Configure the Ethernet interfaces that connect
the firewall to the ACI leaf switches. The VLAN ID number used in
this configuration should be a member of the VLAN pool assigned
to the firewalls in ACI.
The VM-Series firewall does
not support aggregate Ethernet groups.
Select
Network
Interfaces
Ethernet
and
click
Add Aggregate Group
.
Enter a number for the aggregate group in the second
Interface
Name
field.
Select Layer 3 from the
Interface Type
drop-down.
Select the
LACP
tab and click
Enable
LACP
.
Select
Fast
as the
Transmission
Rate
.
Under High Availability Options, select
Enable
in HA Passive State
.
Do not select
Same System MAC Address
for Active-Passive HA
. This option makes the firewall
pair appear as a single device to the switch, so traffic will flow
to both firewalls instead of just the active firewall.
Click
OK
.
Click on the name of an Ethernet interface to configure
it and add it to the aggregate group.
Select
Aggregate Ethernet
from
the Interface Type drop-down.
Select the interface you defined in the aggregate
Ethernet group configuration.
Click
OK
.
Repeat this step for each other member interface of
the aggregate Ethernet group.
Add a subinterface on the aggregate Ethernet interface
for the tenant and VRF.
Select the row of your aggregate Ethernet
group and click
Add Subinterface
.
In the second
Interface Name
field,
enter a numerical suffix to identify the subinterface.
In the
Tag
field, enter the
VLAN tag of the subinterface.
Select the virtual router you configured previously
from the
Virtual Router
drop-down.
Select the zone you configured previously from the
Zone
drop-down.
Select the
IPv4
tab.
Select the
Static
Type.
Click
Add
and enter the subinterface
IP address and network mask in CIDR notation.