Let us learn to configure a sub-interface.
| Where Can I Use
This? | What Do I
Need? |
- Prisma SD-WAN (Managed by Strata Cloud Manager)
|
|
You can create sub-interfaces on physical and use bypass pairs for Local Area Networks (LANs) and
private and public Wide Area Networks (WANs). A sub-interface is created by dividing
one physical interface into multiple virtual interfaces.
The parent interface can be an Ethernet port,
a virtual port, or a bypass pair that does not contain any configuration.
You cannot configure a sub-interface on the controller port or any
interfaces or bypass pairs already configured with loopback as a
member with PPPoE or standard VPNs.
- If the sub-interface
is on a bypass pair and the sub-interface is used for internet or
private WAN, then the sub-interface is created on the bypass pair's
WAN port.
- If the sub-interface is on a bypass pair and the sub-interface
is used for LAN, then the sub-interface is created on the LAN port of
the bypass pair.
Multiple sub-interfaces may be configured
on a physical or virtual interface or bypass pairs. If multiple
interfaces are configured, a VLAN ID is required to create and uniquely
identify each sub-interface.
Pre-5.1.x device releases,
LAN sub-interfaces may only be used for the following branch services. Release
5.1.1 and later device releases enable LAN sub-interfaces to
forward user and application traffic in addition to the following
branch services.
- DHCP Server
- DHCP Relay
- DHCP Relay source interface
- SNMP Agent
- SNMP Trap source interface
- Ping to and from the interface IP
- Secure Socket Shell (SSH) access to the ION device CLI commands
You
cannot configure a Virtual Interface (VI) on a sub-interface. DHCP
Relay and DHCP server cannot be configured on the same sub-interface.
DHCP Relay when configured on a sub-interface:
- Can listen
to broadcast and unicast DHCP requests.
- Can use the sub-interface as the source interface to reach DHCP
servers.
When SNMP is configured on a sub-interface:
- An SNMP Agent can listen to unicast requests.
- An SNMP Trap can use the sub-interface as the source interface
to reach SNMP servers.
When Virtual Routing and Forwarding tables (VRF) is configured
on a sub-interface:
- Select LAN type interface for branch sites.
- Select Peer with the Network for data center sites.