Summary
In this chapter, you learned how to shape sessions to prevent your internet uplink from getting flooded while guaranteeing business-critical applications always have bandwidth available. You can now implement decryption so that TLS sessions can be inspected for App-ID and threats, and you can leverage PBF and ECMP to control how sessions flow, regardless of routing. You are able to implement QoS rules and profiles to efficiently limit bandwidth for chatty applications and ensure your important applications have a guaranteed bandwidth so that even at the busiest times, they will never encounter any bandwidth issues.
If you’re studying for the PCNSE, take note that QoS is achieved by setting rules that assign a class to sessions that match the rule and that profiles are added to interfaces to define which guarantees and maximum throughput are assigned per class; class 4 is the default class. Remember that SSL decryption works best if a decryption profile is assigned...