When running a CIDR interface in SPAN mode, the Sensor uses the following logic to determine direction and VIDS ID:
When a SYN packet arrives on a SPAN port, the Sensor compares its CIDR sub-interfaces against the destination IP address in the SYN packet.
If there is a match, the entire flow is considered inbound and the Sensor stores the VIDS ID of the matched CIDR sub-interface.
If there is no match, the Sensor compares its CIDR sub-interfaces against the source IP address in the SYN packet.
If there is a match, the entire flow is considered outbound and the Sensor stores the VIDS ID of the matched CIDR sub-interface.
If there is no match, the entire flow is considered inbound and the Sensor stores the VIDS ID of the parent interface.