07-07-2023 07:57 AM
Hi,
I have Cisco Firepower 1100 series (FPR-1120)
System image file is "disk0:/installables/switch/fxos-k8-fp1k-lfbff.2.8.1.105.SPA"
I am in a need to configure two or more LAN interfaces to make a LAN which can communicate at LAN level (in other words, in the same VLAN or same network).
I created a Ether channel as:
And let the DHCP (with all default values) to assign the IP addresses.
Now one of the member port is now connected with a network which is distributing IP addresses via DHCP.
When I connect a PC to second member port, it didn't get any IP from DHCP.
What should be configured to achieve a LAN based communication /switching so that I connect multiple devices belonging to the same network.
Note: I fully understand that Firepower is not designed for switching, and best solution should be to connect a LAN Switch in between to attach multiple clients. But sometimes, needs to find a solution outside of the recommended zone.
Any suggestion /step by step guide /screenshots will be appreciated.
Solved! Go to Solution.
07-10-2023 07:50 AM
security level must same for endpoints ports and BVI
name must be different like BVI7_1 and BVI7_2
07-07-2023 11:48 AM
Hi @amh4y0001
If you create a port-channel on the firewall side, it is expected that you connect on the other side of the port-channel another device which supports port-channel like a router, switch or another firewall.
You can not use individual interface on a port-channel like that. Why dont you try with one interface only ? And make sure the firewall supports mdix otherwise you need to use cross-over cable.
07-07-2023 01:50 PM
Then I guess I was wrong to use the Ether channel. Let me explain what is my need.
Goal: Is to have two interfaces or more in same Network /VLAN. On Cisco Firepower it is not possible to two or interface with same IP range /network.
What should I do here?
07-07-2023 02:19 PM
Create a bridge group
"The group members do not have IP addresses. Instead, all member interfaces share the IP address of the Bridge Virtual Interface (BVI). "
07-07-2023 11:54 AM
can you share your topology
thanks
MHM
07-07-2023 01:52 PM
Topology diagram is not available at the moment. But I can explain what I am trying to achieve here:
Goal: Is to have two interfaces or more in same Network /VLAN. On Cisco Firepower it is not possible to two or interface with same IP range /network. What should be the works around to configure multiple Ethernet ports into one LAN?
07-07-2023 01:55 PM
I Think what you looking for us BDI'
Fpr support bdi.
Bdi can make your FW connect to same vlan via two interfaces.
07-07-2023 02:15 PM
@MHM Cisco World Thanks for input, do you have a step by step guide?
07-07-2023 02:23 PM
You mgmt fpr by fmc or fdm ?
07-07-2023 03:05 PM
Device = Cisco Firepower 1100 series (FPR-1120)
System image file is "disk0:/installables/switch/fxos-k8-fp1k-lfbff.2.8.1.105.SPA"
Interface 3:
Static IP Address = 10.10.10.1 255.0.0.0.
Error while configuring Interface 4 with same network as interface 3.
07-08-2023 12:09 AM
this for ASDM,
config bridge group
config BVI <<- assign IP to BVI
07-10-2023 02:21 AM
BVI group has been created and Eth3 and Eth4 are the members. BVI1 has been assigned static IP address.
However, when I connect end points, I get 169.x.x.x APIPA address.
07-10-2023 03:15 AM
this meaning that you not enable DHCP server in BVI interface you add
enable the DHCP server for BVI interface
07-10-2023 04:10 AM
@MHM Cisco World So I should not assign static IP address on BVI1 interface?
Do you have more specific steps /screenshots for follow?
07-10-2023 04:12 AM
NO friend you need assign IP to BVI but also you need to enable DHCP server in this interface to make endpoint get IP from ASA BVI.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide