Objects > SD-WAN Link Management > Path Quality Profile
Table of Contents
Expand all | Collapse all
-
- Objects > Addresses
- Objects > Address Groups
- Objects > Regions
- Objects > Dynamic User Groups
- Objects > Application Groups
- Objects > Application Filters
- Objects > Services
- Objects > Service Groups
- Objects > Devices
- Objects > External Dynamic Lists
- Objects > Custom Objects > Spyware/Vulnerability
- Objects > Custom Objects > URL Category
- Objects > Security Profiles > Antivirus
- Objects > Security Profiles > Anti-Spyware Profile
- Objects > Security Profiles > Vulnerability Protection
- Objects > Security Profiles > File Blocking
- Objects > Security Profiles > WildFire Analysis
- Objects > Security Profiles > Data Filtering
- Objects > Security Profiles > DoS Protection
- Objects > Security Profiles > Mobile Network Protection
- Objects > Security Profiles > SCTP Protection
- Objects > Security Profile Groups
- Objects > Log Forwarding
- Objects > Authentication
- Objects > Decryption > Forwarding Profile
- Objects > Schedules
-
-
- Firewall Interfaces Overview
- Common Building Blocks for Firewall Interfaces
- Common Building Blocks for PA-7000 Series Firewall Interfaces
- Tap Interface
- HA Interface
- Virtual Wire Interface
- Virtual Wire Subinterface
- PA-7000 Series Layer 2 Interface
- PA-7000 Series Layer 2 Subinterface
- PA-7000 Series Layer 3 Interface
- Layer 3 Interface
- Layer 3 Subinterface
- Log Card Interface
- Log Card Subinterface
- Decrypt Mirror Interface
- Aggregate Ethernet (AE) Interface Group
- Aggregate Ethernet (AE) Interface
- Network > Interfaces > VLAN
- Network > Interfaces > Loopback
- Network > Interfaces > Tunnel
- Network > Interfaces > SD-WAN
- Network > VLANs
- Network > Virtual Wires
-
- Network > Network Profiles > GlobalProtect IPSec Crypto
- Network > Network Profiles > IPSec Crypto
- Network > Network Profiles > IKE Crypto
- Network > Network Profiles > Monitor
- Network > Network Profiles > Interface Mgmt
- Network > Network Profiles > QoS
- Network > Network Profiles > LLDP Profile
- Network > Network Profiles > SD-WAN Interface Profile
-
-
- Device > Setup
- Device > Setup > Management
- Device > Setup > Interfaces
- Device > Setup > Telemetry
- Device > Setup > Content-ID
- Device > Setup > WildFire
- Device > Setup > DLP
- Device > Log Forwarding Card
- Device > Config Audit
- Device > Administrators
- Device > Admin Roles
- Device > Access Domain
- Device > Authentication Sequence
- Device > Device Quarantine
-
- Security Policy Match
- QoS Policy Match
- Authentication Policy Match
- Decryption/SSL Policy Match
- NAT Policy Match
- Policy Based Forwarding Policy Match
- DoS Policy Match
- Routing
- Test Wildfire
- Threat Vault
- Ping
- Trace Route
- Log Collector Connectivity
- External Dynamic List
- Update Server
- Test Cloud Logging Service Status
- Test Cloud GP Service Status
- Device > Virtual Systems
- Device > Shared Gateways
- Device > Certificate Management
- Device > Certificate Management > Certificate Profile
- Device > Certificate Management > OCSP Responder
- Device > Certificate Management > SSL/TLS Service Profile
- Device > Certificate Management > SCEP
- Device > Certificate Management > SSL Decryption Exclusion
- Device > Certificate Management > SSH Service Profile
- Device > Response Pages
- Device > Server Profiles
- Device > Server Profiles > SNMP Trap
- Device > Server Profiles > Syslog
- Device > Server Profiles > Email
- Device > Server Profiles > HTTP
- Device > Server Profiles > NetFlow
- Device > Server Profiles > RADIUS
- Device > Server Profiles > TACACS+
- Device > Server Profiles > LDAP
- Device > Server Profiles > Kerberos
- Device > Server Profiles > SAML Identity Provider
- Device > Server Profiles > DNS
- Device > Server Profiles > Multi Factor Authentication
- Device > Local User Database > Users
- Device > Local User Database > User Groups
- Device > Scheduled Log Export
- Device > Software
- Device > Dynamic Updates
- Device > Licenses
- Device > Support
- Device > Policy Recommendation
-
- Network > GlobalProtect > MDM
- Network > GlobalProtect > Clientless Apps
- Network > GlobalProtect > Clientless App Groups
- Objects > GlobalProtect > HIP Profiles
-
- Use the Panorama Web Interface
- Context Switch
- Panorama Commit Operations
- Defining Policies on Panorama
- Log Storage Partitions for a Panorama Virtual Appliance in Legacy Mode
- Panorama > Setup > Interfaces
- Panorama > High Availability
- Panorama > Administrators
- Panorama > Admin Roles
- Panorama > Access Domains
- Panorama > Device Groups
- Panorama > Plugins
- Panorama > Log Ingestion Profile
- Panorama > Log Settings
- Panorama > Server Profiles > SCP
- Panorama > Scheduled Config Export
End-of-Life (EoL)
Objects > SD-WAN Link Management > Path Quality Profile
SD-WAN allows you to create a path quality
profile for each set of applications, application filters, application
groups, services, service objects, and service group objects that
has unique network quality requirements and reference the profile
in an SD-WAN policy rule. In the profile you set maximum thresholds
for three parameters: latency, jitter, and packet loss. When an
SD-WAN link exceeds any one of the thresholds, the firewall selects
a new best path for packets matching the SD-WAN rule where you apply
this profile.
The sensitivity setting for each path quality parameter allows
you to indicate to the firewall which parameter is more important
(preferred) for the application(s) to which the profile applies.
The firewall places more importance on a parameter with a high setting
than a parameter with a medium or low setting. For example, some
applications are more sensitive to packet loss than to jitter or
latency, so you could set packet loss to high sensitivity, which causes
the firewall to examine packet loss first.
If you let the sensitivity settings for latency, jitter, and
packet loss remain at the default setting (medium) or if you set
all three parameters to the same setting, the order of preference
for the profile is packet loss, latency, jitter.
By default, the firewall measures latency and jitter every 200ms
and takes an average of the last three measurements to measure path
quality in a sliding window. You can modify this behavior by selecting
aggressive or relaxed path monitoring when you configure an SD-WAN
Interface Profile.
Path Quality Profile Settings | |
---|---|
Name | Enter a name for the path quality profile
using a maximum of 31 alphanumeric characters, underscore, hyphen,
space, and period. |
Latency (ms) | Threshold—Enter the
number of milliseconds allowed for a packet to leave the firewall,
arrive at the opposite end of the SD-WAN tunnel, and a response
packet to return to the firewall before the threshold is exceeded
(range is 10 to 2,000; default is 100). |
Sensitivity—Select high, medium,
or low (default is medium). | |
Jitter (ms) | Threshold—Enter the
number of milliseconds (range is 10 to 1,000; default is 100). |
Sensitivity—Select high, medium,
or low (default is medium). | |
Packet Loss (%) | Threshold—Enter the
percentage of packets lost on the link before the threshold is exceeded
(range is 1 to 100.0; default is 1). |
Sensitivity—The Sensitivity
setting for Packet Loss has no effect, so leave the default setting (medium). |