Limitations and Precautions for Bypass
Read this section carefully to learn the limitations and precautions before you configure hardware bypass.
Hardware Requirements
The hardware bypass function is supported only when the combo ports numbered from GE0/0/20 to GE0/0/23 of the USG6575E-B/6605E-B work as electrical interfaces.
License Requirements
The hardware bypass function is not license-controlled.
Precautions
- The interfaces numbered from GE0/0/20 to GE0/0/23 are combo ports and can support the hardware bypass function only when they work as electrical interfaces. Therefore, in physical connection, select electrical interface networking.
- The hardware bypass function is supported only on a fixed set of bypass interfaces. You can pair GE0/0/20 with GE0/0/21, GE0/0/22 with GE0/0/23, but not GE0/0/20 with GE0/0/23.
- The hardware bypass function requires that both combo ports in the bypass interface pair work as electrical interfaces. If one of the combo iports works as an optical interface, the hardware bypass function is unavailable.
- The hardware bypass function is mutually exclusive with the optical interface function of the combo port. When the combo port works as an optical interface, its electrical interface cannot be used as a bypass interface, and the hardware bypass function cannot be configured. When the hardware bypass function is configured on the electrical interface, the combo port cannot be switched to the optical interface mode. You must delete the hardware bypass configuration first.
- The connection of the bypass interfaces is to directly connect the two links physically. When the interfaces are in the bypass state, the device cannot process the Layer 3 services such as routing and NAT on the traffic. Therefore, the hardware bypass function is only applicable to Layer 2 networking.
- The hardware bypass function is not suitable for hot standby networking, because hot standby is a more reliable technology than hardware bypass. When active device is abnormal, services can be switched to standby device to continue security processing.