4-21
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter4 Configuring Interfaces
Configuring Inline VLAN Pair Mode
Configuring Inline VLAN Pair Mode
This section describes inline VLAN pair mode and how to configure inline VLAN pairs. It contains the
following topics:
Understanding Inline VLAN Pair Mode, page 4-21
Configuring Inline VLAN Pairs, page 4-22

Understanding Inline VLAN Pair Mode

Note
The ASAIPS modules (ASA 5500-X IPS SSP and ASA 5585-X IPS SSP) do not support inline VLAN
pairs.
You can associate VLANs in pairs on a physical interface. This is known as inline VLAN pair mode.
Packets received on one of the paired VLANs are analyzed and then forwarded to the other VLAN in the
pair.
Inline VLAN pair mode is an active sensing mode where a sensing interface acts as an 802.1q trunk port,
and the sensor performs VLAN bridging between pairs o f VLANs on the trunk. The sensor inspects the
traffic it receives on each VLAN in each pair, and can either forward the packets on the other VLAN in
the pair, or drop the packet if an intrusion attempt is detected. You can configure an IPS sensor to
simultaneously bridge up to 255 VLAN pairs on each sensing inter face. The sensor replaces the
VLAN ID field in the 802.1q header of each rece ived packet with the ID of the egress VLAN on which
the sensor forwards the packet. The sensor drops all packets received on any VLANs that are not
assigned to inline VLAN pairs.
Note
You cannot use the default VLAN as one of the paired VLANs in an inline VLAN pair.
Figure 4-3 illustrates inline VLAN pair mode:
Figure 4-3 Inline VLAN Pair Mode
Host
Sensor
Switch
253445
Router
VLAN B VLAN A
Pairing VLAN A and B
Trunk port carrying
VLAN A and B