The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Background

Prev Next

Imagine you have two hosts residing on the same VLAN and connected to two different switches, but you want them to communicate as if they were directly connected to the same switch, this includes sharing Layer 2 multicasts and broadcasts. The way to achieve this goal is to set up a trunk between the two switches.

When you enable trunking on both switches, they will pass extra information in each frame to identify the VLAN to which that frame belongs.

As a frame travels across a trunk, the receiving switch checks the VLAN ID and copies the frame to local ports in the same VLAN as if that frame had originated locally.

A switch that meets the industry-standard, IEEE 802.1Q specification for trunking will include an additional 32 bits in each frame, of which 12 of the bits are used to indicate the VLAN ID for that frame. Valid VLAN ID values are therefore between 0 and 4095 (2^12).

The actual supported VLAN ID values will vary by switch implementation. For example, VLAN 0 is generally not used, VLAN 1 is the default VLAN is used for management on Cisco switches, and many switches do not support all the way up to VLAN ID 4095 unless you use an enhanced version of software. Trellix IPS will accept values between 1 and 4095.

Note

Trellix IPS will initially accept a value of 0 in the GUI, but then discard it. For example, if you enter a range of 0 - 2, Trellix IPS will accept it, but only include VLAN IDs 1 and 2 in its configuration.

Caution

If you send trunked traffic across a device that does not specifically support trunking, that device will typically discard tagged frames as bad (too large) and communication will fail.

Note

Trellix IPS supports (passes and scans) frames meeting the 802.1Q standard. It does not, however, support Cisco's proprietary, legacy Inter-Switch Link (ISL) protocol. ISL traffic sent through a Sensor will be forwarded and would not be dropped.