Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Asa Firewall

how to implement etherchannel in asa 5520

Super Bronze

Asa Firewall


You can check this in the configuration guide for the ASA.

But in the likelyhood that you are not finding the command to create the actual interface then I would have to guess that you are not running a software level new enough to support Etherchannel/Port-channel.

You will require 8.4(1) software atleast on the ASA to be able to configure Etherchannel/Port-channel

This is from the Release notes

Interface Features

EtherChannel support (ASA 5510 and higher)

You can configure up to 48 802.3ad EtherChannels of eight active interfaces each.

Note You cannot use interfaces on the 4GE SSM, including the integrated 4GE SSM in slot 1 on the ASA 5550, as part of an EtherChannel.

We introduced the following commands: channel-group, lacp port-priority, interface port-channel, lacp max-bundle, port-channel min-bundle, port-channel load-balance, lacp system-priority, clear lacp counters, show lacp, show port-channel.

We introduced or modified the following screens:

Configuration > Device Setup > Interfaces

Configuration > Device Setup > Interfaces > Add/Edit EtherChannel Interface

Configuration > Device Setup > Interfaces > Add/Edit Interface

Configuration > Device Setup > EtherChannel

Here is a link to the configuration guide explaining the configuration steps

Hope this helps

Please do remember to mark a reply as the correct answer if it answered your question.

- Jouni

Asa Firewall


you could do on CLI as below. let me know if you want to do via ASDM.

ciscoasa(config)# interface gigabitethernet1

ciscoasa(config-if)# channel-group ?

interface mode commands/options:

  <1-48>  Channel group number

ciscoasa(config-if)# channel-group 1 ?

interface mode commands/options:

  mode  Etherchannel Mode of the interface

ciscoasa(config-if)# channel-group 1 mode ?

interface mode commands/options:

  active   Enable LACP unconditionally

  on       Enable static port-channel

  passive  Enable LACP only if a LACP device is detected

ciscoasa(config-if)# channel-group 1 mode on

CreatePlease login to create content