Each interface and subinterface has a unique ID called its "VIDS ID," and each VIDS ID is associated with the IPS policy that you apply to the corresponding interface or subinterface. Each IPS policy in turn, is associated with inbound and outbound attack set profiles, and each attack set profile contains a list of rules that determine whether attack definitions are to be included or excluded in your IPS policies. The Sensor must therefore track the VIDS ID and direction of each flow to eventually know which attacks (signatures, Reconnaissance, or DoS) to use when scanning it.
Note
Similar to IPS policy, a VIDS ID is associated with the other security policies that you have applied to the interface or subinterface.
Every time a new flow is established through a Sensor, information about the flow is added to the Sensor's state table. The state table includes standard connection tracking information, such as source and destination IP address/port, protocol ID, and TCP state and sequence numbers. Each state table entry also includes the VIDS ID and direction of the flow in question.
The VIDS ID and direction are determined at the outset of the connection, for example, by the SYN packet. The Sensor scans the entire flow using the attack signatures corresponding to the stored VIDS ID and direction. It does not apply the inbound attack set profile in one direction and the outbound attack set profile in the other.
The determination of VIDS ID and direction depends directly on the operational mode and interface type in question.