Saturday, July 21, 2018

Traffic shaping requirements for Comcast Fiber/DIS using Palo Alto firewall?

tl;dr - Comcast's welcome kit says I should set our traffic shaping to their CIR. We don't have any traffic shaping equipment. What to do?

I set up a friend's small business of ~35 users, using a Palo Alto PA-820 for all network functions in a ROAS configuration. I just switched them from Comcast cable internet to Comcast Dedicated Internet Service (fiber) with a 200mbit CIR.

I'm going through Comcast's welcome kit/requirements, and they state that we should shape our traffic to their CIR or severely degraded TCP performance will result. But we're not doing any traffic shaping and I'm not even sure this little Palo Alto firewall is capable of that. I've used Riverbed and Silverpeak traffic shapers in the past when I was squeezing data over constantly congested satellite connections, but I would have though hardware like that is well out of scope for a small organization like this.

Is this something I actually need to pay attention to, and how severe could the problems be if I don't?

(My background; junior engineer with a CCNA and no real WAN experience yet, feeling my way through these things slowly)



No comments:

Post a Comment