Guidelines for EtherChannels and redundant interfaces
Provides essential configuration rules and limitations for implementing EtherChannels and redundant interfaces to maintain network stability and high availability.
Bridge Group
In routed mode, Cloud-Delivered Firewall Management Center -defined EtherChannels are not supported as bridge group members. EtherChannels on the Firepower 4100/9300 can be bridge group members.
High availability
-
When you use an EtherChannel interface as a High availability link, it must be pre-configured on both units in the High availability pair; you cannot configure it on the primary unit and expect it to replicate to the secondary unit because the High availability link itself is required for replication .
-
If you use an EtherChannel interface for the state link, no special configuration is required; the configuration can replicate from the primary unit as normal. For the Firepower 4100/9300 chassis , all interfaces, including EtherChannels, need to be pre-configured on both units.
-
You can monitor EtherChannel interfaces for High availability . When an active member interface fails over to a standby interface, this activity does not cause the EtherChannel interface to appear to be failed when being monitored for device-level High availability . Only when all physical interfaces fail does the EtherChannel interface appear to be failed (for an EtherChannel interface, the number of member interfaces allowed to fail is configurable) .
-
If you use an EtherChannel interface for a High availability or state link, then to prevent out-of-order packets, only one interface in the EtherChannel is used. If that interface fails, then the next interface in the EtherChannel is used. You cannot alter the EtherChannel configuration while it is in use as a High availability link. To alter the configuration, you need to temporarily disable High availability , which prevents High availability from occurring for the duration.
Model Support
-
You cannot add EtherChannels in the Cloud-Delivered Firewall Management Center for the Firepower 4100/9300 or the Firewall Threat Defense Virtual . The Firepower 4100/9300 supports EtherChannels, but you must perform all hardware configuration of EtherChannels in FXOS on the chassis.
-
You cannot use Firepower 1010 or Secure Firewall 1210/1220 switch ports or VLAN interfaces in EtherChannels.
Clustering
-
To configure a spanned EtherChannel or an individual cluster interface, see the clustering chapter.
General Redundant Interface Guidelines
-
You can configure up to 8 redundant interface pairs.
-
All the Firewall Threat Defense configuration refers to the logical redundant interface instead of the member physical interfaces.
-
You cannot use a redundant interface as part of an EtherChannel, nor can you use an EtherChannel as part of a redundant interface. You cannot use the same physical interfaces in a redundant interface and an EtherChannel interface. You can, however, configure both types on the Firewall Threat Defense device if they do not use the same physical interfaces.
-
If you shut down the active interface, then the standby interface becomes active.
-
Redundant interfaces do not support the Management slot / port interfaces as members. You can, however, set a redundant interface comprised of non- Management interfaces as management-only.
General EtherChannel Guidelines
-
You can configure up to 48 EtherChannels, depending on how many interfaces are available on your model.
-
Each channel group can have up to 8 active interfaces, except for ASA models and the ISA 3000, which supports 16 active interfaces. For switches that support only 8 active interfaces, you can assign up to 16 interfaces to a channel group: while only 8 interfaces can be active, the remaining interfaces can act as standby links in case of interface failure.
-
When you add the first member interface, it sets the required hardware properties of all member interfaces.
-
The media type of member interfaces can be either RJ-45 or SFP; SFPs of different types (copper and fiber) can be mixed. You cannot mix RJ-45 and SFP interfaces.
-
All interfaces must be set to the same speed and duplex.
-
The first interface sets the speed capacity , which cannot be changed later.
-
-
The device to which you connect the Firewall Threat Defense EtherChannel must also support 802.3ad EtherChannels.
-
The Firewall Threat Defense device does not support LACPDUs that are VLAN-tagged. If you enable native VLAN tagging on the neighboring switch using the Cisco IOS vlan dot1Q tag native command, then the Firewall Threat Defense device will drop the tagged LACPDUs.
-
The LACP rate depends on the model. When you set the rate (normal or fast), the device requests that rate from the connecting switch.
-
In Cisco IOS software versions earlier than 15.1(1)S2, Firewall Threat Defense does not support connecting an EtherChannel to a switch stack. To improve compatibility, set the stack-mac persistent timer command to a large enough value to account for reload time.
-
All the Firewall Threat Defense configuration refers to the logical EtherChannel interface instead of the member physical interfaces.