How Do You Isolate BVI Traffic on a Routed FTD?

Answer Correct answer: A — Create a separate VRF for the BVI so bridge group traffic is isolated and not routed through the global routing table of the routed FTD.

A network administrator is configuring a BVI interface on a routed FTD. The administrator wants to isolate traffic on the interfaces connected to the bridge group and not have the FTD route this traffic using the routing table. What must be configured?

  1. A new VRF must be created for the BVI interface Correct Answer
  2. An IP address must be configured on the BVI
  3. IP routing must be removed from the physical interfaces connected to the BVI
  4. The BVI interface must be configured for transparent mode

Community Votes

A
58%
D
25%
B
17%

58% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you know that in routed mode the BVI — not the physical member interfaces — is the point where routing is controlled, and the trap is reaching for transparent mode or the mandatory BVI IP address as the isolation mechanism.

On a routed FTD, a BVI acts as the routed interface for a bridge group, so its traffic can still be leaked into the global routing table. Isolating the bridge group requires placing the BVI in its own VRF rather than changing firewall mode or stripping IP addresses from member interfaces.

Choosing transparent mode is the most common wrong move: candidates remember Cisco's transparent-mode bridge-group guidance and assume the FTD must be switched to transparent mode, but the scenario explicitly states the FTD is already routed and must stay routed.

Community Discussion (5 comments)

tinyJoe 👍 2 Selected: A
It's very difficut to choose, I would choose A. As for D, this FTD is already in Routed mode. I don't think changing it to Transparent is the best solution, since I assume it is already connected to multiple IP subnets. As for B, the configuration to IP addresses to the BVI is mandatory regardless of whether or not there is separation from routing. As for C, I don't understand what you mean by “IP routing must be removed”. Supplementary, the best solution is “not assigning a name to the BVI interface”. I don't understand why this is not an option. https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/760/management-center-device-config -76/device-ops-tfw.html?bookSearch=true#:~:text=not%20assigning%20a%20name
flejd 👍 2 Selected: B
Routed mode and bvi with IP address = traffic is allowed only between member interfaces ( L2 ). Routed mode and bvi with IP an NAMEIF = traffic is allowed only between member interfaces as well as routed interfaces. Nameif is enabling the routing from BVI to other L3 interfaces
Stevens0103 👍 2 Selected: A
"How to Manage Overlapping Segments in Routed Firewall Mode with BVI Interfaces" In the following example, BVI-G is configured in VRG and Bridge Group 1 is the routed interface for interfaces G0/1 and G0/2. Similarly, BVI-B is configured in VRB and Bridge Group 2 is the routed interface for interfaces G0/3 and G0/4. Consider that both BVIs have the same IP subnet address, say 10.10.10.5/24. Because of virtual routers, the network is isolated on the shared resources. https://www.cisco.com/c/dam/en/us/td/i/400001-500000/440001-450000/442001-443000/442782.jpg https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/virtual-routing-for-firepower-threat-defense.html
Dash_888 👍 3 Selected: D
I believe D is the correct answer given the below https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/fpmc-config-guide-v61_chapter_01110000.html#ID-2106-00000036 Bridge Groups in Transparent Firewall Mode Bridge group traffic is isolated from other bridge groups; traffic is not routed to another bridge group within the Firepower Threat Defense device, and traffic must exit the Firepower Threat Defense device before it is routed by an external router back to another bridge group in the Firepower Threat Defense device.
KISRUVEM 👍 3 Selected: A
I’m thinking A. Creating a VRF with just the BVI would effectively isolate it from routing.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In routed firewall mode a BVI is not a purely Layer 2 construct — it is the routed interface that represents the bridge group and it participates in the device's routing table by default. Cisco's guidance for overlapping segments in routed mode with BVI interfaces shows each BVI being assigned to its own VRF precisely so that bridge-group traffic stays local and is never forwarded according to the global routing table. Placing the BVI in a dedicated VRF gives it an isolated routing table with no other interfaces, which satisfies the administrator's requirement that the bridge-group traffic not be routed. That is exactly what option A describes, which is why it is the correct answer.

Why the Other Options Are Wrong

Option B is a real requirement for a functioning BVI, but an IP address alone does not isolate anything — it actually makes the BVI routable, which is the opposite of what the administrator wants. Option C misunderstands the architecture: the physical interfaces in a bridge group are Layer 2 members and are not given IP addresses, so there is no IP routing on them to remove; routing decisions happen at the BVI. Option D would switch the entire firewall from routed to transparent mode, which is a global mode change and contradicts the premise that this is a routed FTD handling multiple subnets.

Community Comment Notes

Dash_888 argued for transparent mode and cited a Cisco guide covering "Bridge Groups in Transparent Firewall Mode", but that material applies when the firewall itself is in transparent mode, not to a routed FTD with a BVI. tinyJoe reasoned similarly to the correct answer and pointed out that "this FTD is already in Routed mode", so converting it to transparent mode is not the right fix, while also noting the BVI IP address is mandatory regardless of isolation. Stevens0103 quoted Cisco's document "How to Manage Overlapping Segments in Routed Firewall Mode with BVI Interfaces", which is the section that actually uses a VRF per BVI. flejd added that "Nameif is enabling the routing from BVI to other L3 interfaces", reinforcing that the BVI, not the member ports, is what must be scoped away from the routing table.

Official Reference

Exam Strategy

Read the mode of the firewall first: the words "routed FTD" eliminate any transparent-mode answer immediately. Then ask which object owns the routing decision — for a bridge group it is the BVI, so look for the option that removes the BVI from the global routing table.

Frequently Asked Questions

Why doesn't the BVI's IP address isolate the bridge group by itself?

An IP address on the BVI is mandatory for it to pass traffic, but that address is what makes the BVI routable. Without a separate VRF, traffic can still be forwarded to other interfaces via the global routing table.

Can I just remove IP addresses from the physical interfaces in the bridge group?

No. Physical interfaces that are members of a bridge group are Layer 2 ports and do not hold IP addresses, so there is nothing to remove. Routing is decided at the BVI, which is why the VRF approach is used.

Related Analysis

← Back to 300-710 Study Guide