Multi-port Sensors support multiple applied IPS policies for interfaces and subinterfaces. This is particularly useful if you have segmented your network traffic by VLAN tags or CIDR addressing. For this scenario, the sample network has been segmented by CIDR addressing. Your Sensor monitors traffic to three networks from an aggregation point. By using Trellix IPS's multiple policy functionality, you can apply appropriate policies to individual networks, thus tuning out alerts for traffic rarely seen in those network segments. This "tuning out" dramatically reduces the number of alerts you see, thus positively affecting your total cost of ownership of a Trellix IPS solution.
You designate port pair G0/1-G0/2 to be a CIDR interface.
The Default Prevention policy is inherited from the admin domain and enforced across the entire interface.
You add three CIDR network addresses to your interface:
192.168.0.0/24: multiple file servers
192.168.1.0/24: multiple file servers
192.168.2.0/24: multiple Windows servers
You create a subinterface, File_Servers, to protect networks 192.168.0.0/24 and 192.168.1.0/24 with a more appropriate policy. You create a File Server policy to protect File_Servers.
Tip
The name File_Servers is used instead of a generic name, such as Sub-interface1, because a unique name describing the subinterface environment is more effective for later identification.
You create another subinterface, Windows_Servers to protect 192.168.2.0/24 with a more appropriate policy. You create a Windows Server policy to protect Windows_Servers.
All interface traffic through port pair G0/1-G0/2 that is not a part of the two subinterfaces mentioned is protected by the Default Prevention policy. The File Server policy is most effective for File_Servers because both networks consist of multiple file servers, and it is specifically tuned to known file server traffic elements. In the same way, the Windows Server policy is most effective for Windows_Servers because this policy is specifically tuned for Windows server traffic. Either of these policies can be cloned and customized, for example, to remove attacks that may be generating false positives and/or to set an automatic response upon detection of specific attacks.