Hi,
We have a pair of Firepower 1120 running FTD in transparent mode and active/standby HA. They should do IPS and threat protection for internet links with two separate ISP connections and different IP ranges and routing.
Separate bridge groups for each ISP.

Uplink switches are 2 x Nexus C9348GC switches with vPC.

What's the best practise for interface assignments in such a setup for throughput and failover resiliency? The FTD admin guide is not very clear about this and the Youtube tutorials were all with virtual FTDs.
- Combined: 4 x 1 Gb/s port-channel with VLAN subinterfaces for both ISPs inside and outside
- Separated: 2 x 1 Gb/s port-channel for ISPs inside and another 2 x 1 Gb/s for outside, both with VLAN subinterfaces
- No port-channel and no VLAN subinterfaces at all, hardwired 1:1 connections
- It doesn't matter
Thanks in advance,
Bernd