Configuring a Sensor to act as a VLAN Bridge.
Defining Bridge VLAN Interfaces: You need to change the Interface Type to Bridge VLAN.
Go to Devices → <Admin Domain Name> → Devices → <Device Name> → IPS Interfaces → <Interface_Name> → Properties.
The Properties page displays.
In the Properties page, change the Interface Type to Bridge VLAN and click OK to confirm.
Caution
When you change the Interface Type, the configurations relevant to the earlier Interface Type is lost. For example, if the Interface was of type VLAN earlier with VLAN ID list configured, the list is lost when you change this interface to Bridge VLAN.
Specifying the VLAN pairs: At the Interface level, you need to specify the VLANs that are to be bridged as a pair. For example, if you want to bridge VLANs 10 and 11, you need to specify them as a pair. Then, the Sensor tags VLAN 10 traffic as VLAN 11 before forwarding it through the peer port. Similarly, it tags VLAN 11 traffic as VLAN 10.
You can define all the VLANs that you want the Sensor to bridge now. Then, you can assign all or some of them to the Sub-Interfaces.
For each VLAN pair that you want to specify:
From the Properties page, click
.The Properties page appears.
Enter the VLAN ID and Peer VLAN ID in the corresponding fields and click Save.
Repeat the steps a and b to add more VLAN pairs.
Note
To delete a VLAN pair, select it in the Properties page and click
.Note
At a given point in time, up to 127 pairs of VLANs can be defined per VIDS. When you reach 127 VLAN pairs at the interface level, you can assign some or all of them to a Sub-Interface to be able to define more at the interface level.
Note
The VLANs should be unique within an Interface. For example, you cannot configure 20-21 and 22-21 as two VLAN pairs for one Interface.
Note
The VLAN pairs are symmetric; the VLANs are mapped with their peer IDs regardless of the Sensor port in which they are seen. The switch port connecting to the Sensor port must be configured to receive the corresponding VLAN traffic.
Updating the Sensor: After you define the Bridge VLAN interface, you must update the Sensor about this configuration change.