4-32
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter4 Configuring Interfaces
Configuring VLAN Group Mode
b.
Verify the settings.
sensor(config-int-phy-vla-sub)# show settings
subinterface-number: 1
-----------------------------------------------
description: <defaulted>
vlans
-----------------------------------------------
range: 1,5-8,10-15
-----------------------------------------------
-----------------------------------------------
sensor(config-int-phy-vla-sub)#
c.
Configure unassigned VLANs.
sensor(config-int-phy-vla-sub)# vlans unassigned
sensor(config-int-phy-vla-sub)#
d.
Verify the settings.
sensor(config-int-phy-vla-sub)# show settings
subinterface-number: 1
-----------------------------------------------
description: <defaulted>
vlans
-----------------------------------------------
unassigned
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
sensor(config-int-phy-vla-sub)#
Note
Assigning the unassigned VLANs to a separate virtual sensor allows you to specify a policy
for all VLANs that you have not specifically assigned to other groups. For example, you can
group your important internal VLANs in one group and apply a stringent security policy to
that group. You can group the other less important unassigned VLANs into another group,
and apply the default security policy to that group, so that only very serious alerts are
reported.
Step 13
Add a description for the VLAN group.
sensor(config-int-phy-inl-sub)# description INT1 vlans 52 and 53
Step 14
Verify the VLAN group settings.
sensor(config-int-phy-vla-sub)# show settings
subinterface-number: 1
-----------------------------------------------
description: GROUP1 default:
vlans
-----------------------------------------------
unassigned
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
sensor(config-int-phy-vla-sub)#