If there is VLAN,Bridge VLAN or CIDR traffic transmitting across a monitored segment, you can create one or more sub-interfaces. Before creating a sub-interface, the "Interface Type" must be set to VLAN or CIDR in Managing an interface, and you must have already entered VLAN or CIDR IDs.
Note
If you entered IDs that do not flow in the monitored link, the parent interface's policy protects all traffic.
Note
Before creating sub-interfaces, it is important to note that you will not be able to perform the Manage DoS IDs action at the interface level once a sub-interface is created. If you create a sub-interface, then you must utilize Manage DoS IDs at the sub-interface level.
If you added more than one VLAN or CIDR ID to an interface, you can create a sub-interface with one or multiple IDs or you can create multiple sub-interfaces. To create more than one sub-interface, you must repeat the steps that follow.
For a standalone Sensor, select Devices → <Admin Domain Name> → Devices → <Device Name> → IPS Interfaces → <Interface_Name> → Sub-interfaces.
For Sensors in a stack, select Devices → <Admin Domain Name> → Devices → <Device Name> → IPS Interfaces → <Stackname-node id> → <Interface_Name> → Sub-interfaces.
Manage Sub-Interface.png)
Click
.Note
To edit an existing sub-interface, select the sub-interface and click
; then follow the steps below. To delete a sub-interface, select the sub-interface and click
; then confirm the deletion.Type a Sub-interface Name.
Select a policy (Policy Name) to be enforced on the sub-interface(s).
Create Sub-Interface - CIDR.png)
Do one of the following:
For VLAN and Bridge VLAN, move an ID from "Available" to "Allocated" by selecting the ID and clicking the
button.For CIDR, type the network IP Address in the text box provided and the mask length value in the box provided after the forward slash, and click Add to List. A valid CIDR can be from the list you entered on clicking
at IPS Interfaces → Interface_Name (For Sensors in stack, IPS Interfaces → <Stackname-node id> → Interface_Name), or a CIDR host(s) within a network in your entered list. For example, if you had entered 192.168.3.0/24, you can enter 192.168.3.1/32 and 192.168.3.2/32 here for sub-interface creation.Note
If you are creating another sub-interface from a CIDR address that has not been allocated, you can check to see which have already been allocated by clicking List of Allocated CIDRs.
Click Save.
The new sub-interface appears in the Sub-Interfaces list table as well as under IPS Interfaces as a node under the interface node within which it was created.
Download the changes to your Sensor by clicking Deploy Pending Changes.