300-710 · Question #161
An engineer is configuring Cisco FMC and wants to allow multiple physical interfaces to be part of the same VLAN. The managed devices must be able to perform Layer 2 switching between interfaces…
The correct answer is D. integrated routing and bridging. To enable multiple physical interfaces or sub-interfaces on a Cisco FTD to be part of the same VLAN and perform Layer 2 switching between them, integrated routing and bridging (IRB) must be configured. IRB allows the FTD device to function as both a Layer 2 switch and a Layer 3…
Question
An engineer is configuring Cisco FMC and wants to allow multiple physical interfaces to be part of the same VLAN. The managed devices must be able to perform Layer 2 switching between interfaces, including sub-interfaces. What must be configured to meet these requirements?
Options
- Ainter-chassis clustering VLAN
- BCisco ISE Security Group Tag
- Cinterface-based VLAN switching
- Dintegrated routing and bridging
How the community answered
(26 responses)- A12% (3)
- B8% (2)
- C4% (1)
- D77% (20)
Why each option
To enable multiple physical interfaces or sub-interfaces on a Cisco FTD to be part of the same VLAN and perform Layer 2 switching between them, integrated routing and bridging (IRB) must be configured. IRB allows the FTD device to function as both a Layer 2 switch and a Layer 3 router.
Inter-chassis clustering VLANs are related to high availability deployments across multiple physical devices, not to enabling internal Layer 2 switching capabilities within a single FTD device.
Cisco ISE Security Group Tags (SGTs) are used for identity-based policy enforcement and segmentation, not for configuring Layer 2 switching between firewall interfaces.
While 'interface-based VLAN switching' describes the desired outcome, 'integrated routing and bridging' (IRB) is the specific Cisco feature and configuration model that enables this Layer 2 switching behavior on FTD devices.
Integrated routing and bridging (IRB) allows a Cisco FTD device to act as a Layer 2 switch for interfaces (including sub-interfaces) assigned to the same bridge group (VLAN), while also enabling Layer 3 routing capabilities for that VLAN. This configuration meets the requirement of performing Layer 2 switching between interfaces within the same VLAN.
Concept tested: Cisco FTD Integrated Routing and Bridging (IRB)
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Interfaces_for_Firepower_Threat_Defense.html#concept_AC441E7A33374495BF7C63D084620023
Topics
Community Discussion
No community discussion yet for this question.