Configure the bridge virtual interface (BVI)
Configure a Bridge Virtual Interface (BVI) to provide IP addressing for each bridge group, which enables traffic routing and management functionality for the bridge group members.
Each bridge group requires a BVI for which you configure an IP address. The Firewall Threat Defense uses this IP address as the source address for packets originating from the bridge group. The BVI IP address must be on the same subnet as the connected network. For IPv4 traffic, the BVI IP address is required to pass any traffic. For IPv6 traffic, you must, at a minimum, configure the link-local addresses to pass traffic, but a global management address is recommended for full functionality, including remote management and other management operations.
For routed mode, if you provide a name for the BVI, then the BVI participates in routing. Without a name, the bridge group remains isolated as in transparent firewall mode.
Before you begin
You cannot add the BVI to a security zone; therefore, you cannot apply Access Control policies to the BVI. You must apply your policy to the bridge group member interfaces based on their zones.
Follow these steps to configure the Bridge Virtual Interface (BVI):
Procedure
Step 1 | On the Cloud-Delivered Firewall Management Center, choose and click Edit ( |
Step 2 | Choose . |
Step 3 | In the Bridge Group ID field, enter the bridge group ID between 1 and 250. |
Step 4 | In the Description field, enter a description for this bridge group. |
Step 5 | On the Interfaces tab, click an interface and then click Add to move it to the Selected Interfaces area. Repeat for all interfaces that you want to make members of the bridge group. |
Step 6 | Click the IPv4 tab. |
Step 7 | (Optional) Refer to Configure IPv6 addressing to configure IPv6 addressing. |
Step 8 | (Optional) Refer to Add a static ARP entry and Add a static MAC address and disable MAC learning for a bridge group (for transparent mode only) to configure the ARP and MAC settings. |
Step 9 | Click OK. Click Save. |
What to do next
Go to and deploy the policy to assigned devices. The changes are not active until you deploy them.