Guidelines for configuring inline sets and passive interfaces

Firewall mode restrictions

Use ERSPAN interfaces only when the device is in routed firewall mode.

Clustering restrictions

Consider clustering limitations when configuring inline sets and passive interfaces.

  • Link State Propagation for an inline set is not supported with clustering.

Multi-Instance mode restrictions

Use unshared physical interfaces or EtherChannels when configuring multi-instance mode.

  • Multi-instance shared interfaces are not supported. You must use an unshared interface.

  • Multi-instance chassis-defined subinterfaces are not supported. You must use a physical interface or EtherChannel.

General configuration guidelines

Consider these interface and traffic inspection requirements when configuring inline sets and passive interfaces.

  • Inline sets and passive interfaces support only physical interfaces and EtherChannels. You cannot use VLANs or other virtual interfaces, including multi-instance chassis-defined subinterfaces.

  • Because IPS interfaces do not support regular firewall protections, traffic must pass through the same Firewall Threat Defense to ensure all traffic is inspected according to the IPS security policy (Snort).

  • Bidirectional Forwarding Detection (BFD) echo packets are not allowed through the Firewall Threat Defense when using inline sets. If there are two neighbors on either side of the Firewall Threat Defense running BFD, then the Firewall Threat Defense will drop BFD echo packets because they have the same source and destination IP address and appear to be part of a LAND attack.

  • For inline sets and passive interfaces, the Firewall Threat Defense supports up to two 802.1Q headers in a packet (also known as Q-in-Q support), with the exception of the Firepower 4100/9300, which only supports one 802.1Q header. Note: Firewall-type interfaces do not support Q-in-Q, and only support one 802.1Q header.

Hardware Bypass Guidelines

Consider Hardware Bypass limitations and clustering requirements when configuring inline sets.

  • Hardware Bypass ports are supported only for inline sets.

  • Hardware Bypass ports cannot be part of an EtherChannel.

  • Hardware Bypass is not supported in high availability mode.

  • Hardware Bypass ports are supported with intra-chassis clustering on the Firepower 9300. Ports are placed in Hardware Bypass mode when the last unit in the chassis fails. Inter-chassis clustering is not supported, because inter-chassis clustering only supports Spanned EtherChannels; Hardware Bypass ports cannot be part of an EtherChannel.

  • If all modules in an intra-chassis cluster on the Firepower 9300 fail, then Hardware Bypass is triggered on the final unit, and traffic continues to pass. When units come back up, Hardware Bypass returns to standby mode. If rules matching application traffic are used, connections might be dropped and require reestablishment. Connections are dropped because state information is not retained on the cluster unit, and the unit cannot identify the traffic as belonging to an allowed application. To prevent a traffic drop, use a port-based rule instead of an application-based rule, if appropriate for your deployment.

  • You can use Hardware Bypass interfaces as regular interfaces without the Hardware Bypass feature enabled.

Unsupported firewall features on IPS interfaces

These firewall features are not supported on IPS interfaces.

  • DHCP server

  • DHCP relay

  • DHCP client

  • TCP Intercept

  • Routing

  • NAT

  • VPN

  • Application inspection

  • QoS

  • NetFlow

  • VXLAN