The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

CIDR interface

Prev Next

When running a CIDR interface in SPAN mode, the Sensor uses the following logic to determine direction and VIDS ID:

  • When a SYN packet arrives on a SPAN port, the Sensor compares its CIDR sub-interfaces against the destination IP address in the SYN packet.

  • If there is a match, the entire flow is considered inbound and the Sensor stores the VIDS ID of the matched CIDR sub-interface.

  • If there is no match, the Sensor compares its CIDR sub-interfaces against the source IP address in the SYN packet.

  • If there is a match, the entire flow is considered outbound and the Sensor stores the VIDS ID of the matched CIDR sub-interface.

  • If there is no match, the entire flow is considered inbound and the Sensor stores the VIDS ID of the parent interface.