<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower 2130 IPS inline deployment with port-channel in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-2130-ips-inline-deployment-with-port-channel/m-p/3359024#M922132</link>
    <description>&lt;P&gt;Hello all. I'm trying to configure an IPS inline pair&amp;nbsp;between an ASA and Nexus switch. The ASA is currently port-channeled down to the Nexus and I want to implement the Firepower 2130 inline in between them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to configure and 2 ether-channels on the IPS - 1&amp;nbsp;ether-channel for inside, 1 for outside and configure a single&amp;nbsp;inline set between the ether-channel interfaces. or do I need to configure individual interfaces on the IPS and set up 2 independent inline sets?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I configure the inline set between the 2 ether-channel interfaces, it does not automatically change the ether-channel interfaces to inline mode like it should. It works when I use physical links for the inline sets.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According to page 13 of the attached&amp;nbsp;document, ether-channel with inline sets on the 4150 should work, but I am unable to get ether-channel to work with inline set on the 2130.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;appreciate any help.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:35:23 GMT</pubDate>
    <dc:creator>west33637</dc:creator>
    <dc:date>2020-02-21T15:35:23Z</dc:date>
    <item>
      <title>Firepower 2130 IPS inline deployment with port-channel</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2130-ips-inline-deployment-with-port-channel/m-p/3359024#M922132</link>
      <description>&lt;P&gt;Hello all. I'm trying to configure an IPS inline pair&amp;nbsp;between an ASA and Nexus switch. The ASA is currently port-channeled down to the Nexus and I want to implement the Firepower 2130 inline in between them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to configure and 2 ether-channels on the IPS - 1&amp;nbsp;ether-channel for inside, 1 for outside and configure a single&amp;nbsp;inline set between the ether-channel interfaces. or do I need to configure individual interfaces on the IPS and set up 2 independent inline sets?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I configure the inline set between the 2 ether-channel interfaces, it does not automatically change the ether-channel interfaces to inline mode like it should. It works when I use physical links for the inline sets.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According to page 13 of the attached&amp;nbsp;document, ether-channel with inline sets on the 4150 should work, but I am unable to get ether-channel to work with inline set on the 2130.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;appreciate any help.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:35:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2130-ips-inline-deployment-with-port-channel/m-p/3359024#M922132</guid>
      <dc:creator>west33637</dc:creator>
      <dc:date>2020-02-21T15:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2130 IPS inline deployment with port-channel</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2130-ips-inline-deployment-with-port-channel/m-p/3359050#M922133</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I recall, etherchannel in IPS mode only are supported only on FP4100 and 9300 chassis.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had (don't remember how) an email from Cisco saying:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Answer: IPS-only interfaces support physical interfaces only, and cannot be EtherChannels, redundant interfaces, VLANs, and so on.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;The exception is for EtherChannels (Port-channel) configured on the Firepower 4100/9300 chassis, which are supported.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 15:25:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2130-ips-inline-deployment-with-port-channel/m-p/3359050#M922133</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-04-02T15:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2130 IPS inline deployment with port-channel</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2130-ips-inline-deployment-with-port-channel/m-p/3359070#M922134</link>
      <description>Any documentation to back this? I believe your statement is accurate, but I need some documentation to point my client to. Thanks,</description>
      <pubDate>Mon, 02 Apr 2018 15:51:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2130-ips-inline-deployment-with-port-channel/m-p/3359070#M922134</guid>
      <dc:creator>west33637</dc:creator>
      <dc:date>2018-04-02T15:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2130 IPS inline deployment with port-channel</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2130-ips-inline-deployment-with-port-channel/m-p/3359073#M922135</link>
      <description>Nope. I can try to found it later tonight otherwise, you can open a case to Partner Helpline and ask this question, they will reply with a doc certainly.&lt;BR /&gt;</description>
      <pubDate>Mon, 02 Apr 2018 15:53:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2130-ips-inline-deployment-with-port-channel/m-p/3359073#M922135</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-04-02T15:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2130 IPS inline deployment with port-channel</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2130-ips-inline-deployment-with-port-channel/m-p/3764041#M922136</link>
      <description>&lt;P&gt;Hello Francesco&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’m a little confused cause by the following situation and I would like have an explanation: According to your response the Firepower 4100 series can be deployed transparently for LACP with inline-pairs, but there is a colleague doing another Inline deployment with Firepower 7120s IPS-Only located among a Link-Aggregation between FW and LoadBalancer and there is VLAN Tagged Traffic through it. When he deployed the Firepower 7120s (Using a Inline interface pairs instead of LinkAggregation configuration towards FW and LoadBalancer) there were troubles with the Tagged Traffic and it doesn't works. Then he had to configure a LinkAggregation Interfaces on Firepower 4100 and Logical(Tagged) interface for resolving it. Could happen the same thing with Firepower 4100 ? Please let me know your point of view about it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And I want to know If you can help me to confirm how must be deployed the FP4100 according to the "Best Practices":&lt;/P&gt;
&lt;P&gt;1. First Stage: The FP4100 must be deployed in Passive Mode (SPAN or Port Mirror) for Learning stage ?&lt;BR /&gt;2. Second Stage: After the learning stage the FP4100 must be deployed Inline using Interface-Pairs or LACP Interface? What feature inspections can gain or loose in any of those modes? Could I inspect tagged Traffic in any f those modes? Which mode could guarantee the well function of Hardware Bypass? I've attached a generic Topology.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank a lot&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edgar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 19:02:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2130-ips-inline-deployment-with-port-channel/m-p/3764041#M922136</guid>
      <dc:creator>maur7311</dc:creator>
      <dc:date>2018-12-14T19:02:26Z</dc:date>
    </item>
  </channel>
</rss>

