Explains how enhanced policy-based routing on Bridge Virtual Interfaces applies ingress security policies and traffic steering to Layer 2 traffic before Layer 3 routing.
Enhanced Policy-Based Routing (ePBR) on Bridge Virtual Interface (BVI) is a routing feature that
-
applies ingress security policies and traffic steering to Layer 2 traffic entering a Provider Edge (PE) router through a BVI
-
processes packets before they are routed to a Layer 3 interface, and
-
provides granular control over traffic handling through dedicated redirect, drop, and transmit actions.
| Feature Name |
Release Information |
Feature Description |
|---|---|---|
| ePBR on BVI |
Release 26.1.1 | Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100, K100]) (select variants only*); Centralized Systems (8400 [ASIC: K100]) (select variants only*); Modular Systems (8800 [LC ASIC: P100]) (select variants only*) You can ensure secure and efficient traffic handling at the network ingress by applying ePBR policies directly to the BVI. This feature allows the Cisco IOS XR software to intercept and steer inbound Layer 2 traffic before it transitions to Layer 3 routing. *This feature is supported on:
|
The ePBR on BVI feature allows you to apply ingress security policies and traffic steering to Layer 2 traffic entering a PE router from a VPN through a BVI before it is routed to a Layer 3 interface.
By applying ePBR policies to a BVI, you can:
-
Redirect: Forward traffic to a specific next-hop, bypassing the standard routing table.
-
Drop: Discard malicious or unauthorized traffic at the ingress interface.
-
Transmit: Explicitly permit traffic to follow standard routing table lookups.
For more information on ePRB, see ePBR drop and transmit actions.