The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How Trellix IPS handles double VLAN tagged traffic?

Prev Next

Sensors by default inspect double VLAN tagged traffic for attacks. There is no additional configuration required for inspecting double VLAN tagged traffic.

For double VLAN tagged frames, Trellix IPS uses the VLAN ID in the outer tag (CID). A Sensor uses the outer VLAN tag for identifying the VLAN subinterface the traffic belongs to. For such traffic, only the outer VLAN tag is displayed in the alerts, dashboard, reports and so on.

Note

Trellix IPS supports attack detection for double VLAN tagged frames having Ethernet type as 0x8100 in the outer VLAN tag. Frames having outer VLAN tag with other possible Ethernet type values (0x9100 and 0x9200) will be forwarded without parsing for attack detection.

NS-series Sensor models can inspect double VLAN tagged traffic for attacks.