There is no rule governing when to use one approach over the other. Instead, consider the most common uses of each:
- VLAN sub-interfaces are most common when the customer has grouped like systems by VLANs and the Sensor resides at an aggregation point on the network. You can obviously only take advantage of VLAN sub-interfaces when the traffic in question is trunked VLAN tagged.
- Bridge VLAN sub-interfaces, however, have a specific use. This is applicable only for M-series and NS-series Sensors deployed in in-line mode. You use this feature to subject all inter-VLAN traffic to IPS using the minimal number of Sensors.
- CIDR sub-interfaces have a specific use. You can create sub-interfaces and then allocate policies to them.