Configure an Aggregate Ethernet Layer 2 Switch Interface
Focus
Focus
Next-Generation Firewall

Configure an Aggregate Ethernet Layer 2 Switch Interface

Table of Contents

Configure an Aggregate Ethernet Layer 2 Switch Interface

Bundle multiple physical ports into a single logical interface to increase bandwidth and provide redundancy on your firewalls.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by PAN-OS or Panorama)
  • PAN-OS 12.2.2 or a later release
  • PA-500 Series: PA-550, PA-560
  • No additional license required
Link aggregation groups (LAGs) bundle multiple physical ports into a single logical interface for increased bandwidth and redundancy using IEEE 802.1AX. Layer 2 switch interfaces support both static aggregation and LACP-dynamic aggregation. Each platform supports up to 12 aggregate Ethernet (AE) interfaces with up to eight member ports per AE interface.
Multi-chassis LAG (MCLAG) is not supported. All LAG member ports must reside on the same firewall.
  1. Assign each physical member interface to the aggregate group:
    1. Select NetworkInterfacesEthernet and click a member interface.
    2. For Interface Type, choose Aggregate Ethernet.
    3. For Aggregate Group, choose the AE interface this port will join, for example, ae1.
    4. Click OK.
    5. Repeat for all remaining member interfaces in the LAG.
  2. Select NetworkInterfacesEthernet and click the aggregate interface you created, for example, ae1.
  3. For Interface Type, choose Layer2 Switch.
  4. Configure Port Type (Access or Trunk) and VLAN settings following the same steps as for a single Ethernet interface. Storm control and STP settings apply to each member port individually and are not aggregated across the LAG.
    Storm control log entries are generated per member port independently. When a storm condition is detected, the log entry identifies the specific physical member interface (for example, ethernet1/2), not the aggregate Ethernet interface. Each member port is evaluated against the threshold and logged separately based on its own individual traffic levels.
  5. (Optional) If you are using LACP, click the LACP tab and choose Active or Passive mode. For a static LAG without a control protocol, skip this step.
  6. Click OK and Commit.