In software versions 9.7 and later, individual ports can be combined into bridge groups that make them act like switch ports on the same logical network. In this way, multiple devices can be connected directly to the ASA 5506-X in the DMZ and inside logical networks. This is done by configuring the ports in bridged virtual interfaces (BVI). The BVI is then configurated with a name, security-level, IP address and mask, and other settings. In order to permit devices on different physical interfaces, the same-security-traffic permit inter-interface global configuration command must be configured. A drawback to using BVIs is that many commands, such as no shutdown, must be configured on the individual interfaces. In addition, if an access list is to be used on the BVI, the list must be grouped with each physical interface individually.
-
-