You can allocate one or more VLAN pairs defined at the interface to a sub-interface to further refine the process.
Select Devices → <Admin Domain Name> → Devices → <Device_Name> → IPS Interfaces → <Interface_Name> → Sub-Interfaces.
The sub-interface list appears.
To allocate VLAN pairs to an existing sub-interface, click
; else click
.If you are creating the sub-interface, specify the sub-interface name and policy to be applied.
Select the required VLAN pairs from the Available VLAN IDs list and move them to the Allocated VLAN IDs list.
The Available VLAN ID list contains the VLAN pairs defined at the interface.
For the configuration shown above, if the Sensor sees traffic tagged with VLANs 10, 11, 12, or 13, it applies the corresponding policy of Finance_VLAN sub-interface. After applying this policy, if the Sensor finds traffic to be clean, it changes the VLAN tag to that of the peer VLAN and forwards it through the peer port. For example, if the traffic is tagged 12 and seen at G0/1, then tags it as VLAN 13 and forwards it through G0/2.
If the traffic seen at an interface is tagged with a VLAN defined at the Interface level but not allocated to a Sub-Interface, then the Sensor applies the policy specified for the Interface and also changes the VLAN tag to that of its peer.
Updating the Sensor: After you allocate VLAN pairs to sub-interfaces, you must update the Sensor about this configuration change.