It is also worth noting that each interface and sub-interface maintains a unique Denial-of-Service (DoS) profile. DoS policies can be applied to subsets of a sub-interface for even more granular security monitoring. These DoS profile instances are known as DoS IDs. You can monitor DoS attacks to the granularity of individual hosts. Any deviation from the established normal traffic behavior flags a DoS condition, even a situation wherein a single host/subnet downstream to a gigabit network link comes under attack—with even a couple of Mbps of traffic. The Sensor's granular DoS detection can spot the attack.
Another reason to consider creating a sub-interface for a single host is when that host tends to have traffic patterns that are significantly different from the rest of the hosts sharing the interface. An example is an e-commerce Web server as compared to internal file and print servers; the Web server will no doubt have a different traffic pattern than the file and print servers. If not isolated from the file and print servers, that one Web server is potentially skewing the calculations for the entire interface and therefore creating false positives, or even false negatives, in the DoS analysis process. By isolating that one host, you allow the Sensor to analyze the traffic destined to and originating from the file and print servers independently of the traffic to and from the Web server, and therefore increase the likelihood the analysis will be accurate.