT boundary | ICMP - Latency, Loss, Jitter DNS - Transaction Time, Transaction Failure HTTP/S - Transaction Time, Init Failure | N/A |
Visibility | Not Supported | Supported | Not Supported | Not Supported | |
Incident | Supported | Supported | Supported | Supported | |
FEC | Not Supported | Packet Loss Required | Not Supported | N/A | |
Packet Duplication | Not Supported | Packet Loss Required | Not Supported | N/A | |
Match Criteria | Application ID, Transfer Type | Required | Supported | Supported | N/A |
Circuit Category, Path Type | Supported | Supported | Supported | Supported | |
Service & DC Groups | Supported | Supported | Supported | N/A | |
SLA | Application Metrics | -- | N/A | N/A | N/A |
Link Quality Metrics | -- | -- | N/A | N/A | |
Service Health Probes | -- | -- | -- | N/A | |
System Metrics | -- | -- | -- | -- |