Most Sensor-based IPS products permit you to apply only one security policy for the entire Sensor. Typically these one-policy Sensors also have only one port which cannot be segmented for more granular policy application. However, if you have multiple segments to monitor or you need to monitor aggregated traffic — like on Gigabit uplinks — a multi-port box and more granularity in the inspection process makes for a much more cost-effective and efficient security solution. Sensor appliances have multiple ports coupled with multiple policy application options. Thus, Trellix IPS offers Virtual IDS (VIDS) and Virtual IPS (VIPS).
To make use of virtualization, consider that a Sensor is made of the following resources:
Sensor itself as a whole
Sensor monitoring ports
Interfaces
Sub-interfaces
The VIPS feature enables you to configure multiple policies for multiple unique environments and traffic directions all monitored with a single Sensor. The goal of virtualization is scanning granularity. Virtualization allows you to apply multiple policies to traffic flowing through a single interface. In this way, a unique scanning policy can be applied to a single host or group of hosts, when their traffic will not travel through a unique Sensor port.
For example, suppose port G3/1 of an NS9500 Sensor is connected to the SPAN port on a switch. Port G3/1 is configured with a specific environment detection policy. The rest of the ports on the Sensor can have policies completely different than the policy on G3/1, or they can use the same policy. In this case, each monitoring port of the Sensor is an interface. The other option is to segment each monitoring port by multiple VLAN tags or CIDR addresses, each customized with its own security policy. In this case, each monitoring port is segmented into virtual sub-interfaces.