For When You Can't Have The Real Thing
VLAN interfaces

Created by dave. Last edited by dave, 13 years and 152 days ago. Viewed 4,537 times. #4
Creating VLAN interfaces

(20 December 2010, ScreenOS 6.2)

This is stupid-simple, but I always forget exactly how to do it. There's always the temptation to set up the security zone and interface as a VLAN type, but that's wrong.


Create your new security zone as a layer-3 security zone.

Go to the interfaces page.

Select New SubInterface.

On this screen you can now set:

  • the physical interface (or bgroup) to use
  • the VID
  • the security zone (which you created above)
  • IP and management information for the interface (usually I don't have a management IP, and enable only ICMP management)
Tag up the switchport which is connected to the physical interface in use, set your policies, and you should be good to go.
