At the minimum, enabling a QoS interfaces requires you
to select a default QoS profile rule that defines bandwidth and
priority settings for clear text traffic egressing the interface.
However, when setting up or modifying a QoS interface, you can apply
granular QoS settings to outgoing clear text traffic and tunneled
traffic. QoS preferential treatment and bandwidth limiting can be
enforced for tunneled traffic, for individual tunnel interfaces,
and/or for clear text traffic originating from different source
interfaces and source subnets. On Palo Alto Networks firewalls,
tunneled
traffic refers to tunnel interface traffic, specifically
IPSec traffic in tunnel mode.