Guidelines for Inline Sets and Passive Interfaces
Firewall Mode
-
ERSPAN interfaces are only allowed when the device is in routed firewall mode.
General Guidelines
-
Inline sets and passive interfaces support physical interfaces only, and cannot use EtherChannels, redundant interfaces, VLANs, and so on.
-
Inline sets and passive interfaces are supported in intra-chassis and inter-chassis clustering.
-
Bidirectional Forwarding Detection (BFD) echo packets are not allowed through the FTD when using inline sets. If there are two neighbors on either side of the FTD running BFD, then the FTD will drop BFD echo packets because they have the same source and destination IP address and appear to be part of a LAND attack.
-
For all models except for the Firepower 4100/9300, the FTD supports no more than two 802.1Q headers in a packet (also known as Q-in-Q support) for inline sets and passive interfaces. Firewall interfaces do not support Q-in-Q, and the Firepower 4100/9300 models do not support Q-in-Q for any type of interface.
Unsupported Firewall Features on IPS Interfaces
-
DHCP server
-
DHCP relay
-
DHCP client
-
TCP Intercept
-
Routing
-
NAT
-
VPN
-
Application inspection
-
QoS
-
NetFlow
-
VXLAN