Configure General Bridge Group Member Interface Parameters
This procedure describes how to set the name and security zone for each bridge group member interface. The same bridge group can include different types of interfaces: physical interfaces, VLAN subinterfaces, Firepower 1010 and Secure Firewall 1210/1220 VLAN interfaces, EtherChannels, and redundant interfaces. The Management interface is not supported. In routed mode, EtherChannels are not supported. For the Firepower 4100/9300, data-sharing type interfaces are not supported.
Before you begin
-
Firepower 4100/9300
-
(Optional) Configure any special interfaces.
-
Add a Subinterface in management center
-
(Optional) All other models:
-
Firepower 1010 and Secure Firewall 1210/1220: Configure a VLAN Interface
Procedure
Step 1 | Select Edit () for your threat defense device. The Interfaces page is selected by default. and click | ||||||||||||||||||||||||
Step 2 | Click Edit () for the interface you want to edit. | ||||||||||||||||||||||||
Step 3 | In the Name field, enter a name up to 48 characters in length. You cannot start the name with the phrase "cluster". It is reserved for internal use. | ||||||||||||||||||||||||
Step 4 | Enable the interface by checking the Enabled check box. | ||||||||||||||||||||||||
Step 5 | (Optional) Set this interface to Management Only to limit traffic to management traffic; through-the-box traffic is not allowed. | ||||||||||||||||||||||||
Step 6 | (Optional) Add a description in the Description field. The description can be up to 200 characters on a single line, without carriage returns. | ||||||||||||||||||||||||
Step 7 | In the Mode drop-down list, choose None. Regular firewall interfaces have the mode set to None. The other modes are for IPS-only interface types. After you assign this interface to a bridge group, the mode will show as Switched. | ||||||||||||||||||||||||
Step 8 | From the Security Zone drop-down list, choose a security zone or add a new one by clicking New. The bridge group member interface is a Switched-type interface, and can only belong to Switched-type zones. Do not configure any IP address settings for this interface. You will set the IP address for the Bridge Virtual Interface (BVI) only. Note that the BVI does not belong to a zone, and you cannot apply access control policies to the BVI. | ||||||||||||||||||||||||
Step 9 | See Configure the MTU for information about the MTU. | ||||||||||||||||||||||||
Step 10 | (Optional) Set the duplex and speed by clicking .
| ||||||||||||||||||||||||
Step 11 | (Optional) See Configure IPv6 Addressing to configure IPv6 addressing on the IPv6 tab. | ||||||||||||||||||||||||
Step 12 | (Optional) See Configure the MAC Address to manually configure the MAC address on the Advanced tab. | ||||||||||||||||||||||||
Step 13 | Click OK. | ||||||||||||||||||||||||
Step 14 | Click Save. You can now go to and deploy the policy to assigned devices. The changes are not active until you deploy them. |