Configure an Inline Set
This section enables and names two physical interfaces that you can add to an inline set. You can also optionally enable Hardware Bypass for supported interface pairs.
Note | For the threat defense on the FXOS chassis, you configure basic interface settings on the Firepower 4100/9300 chassis. See Configure a Physical Interface for more information. |
Before you begin
-
We recommend that you set STP PortFast for STP-enabled switches that connect to the threat defense inline pair interfaces. This setting is especially useful for Hardware Bypass configurations and can reduce bypass times.
Procedure
Step 1 | Select Edit () for your threat defense device. The Interfaces page is selected by default. and click | ||||
Step 2 | Click Edit () for the interface you want to edit. | ||||
Step 3 | In the Mode drop-down list, choose None. After you add this interface to an inline set, this field will show Inline for the mode. | ||||
Step 4 | Enable the interface by checking the Enabled check box. | ||||
Step 5 | In the Name field, enter a name up to 48 characters in length. Do not set the security zone yet; you must set it after you create the inline set later in this procedure. | ||||
Step 6 | (Optional) Add a description in the Description field. The description can be up to 200 characters on a single line, without carriage returns. | ||||
Step 7 | (Optional) Set the duplex and speed by clicking Hardware Configuration. The exact speed and duplex options depend on your hardware.
| ||||
Step 8 | Click OK. Do not set any other settings for this interface. | ||||
Step 9 | Click Edit () for the second interface you want to add to the inline set. | ||||
Step 10 | Configure the settings as for the first interface. | ||||
Step 11 | Click Inline Sets. | ||||
Step 12 | Click Add Inline Set. The Add Inline Set dialog box appears with General selected. | ||||
Step 13 | In the Name field, enter a name for the set. | ||||
Step 14 | (Optional) Change the MTU to enable jumbo frames. For inline sets, the MTU setting is not used. However, the jumbo frame setting is relevant to inline sets; jumbo frames enable the inline interfaces to receive packets up to 9000 bytes. To enable jumbo frames, you must set the MTU of any interface on the device above 1500 bytes. | ||||
Step 15 | (Optional) For the Bypass mode, choose one of the following options:
| ||||
Step 16 | In the Available Interfaces Pairs area, click a pair and then click Add to move it to the Selected Interface Pair area. All possible pairings between named and enabled interfaces with the mode set to None show in this area. | ||||
Step 17 | (Optional) Click Advanced to set the following optional parameters:
| ||||
Step 18 | Click Interfaces. | ||||
Step 19 | Click Edit () for one of the member interfaces. | ||||
Step 20 | From the Security Zone drop-down list, choose a security zone or add a new one by clicking New. You can only set the zone after you add the interface to the inline set; adding it to an inline set configures the mode to Inline and lets you choose inline-type security zones. | ||||
Step 21 | Click OK. | ||||
Step 22 | Set the security zone for the second interface. | ||||
Step 23 | Click Save. You can now go to and deploy the policy to assigned devices. The changes are not active until you deploy them. |