Sensors by default inspect double VLAN tagged traffic for attacks. There is no additional configuration required for inspecting double VLAN tagged traffic.
For double VLAN tagged frames, Trellix IPS uses the VLAN ID in the outer tag (CID). A Sensor uses the outer VLAN tag for identifying the VLAN subinterface the traffic belongs to. For such traffic, only the outer VLAN tag is displayed in the alerts, dashboard, reports and so on.
Note
Trellix IPS supports attack detection for double VLAN tagged frames having Ethernet type as 0x8100 in the outer VLAN tag. Frames having outer VLAN tag with other possible Ethernet type values (0x9100 and 0x9200) will be forwarded without parsing for attack detection.
NS-series Sensor models can inspect double VLAN tagged traffic for attacks.