Configure an Existing Physical Interface for Switch Port Mode

Procedure


Step 1

In the navigation pane, click Inventory.

Step 2

Click the Devices tab to locate the device or the Templates tab to locate the model device.

Step 3

Click the FTD tab and select the device you want to configure interfaces for.

Step 4

In the Management pane on the right, click Interfaces.

Step 5

On the Interfaces page, select the physical interface you want to modify. In the Action Pane on the right, click the edit icon .

Step 6

Interfaces configured for switch port mode do not support logical names. If the interface has a logical name, delete it.

Step 7

Locate the Mode and use the drop-down menu to select Switch Port.

Step 8

Configure the physical interface for switch port mode:

  • (Optional) Check the Protected Port check box to set this switch port as protected, so you can prevent the switch port from communicating with other protected switch ports on the same VLAN. You might want to prevent switch ports from communicating with each other if: the devices on those switch ports are primarily accessed from other VLANs; you do not need to allow intra-VLAN access; and you want to isolate the devices from each other in case of infection or other security breach. For example, if you have a DMZ that hosts three web servers, you can isolate the web servers from each other if you apply this option to each switch port. The inside and outside networks can both communicate with all three web servers, and vice versa, but the web servers cannot communicate with each other.

  • For the Usage Type, select Access or Trunk. See Switch Port Mode Interfaces for FTD to determine which port type you need.

    • If you select Trunk, you must select one VLAN interface as the Native Trunk VLAN to forward untagged traffic and at least one Associated VLAN to forward tagged traffic. Click the icon to view the existing physical interfaces. You can select up to 20 VLAN interfaces as associated VLANs.

    • You can create a new VLAN interface set to Access mode by clicking C reate new VLAN.

Step 9

Click Save. Confirm that you want to reset the VLAN configuration and reassign an IP address to the interface.

Step 10

Review and deploy now the changes you made, or wait and deploy multiple changes at once.