SonicOSX 7 System

Configuring an L2 Bypass for Hardware Failures

An L2 bypass enables you to perform a physical bypass of the appliance when an interface is bridged to another interface with LAN bypass capability. This allows network traffic to continue flowing when an unrecoverable firewall failure occurs.

When the L2 bypass relay is closed, the network cables attached to the bypassed interfaces (X0 and X1) are physically connected as if they were a single continuous network cable. The Engage physical bypass on malfunction option provides you the choice of avoiding disruption of network traffic by bypassing the firewall in the event of a malfunction.

L2 bypass is only applicable to interfaces in Layer 2 Bridged Mode. The Engage physical bypass on malfunction option only appears when the Layer 2 Bridged Mode option is selected from Mode / IP Assignment. This option does not appear unless a physical bypass relay exists between the two interfaces of the bridge-pair.

When the Engage physical bypass on malfunction option is enabled, the other Layer 2 Bridged Mode options are automatically set

  • Block all non-IPv4 traffic – disabled. When enabled, this option blocks all non-IPv4 Ethernet frames. So, this option is disabled.
  • Never route traffic on this bridge-pair – enabled. When enabled, this option prevents packets from being routed to a network other than the peer network of the bridged pair. So, this option is enabled.
  • Only sniff traffic on this bridge-pair – disabled. When enabled, traffic received on the bridge-pair interface is never forwarded. So, this option is disabled.
  • Disable stateful-inspection on this bridge-pair – unchanged. This option is not affected.

To configure an L2 bypass

  1. Navigate to NETWORK | System > Interfaces.
  2. Click the Edit icon in the Configure column for the interface you want to configure. The Edit Interface dialog displays.
  3. Select Engage physical bypass on malfunction.

    The Engage physical bypass on malfunction option is available only when the X0 and X1 interfaces are bridged together on an NSA-6600 or above.

  4. Click OK.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden