The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sub-interfaces

Prev Next

If the same port on which the SYN packet arrives is instead associated with a VLAN or CIDR interface, the Sensor applies the same logic to determine the direction of the flow, but must do additional work to determine the VIDS ID.

If the interface type is VLAN, the Sensor compares the VLAN tag in the SYN packet against all previously defined VLAN IDs to determine the sub-interface to which the flow belongs.

  • If the Sensor matches the VLAN in the SYN tag packet with one of its VLAN IDs, it stores the VIDS ID of the matching sub-interface in its state table.

  • If the Sensor does not match the VLAN tag in the SYN packet with one of its VLAN IDs, it stores the VIDS ID associated with the parent interface instead.

If the interface type is CIDR, the Sensor uses the direction of the flow to determine the sub-interface to which the flow belongs.

  • If the flow is inbound, the Sensor compares the destination IP address of the SYN packet against its CIDR sub-interfaces.

  • If there is a match, the Sensor stores the VIDS ID associated with the matched CIDR sub-interface.

  • Otherwise, it stores the VIDS ID associated with the parent interface.

  • If the flow is outbound, the Sensor compares the source IP address of the SYN packet against its CIDR sub-interfaces.

  • If there is a match, the Sensor stores the VIDS ID associated with the matched CIDR sub-interface.

  • Otherwise, it stores the VIDS ID associated with the parent interface.