what's the difference between VLAN-interface and L3-subinterface?

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

what's the difference between VLAN-interface and L3-subinterface?

Not applicable

hi all,

can you please explain exact difference between the VLAN-interface and L3-subinterface. i've read the forum and saw some docs but i'm still confused with it.


L4 Transporter

The L3 subinterface is for router-on-a-stick/trunking configurations. You could use one switch with three different VLANs and trunk them all back to one interface using an ethernet cable. The alternative would be to buy three switches and use three different interfaces on your firewall. It's cost savings/easy configuration/less cabling.

I haven't done anything with a PAN devices in L2 yet. I think you can group interfaces together that way.

i knew it! Smiley Wink

the Q is still open. is VLAN-interface analog to SVI interface in cisco catalysts or not? so i can point two or more phisical ports (L2 type) to ONE vlan and make VLAN-interface for routing. am i right?

someone! explain, plz

You can do this, BUT we do not recommend it for most environments.

Debugging traffic flows is more involved when you set up multiple L2 interfaces and use VLAN interfaces.

Let's take a look at the two scenarios:

scenario 1:

L3 interface with multiple 802.1q tagged subinterfaces

sessions on the firewall show up with the subinterfaces as ingress and egress (via the show session info command or via the details on the web UI).

scenario 2:

L2 interfaces and VLAN interfaces

sessions on firewall show up with the L2 interfaces as the ingress and egress interface. VLAN interfaces do not show up as ingress or egress interface.

In scenario 1 when you want to verify a traffic flow you check the details on a session to validate that the ingress and egress interfaces are correct.

In scenario 2 you must use the debug commands to debug traffic flow. Using the debug commands is a non-trivial activity and if done improperly can cause resource exhaustion on the dataplane.

many thks for clear answer.

  • 5 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!