Interface pairs

This help contains the following topics:

Introduction

Interface pairs monitor traffic at the data link layer. It is typically used on security devices. Layer 2 traffic arriving at a device is redirected to a security device, filtered, and then forwarded toward the destination.

The following forwarding modes are supported:

Forwarding of tunneled packets

By default, tunneled packets are forwarded based on the tunnel headers.

You can configure the device to forward tunneled packets based on the original packet headers.

VLAN ID check

This feature enables the device to check the VLAN ID of each packet that matches a session entry during inline forwarding.

On a hot backup system, you must disable VLAN ID check if the traffic incoming interfaces on the primary and secondary devices belong to different VLANs. If you enable VLAN ID check, traffic cannot match session entries correctly after a primary/secondary device switchover occurs or when asymmetric-path traffic exists.

Security service bypass

By default, packets are processed by the security service first before being forwarded according to the configured bridge forwarding mode.

The security service bypass feature enables user traffic to bypass security service processing of a security device and be forwarded directly according to the configured bridge forwarding mode.

Security service bypass can be classified into internal bypass and external bypass.

Internal bypass

User traffic is sent to the security device but is not processed by it. The security device directly forwards or drops the traffic according to the configured bridge forwarding mode.

Internal bypass is available for interface pairs operating in reflect-type, blackhole-type, or forward-type forwarding mode.

External bypass

User traffic is forwarded by the Power Free Connector (PFC) device directly without passing through the security device.

Internal bypass is available only for interface pairs using the forward-type forwarding mode.

External bypass can be further classified in to the following types:

vSystem support information

Support of non-default vSystems for this feature depends on the device model. This feature is available on the Web interface only if it is supported.

Restrictions and guidelines

Configure an interface pair

Procedure

  1. Click the Network tab.

  2. In the navigation pane, select Interface Configuration > Inline > Interface Pairs.

  3. Click Create.

    The Create Interface Pair page opens.

  4. Create an interface pair.

Table-1 Interface pair configuration items

Item

Description

Forwarding mode

Select the forwarding mode of the interface pair. Options include:

  • Reflect

  • Blackhole

  • Forward

Security service bypass

Enable or disable security service bypass.

Interface 1

Select an interface as receiving interface 1 of packets.

Interface 2

Select an interface as receiving interface 2 of packets.

This field is available only when the Forward mode is selected.

  1. Click OK. The interface pair will displayed on the Interface Pairs page.

  2. On the Advanced Settings page, configure advanced settings.

Table-2 Configuration items for advanced settings

Item

Description

Forward tunneled packets based on

Select the basis for forwarding tunneled packets. Options include:

  • Original packet headers—Forward tunneled packets based on the original packet headers.

  • Tunnel headers—Forward tunneled packets based on tunnel headers.

VLAN ID Check

Enable or disable VLAN ID check.