Configure a Sub-Interface
Table of Contents
Expand all | Collapse all
-
-
- Add a Branch
- Add a Data Center
- Add a Branch Gateway
- Configure Circuits
- Configure Internet Circuit Underlay Link Aggregation
- Configure Private WAN Underlay Link Quality Aggregation
- Configure Circuit Categories
- Configure Device Initiated Connections for Circuits
- Add Public IP LAN Address to Enterprise Prefixes
- Manage Data Center Clusters
- Configure a Site Prefix
- Configure a DHCP Server
- Configure NTP for Prisma SD-WAN
- Configure the ION Device at a Branch Site
- Configure the ION Device at a Data Center
- Switch a Site to Control Mode
- Allow IP Addresses in Firewall Configuration
-
- Configure a Controller Port
- Configure Internet Ports
- Configure WAN/LAN Ports
- Configure a Loopback Interface
- Configure a PoE Port
- Configure and Monitor LLDP Activity and Status
- Configure a PPPoE Interface
- Configure a Layer 3 LAN Interface
- Configure Application Reachability Probes
- Configure a Secondary IP Address
- Configure a Static ARP
- Configure a DHCP Relay
- Configure IP Directed Broadcast
- VPN Keep-Alives
-
- Configure Prisma SD-WAN IPFIX
- Configure IPFIX Profiles and Templates
- Configure and Attach a Collector Context to a Device Interface in IPFIX
- Configure and Attach a Filter Context to a Device Interface in IPFIX
- Configure Global and Local IPFIX Prefixes
- Flow Information Elements
- Options Information Elements
- Configure the DNS Service on the Prisma SD-WAN Interface
- Configure SNMP
-
-
- Prisma SD-WAN Branch Routing
- Prisma SD-WAN Data Center Routing
-
- Configure Multicast
- Create a WAN Multicast Configuration Profile
- Assign WAN Multicast Configuration Profiles to Branch Sites
- Configure a Multicast Source at a Branch Site
- Configure Global Multicast Parameters
- Configure a Multicast Static Rendezvous Point (RP)
- Learn Rendezvous Points (RPs) Dynamically
- View LAN Statistics for Multicast
- View WAN Statistics for Multicast
- View IGMP Membership
- View the Multicast Route Table
- View Multicast Flow Statistics
- View Routing Statistics
- Prisma SD-WAN Incident Policies
-
- Prisma SD-WAN Branch HA Key Concepts
- Configure Branch HA
- Configure HA Groups
- Add ION Devices to HA Groups
- View Device Configuration of HA Groups
- Edit HA Groups and Group Membership
-
- Configure Branch HA with Gen-1 Platforms (2000, 3000, 7000, and 9000)
- Configure Branch HA with Gen-2 Platforms (3200, 5200, and 9200)
- Configure Branch HA with Gen-2 Embedded Switch Platforms (1200-S or 3200-L2)
- Configure Branch HA for Devices with Software Cellular Bypass (1200-S-C-5G)
- Configure Branch HA for Platforms without Bypass Pairs
- Configure Branch HA in a Hybrid Topology with Gen-1 (3000) and Gen-2 (3200) Platforms
- Prisma SD-WAN Incidents and Alerts
Configure a Sub-Interface
Let us learn to configure a sub-interface.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
You can create sub-interfaces on physical
or virtual interfaces and use bypass pairs for Local Area Networks (LANs)
and private and public Wide Area Networks (WANs). A sub-interface
is created by dividing one physical interface into multiple virtual
interfaces.
The parent interface can be an Ethernet port,
a virtual port, or a bypass pair that does not contain any configuration.
You cannot configure a sub-interface on the controller port or any
interfaces or bypass pairs already configured with loopback as a
member with PPPoE or standard VPNs.
- If the sub-interface is on a bypass pair and the sub-interface is used for internet or private WAN, then the sub-interface is created on the bypass pair's WAN port.
- If the sub-interface is on a bypass pair and the sub-interface is used for LAN, then the sub-interface is created on the LAN port of the bypass pair.
Multiple sub-interfaces may be configured
on a physical or virtual interface or bypass pairs. If multiple
interfaces are configured, a VLAN ID is required to create and uniquely
identify each sub-interface.
Pre-5.1.x device releases,
LAN sub-interfaces may only be used for the following branch services. Release
5.1.1 and later device releases enable LAN sub-interfaces to
forward user and application traffic in addition to the following
branch services.
- DHCP Server
- DHCP Relay
- DHCP Relay source interface
- SNMP Agent
- SNMP Trap source interface
- Ping to and from the interface IP
- Secure Socket Shell (SSH) access to the ION device CLI commands
You
cannot configure a Virtual Interface (VI) on a sub-interface. DHCP
Relay and DHCP server cannot be configured on the same sub-interface.
DHCP Relay when configured on a sub-interface:
- Can listen to broadcast and unicast DHCP requests.
- Can use the sub-interface as the source interface to reach DHCP servers.
When SNMP is configured on a sub-interface:
- An SNMP Agent can listen to unicast requests.
- An SNMP Trap can use the sub-interface as the source interface to reach SNMP servers.
When Virtual Routing and Forwarding tables (VRF) is configured
on a sub-interface:
- Select LAN type interface for branch sites.
- Select Peer with the Network for data center sites.
- Select WorkflowsDevicesClaimed Devices, select the device you want to configure.Select the Interfaces tab.Select a port.For Admin Up, select Yes.(Optional) Enter a Description.Leave Use This Port To and IPv4 Configuration blank.For VRF, select Global or any other custom VRF listed. VRF Global is enabled only when the associated device supports VRF.Currently, VRF supports LAN. Configure the sub-interface individually, as the sub-interface configurations don’t inherit from the parent interface.Save Port.Click the Sub-Interfaces tab.Select + Add Sub-Interface to create a new sub-interface.For Admin Up, select Yes.(Optional) Enter a Description.From Use This Sub-Interface To drop-down, select the option applicable to the interface you are configuring; Connect to Internet, or Peer with a Network.For Circuit Label, select circuits and click Done.Enter a VLAN ID.The VLAN ID can be updated or changed.Mark the Native VLAN box if the identified sub-interface is used for native VLAN.Only one sub-interface of a parent interface can be configured for native VLAN. By default, the native VLAN box is unchecked.DNS Servers need to be entered for Internet and Private WAN but not for LAN.(Optional) If DHCP Relay functions are required, choose DHCP for the Configuration field. Change Add DHCP Relay from No to Yes.Select Create Sub-Interface.The following use case shows a topology in which a sub-interface is used for the MPLS connection to the provider router on the WAN side. On the LAN side, there is a trunk interface with 2 VLANs (user and server) connected to a LAN switch.The interface configuration summary for the above topology is as follows:Detailed configuration for LAN sub-interface 3.100Detailed configuration for LAN sub-interface 3.101Detailed configuration for WAN sub-interface 2.200