Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Configure Interface Priority

Want to summarize with AI?

Log in

Overview

Provides instructions to set interface priority for a Threat Defense device to control preferred internet egress paths when routing internet‑bound traffic.

Cisco Secure Firewall Threat Defense uses interface priority to determine the optimal internet path. Priority ranges from 0 to 65535, and determines the preference of a particular ISP when sending the traffic out to the internet. The traffic is forwarded based on the priority of the interfaces. Traffic is routed to the interface with the least priority value first. When an interface is not available, traffic is forwarded to the interface with the next lowest priority value. For example, let us assume that outside2 and outside3 are configured with priority values 10 and 20 respectively. The traffic is forwarded to outside2. If outside2 becomes unavailable, the traffic is then forwarded to outside3.

Procedure

1.

Choose Devices > Device Management, and edit the threat defense device (NGFWBR1).

2.

Click the Routing tab on the interface view of NGFWBR1.

3.

Click Policy Based Routing.

4.

Click Configure Interface Priority.

5.

In the dialog box, provide the priority number against the interfaces.

When the priority value is the same for all the interfaces, the traffic is balanced among the interfaces.

6.

Click Save.