Objects > SD-WAN Link Management > Path Quality Profile
Table of Contents
Expand all | Collapse all
-
- Objects > Addresses
- Objects > Address Groups
- Objects > Regions
- Objects > Dynamic User Groups
- Objects > Application Groups
- Objects > Application Filters
- Objects > Services
- Objects > Service Groups
- Objects > External Dynamic Lists
- Objects > Custom Objects > Spyware/Vulnerability
- Objects > Custom Objects > URL Category
- Objects > Security Profiles > Antivirus
- Objects > Security Profiles > Anti-Spyware Profile
- Objects > Security Profiles > Vulnerability Protection
- Objects > Security Profiles > File Blocking
- Objects > Security Profiles > WildFire Analysis
- Objects > Security Profiles > Data Filtering
- Objects > Security Profiles > DoS Protection
- Objects > Security Profiles > GTP Protection
- Objects > Security Profiles > SCTP Protection
- Objects > Security Profile Groups
- Objects > Log Forwarding
- Objects > Authentication
- Objects > Decryption > Forwarding Profile
- Objects > Schedules
-
-
- Firewall Interfaces Overview
- Common Building Blocks for Firewall Interfaces
- Common Building Blocks for PA-7000 Series Firewall Interfaces
- Tap Interface
- HA Interface
- Virtual Wire Interface
- Virtual Wire Subinterface
- PA-7000 Series Layer 2 Interface
- PA-7000 Series Layer 2 Subinterface
- PA-7000 Series Layer 3 Interface
- Layer 3 Interface
- Layer 3 Subinterface
- Log Card Interface
- Log Card Subinterface
- Decrypt Mirror Interface
- Aggregate Ethernet (AE) Interface Group
- Aggregate Ethernet (AE) Interface
- Network > Interfaces > VLAN
- Network > Interfaces > Loopback
- Network > Interfaces > Tunnel
- Network > Interfaces > SD-WAN
- Network > VLANs
- Network > Virtual Wires
-
- Network > Network Profiles > GlobalProtect IPSec Crypto
- Network > Network Profiles > IPSec Crypto
- Network > Network Profiles > IKE Crypto
- Network > Network Profiles > Monitor
- Network > Network Profiles > Interface Mgmt
- Network > Network Profiles > QoS
- Network > Network Profiles > LLDP Profile
- Network > Network Profiles > SD-WAN Interface Profile
-
-
- Device > Setup
- Device > Setup > Management
- Device > Setup > Interfaces
- Device > Setup > Telemetry
- Device > Setup > Content-ID
- Device > Setup > WildFire
- Device > Log Forwarding Card
- Device > Config Audit
- Device > Administrators
- Device > Admin Roles
- Device > Access Domain
- Device > Authentication Sequence
-
- Security Policy Match
- QoS Policy Match
- Authentication Policy Match
- Decryption/SSL Policy Match
- NAT Policy Match
- Policy Based Forwarding Policy Match
- DoS Policy Match
- Routing
- Test Wildfire
- Threat Vault
- Ping
- Trace Route
- Log Collector Connectivity
- External Dynamic List
- Update Server
- Test Cloud Logging Service Status
- Test Cloud GP Service Status
- Device > Virtual Systems
- Device > Shared Gateways
- Device > Certificate Management
- Device > Certificate Management > Certificate Profile
- Device > Certificate Management > OCSP Responder
- Device > Certificate Management > SSL/TLS Service Profile
- Device > Certificate Management > SCEP
- Device > Certificate Management > SSL Decryption Exclusion
- Device > Response Pages
- Device > Server Profiles
- Device > Server Profiles > SNMP Trap
- Device > Server Profiles > Syslog
- Device > Server Profiles > Email
- Device > Server Profiles > HTTP
- Device > Server Profiles > NetFlow
- Device > Server Profiles > RADIUS
- Device > Server Profiles > TACACS+
- Device > Server Profiles > LDAP
- Device > Server Profiles > Kerberos
- Device > Server Profiles > SAML Identity Provider
- Device > Server Profiles > DNS
- Device > Server Profiles > Multi Factor Authentication
- Device > Local User Database > Users
- Device > Local User Database > User Groups
- Device > Scheduled Log Export
- Device > Software
- Device > Dynamic Updates
- Device > Licenses
- Device > Support
-
- Network > GlobalProtect > MDM
- Network > GlobalProtect > Device Block List
- Network > GlobalProtect > Clientless Apps
- Network > GlobalProtect > Clientless App Groups
- Objects > GlobalProtect > HIP Profiles
-
- Use the Panorama Web Interface
- Context Switch
- Panorama Commit Operations
- Defining Policies on Panorama
- Log Storage Partitions for a Panorama Virtual Appliance in Legacy Mode
- Panorama > Setup > Interfaces
- Panorama > High Availability
- Panorama > Administrators
- Panorama > Admin Roles
- Panorama > Access Domains
- Panorama > Device Groups
- Panorama > Plugins
- Panorama > Log Ingestion Profile
- Panorama > Log Settings
- Panorama > Scheduled Config Export
End-of-Life (EoL)
Objects > SD-WAN Link Management > Path Quality Profile
Create an SD-WAN path quality profile.
SD-WAN allows you to create a path quality
profile for each set of applications, application filters, application
groups, services, service objects, and service group objects that
has unique network quality requirements and then reference that
profile in an SD-WAN policy rule. In the profile, you set maximum
thresholds for three parameters: latency, jitter, and packet loss.
When an SD-WAN link exceeds any one of the thresholds, the firewall
selects a new best path for packets matching the SD-WAN rule where
you applied this profile.
The sensitivity setting for each path quality parameter allows
you to indicate to the firewall which parameter is more important
(preferred) for the applications to which the profile applies. The
firewall places more importance on a parameter with a high setting
than a parameter with a medium or low setting. For example, some
applications are more sensitive to packet loss than to jitter or
latency, so you could set packet loss to high sensitivity for the
profile associated with those applications, which causes the firewall
to examine packet loss first.
If you leave the sensitivity settings for latency, jitter, and
packet loss at the default setting (medium) or if you set all three
parameters to the same setting, the order of preference for the
profile is packet loss, then latency, and then jitter.
By default, the firewall measures latency and jitter every 200ms
and takes an average of the last three measurements to measure path
quality in a sliding window. You can modify this behavior by selecting
aggressive or relaxed path monitoring when you configure an SD-WAN
Interface Profile.
Path Quality Profile Settings | |
---|---|
Name | Enter a Name for
the path quality profile using any combination and maximum of 31
alphanumeric characters, underscores, hyphens, spaces, and periods. |
Latency (ms) | Threshold—Enter the
number of milliseconds allowed for a packet to leave the firewall,
arrive at the opposite end of the SD-WAN tunnel, and a response
packet for that packet to return to the firewall before the threshold
is exceeded (range is 10 to 2,000; default is 100). |
Sensitivity—Select high, medium (default),
or low. | |
Jitter (ms) | Threshold—Enter the
average variation, in milliseconds, that SD-WAN packet latencies
can vary (range is 10 to 1,000; default is 100). The default jitter
threshold of 100ms means that latency measurements can vary by an
average of 100ms before the jitter threshold is exceeded. |
Sensitivity—Select high, medium (default),
or low. | |
Packet Loss (%) | Threshold—Enter the
percentage of packets lost on the link before the threshold is exceeded
(range is 1 to 100.0; default is 1). |
Sensitivity—Select high, medium (default),
or low. |