This topic describes how access control lists (ACLs) on a Bridge Virtual Interface (BVI) filter traffic for a group of Layer 2 interfaces.
The Bridge Virtual Interface (BVI) is a virtual interface that
-
acts as a bridge between the routing and bridging domains on a router
-
is a logical interface that operates as a regular routed interface with an IP address, and
-
enables traffic filtering through Access Control Lists (ACLs) for the network using the interface.
Feature History Table
|
Feature Name |
Release Information |
Description |
|---|---|---|
|
ACLs on BVI |
Release 26.3.1 |
Introduced in this release on: Modular Systems (8800 [LC ASIC: K100])(select variants only*) *This feature is supported on Cisco 88-LC1-48Y8F-EM line cards. |
|
Extend support for ACLs on BVI to A100-based ASICs |
Release 26.2.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100] You can now apply ACLs on Bridged Virtual Interfaces (BVIs) on A100-based ASICs. This feature allows the router to block malicious traffic that targets the router. You can apply ACLs in both ingress and egress directions on a BVI. This feature support is now extended to:
|
|
Extend support for ACLs on BVI to K100-based ASICs |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100]); Modular Systems (8800 [LC ASIC: K100]) You can now apply ACLs on Bridged Virtual Interfaces (BVIs) on K100-based ASICs. This feature allows the router to block malicious traffic that targets the router. You can apply ACLs in both ingress and egress directions on a BVI. This feature support is now extended to:
|
|
Extend support for ACLs on BVI to P100-based ASICs |
Release 25.3.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100]); Fixed Systems (8700 [ASIC: P100]); Modular Systems (8800 [LC ASIC: P100]) You can now apply ACLs on Bridged Virtual Interfaces (BVIs) on P100-based ASICs. This feature allows the router to block malicious traffic that targets the router. You can apply ACLs in both ingress and egress directions on a BVI. This feature support is now extended to:
|
|
ACLs on BVI |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100], 8700 [ASIC: K100])(select variants only*) This feature is now supported on:
|
|
ACLs on BVI |
Release 7.3.1 |
This feature allows traffic filtering by configuring ACLs on Bridge Virtual Interfaces (BVIs). A single configuration can be applied for multiple interfaces that are part of the BVI. You can therefore, filter traffic for a group of interfaces with a particular purpose. |
The Cisco 8010 Series Routers do not support this feature. For a list of supported features on the Cisco 8010 Series Routers, see Compatibility Matrix for Cisco 8010 Series Routers.
Increased TCAM consumption with configuring ACLs on BVIs
The consumption of TCAM resources is impacted in the following manner when ACLs are configured on BVIs:
-
When an ACL is attached to a BVI interface, TCAM entries are programmed on all line cards regardless of physical interface membership. This process leads to greater consumption of TCAM resources even on line cards that do not have BVI member interfaces.
-
For ingress and egress ACLs, the TCAM entries for the same ACL are shared across interfaces on the same NPU.