Configure a Sub-Interface
Table of Contents
Expand all | Collapse all
-
-
- Add a Branch
- Add a Data Center
- Add a Branch Gateway
- Configure Circuits
- Configure Internet Circuit Underlay Link Aggregation
- Configure Private WAN Underlay Link Quality Aggregation
- Configure Circuit Categories
- Configure Device Initiated Connections for Circuits
- Add Public IP LAN Address to Enterprise Prefixes
- Manage Data Center Clusters
- Configure a Site Prefix
- Configure a DHCP Server
- Configure NTP for Prisma SD-WAN
- Configure the ION Device at a Branch Site
- Configure the ION Device at a Data Center
- Switch a Site to Control Mode
- Allow IP Addresses in Firewall Configuration
-
- Configure a Controller Port
- Configure Internet Ports
- Configure WAN/LAN Ports
- Configure a Loopback Interface
- Configure a PoE Port
- Configure and Monitor LLDP Activity and Status
- Configure a PPPoE Interface
- Configure a Layer 3 LAN Interface
- Configure Application Reachability Probes
- Configure a Secondary IP Address
- Configure a Static ARP
- Configure a DHCP Relay
- Configure IP Directed Broadcast
- VPN Keep-Alives
-
- Configure Prisma SD-WAN IPFIX
- Configure IPFIX Profiles and Templates
- Configure and Attach a Collector Context to a Device Interface in IPFIX
- Configure and Attach a Filter Context to a Device Interface in IPFIX
- Configure Global and Local IPFIX Prefixes
- Flow Information Elements
- Options Information Elements
- Configure the DNS Service on the Prisma SD-WAN Interface
- Configure SNMP
-
-
- Prisma SD-WAN Branch Routing
- Prisma SD-WAN Data Center Routing
-
- Configure Multicast
- Create a WAN Multicast Configuration Profile
- Assign WAN Multicast Configuration Profiles to Branch Sites
- Configure a Multicast Source at a Branch Site
- Configure Global Multicast Parameters
- Configure a Multicast Static Rendezvous Point (RP)
- Learn Rendezvous Points (RPs) Dynamically
- View LAN Statistics for Multicast
- View WAN Statistics for Multicast
- View IGMP Membership
- View the Multicast Route Table
- View Multicast Flow Statistics
- View Routing Statistics
- Prisma SD-WAN Incident Policies
-
- Prisma SD-WAN Branch HA Key Concepts
- Configure Branch HA
- Configure HA Groups
- Add ION Devices to HA Groups
- View Device Configuration of HA Groups
- Edit HA Groups and Group Membership
-
- Configure Branch HA with Gen-1 Platforms (2000, 3000, 7000, and 9000)
- Configure Branch HA with Gen-2 Platforms (3200, 5200, and 9200)
- Configure Branch HA with Gen-2 Embedded Switch Platforms (1200-S or 3200-L2)
- Configure Branch HA for Devices with Software Cellular Bypass (1200-S-C-5G)
- Configure Branch HA for Platforms without Bypass Pairs
- Prisma SD-WAN Clarity Reports
- Prisma SD-WAN Incidents and Alerts
Configure a Sub-Interface
Let us learn to configure a sub-interface.
Where Can I Use
This? | What Do I
Need? |
---|---|
|
|
You can create sub-interfaces on physical
or virtual interfaces and use bypass pairs for Local Area Networks (LANs)
and private and public Wide Area Networks (WANs). A sub-interface
is created by dividing one physical interface into multiple virtual
interfaces.
The parent interface can be an Ethernet port,
a virtual port, or a bypass pair that does not contain any configuration.
You cannot configure a sub-interface on the controller port or any
interfaces or bypass pairs already configured with loopback as a
member with PPPoE or standard VPNs.
- If the sub-interface is on a bypass pair and the sub-interface is used for internet or private WAN, then the sub-interface is created on the bypass pair's WAN port.
- If the sub-interface is on a bypass pair and the sub-interface is used for LAN, then the sub-interface is created on the LAN port of the bypass pair.
Multiple sub-interfaces may be configured
on a physical or virtual interface or bypass pairs. If multiple
interfaces are configured, a VLAN ID is required to create and uniquely
identify each sub-interface.
Pre-5.1.x
device releases,
LAN sub-interfaces may only be used for the following branch services. Release
5.1.1 and later
device releases enable LAN sub-interfaces to
forward user and application traffic in addition to the following
branch services.- DHCP Server
- DHCP Relay
- DHCP Relay source interface
- SNMP Agent
- SNMP Trap source interface
- Ping to and from the interface IP
- Secure Socket Shell (SSH) access to the ION device CLI commands
You
cannot configure a Virtual Interface (VI) on a sub-interface. DHCP
Relay and DHCP server cannot be configured on the same sub-interface.
DHCP Relay when configured on a sub-interface:
- Can listen to broadcast and unicast DHCP requests.
- Can use the sub-interface as the source interface to reach DHCP servers.
When SNMP is configured on a sub-interface:
- An SNMP Agent can listen to unicast requests.
- An SNMP Trap can use the sub-interface as the source interface to reach SNMP servers.
When Virtual Routing and Forwarding tables (VRF) is configured
on a sub-interface:
- SelectLANtype interface for branch sites.
- SelectPeer with the Networkfor data center sites.
- Select, select the device you want to configure.WorkflowsDevicesClaimed Devices
- Select theInterfacestab.
- Select a port.
- ForAdmin Up, selectYes.
- (Optional)Enter aDescription.
- LeaveUse This Port ToandIPv4 Configurationblank.
- ForVRF, selectGlobalor any other custom VRF listed. VRF Global is enabled only when the associated device supports VRF.Currently, VRF supports LAN. Configure the sub-interface individually, as the sub-interface configurations don’t inherit from the parent interface.
- Save Port.
- Click theSub-Interfacestab.
- Select+ Add Sub-Interfaceto create a new sub-interface.
- ForAdmin Up, selectYes.
- (Optional)Enter aDescription.
- FromUse This Sub-Interface Todrop-down, select the option applicable to the interface you are configuring;Connect to Internet, orPeer with a Network.
- ForCircuit Label, select circuits and clickDone.
- Enter aVLAN ID.The VLAN ID can be updated or changed.
- Mark the Native VLAN box if the identified sub-interface is used for native VLAN.Only one sub-interface of a parent interface can be configured for native VLAN. By default, the native VLAN box is unchecked.DNS Servers need to be entered for Internet and Private WAN but not for LAN.
- (Optional)If DHCP Relay functions are required, chooseDHCPfor theConfigurationfield. ChangeAdd DHCP RelayfromNotoYes.
- SelectCreate Sub-Interface.The following use case shows a topology in which a sub-interface is used for the MPLS connection to the provider router on the WAN side. On the LAN side, there is a trunk interface with 2 VLANs (user and server) connected to a LAN switch.The interface configuration summary for the above topology is as follows:Detailed configuration for LAN sub-interface 3.100Detailed configuration for LAN sub-interface 3.101Detailed configuration for WAN sub-interface 2.200