09-10-2021 03:57 AM
so both seems grouping of interfaces , BVI can provide connectivity by being the gateway , inline set can provide connectivity by connecting to another physical interface . what is the difference and why would i use one or the other?thanks
Solved! Go to Solution.
09-10-2021 04:18 AM
They are meant to be used in different use cases. BVIs are for firewall-implementations where you just want to have multiple interfaces (also more than two) in the same IP-network.
Inline-sets are meant to be used in a pure IPS setup. Only two interfaces can be combined, there is no routing involved, what gets in on interface 1 in the set leaves on interface 2 unless being dropped by IPS. There is also reduced functionality in LINA (the underlying ASA data-plane).
09-10-2021 04:18 AM
They are meant to be used in different use cases. BVIs are for firewall-implementations where you just want to have multiple interfaces (also more than two) in the same IP-network.
Inline-sets are meant to be used in a pure IPS setup. Only two interfaces can be combined, there is no routing involved, what gets in on interface 1 in the set leaves on interface 2 unless being dropped by IPS. There is also reduced functionality in LINA (the underlying ASA data-plane).
09-10-2021 04:45 AM
ok now it clicked , that make so much sense now , thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide