The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

3. Configure fail-open switch parameters

Prev Next

Prerequisites:

To proceed with the setup, you will require:

  • One RJ-11 RS-232 cable

  • One RJ-45 cable

Perform the following steps to configure the parameters of the fail-open switch.

  1. Connect the applicable cables to the fail-open switch.

  2. Connect the other end to a computer which runs a terminal emulation software such as HyperTerminal or PuTTY.

  3. Launch the terminal emulation software, and set the communications parameters as shown below:

    • Baud rate: 9600

    • Data bits: 8

    • No parity

    • Stop bits: 1

    • No flow control

  4. Turn on the fail-open switch.

    The CLI banner and login prompt are displayed.

  5. At the login prompt, type the username and password, and press Enter.

    Username and password for both sets of fail-open switches

    For fail-open switches 6 thru 10

    Username

    Trellix00

    Password

    Trellix00



    The fail-open switch CLI prompt is displayed.

  6. Use these commands for fail-open switch models 6 thru 10.

    CLI commands for fail-open switch models 6 thru 10

    Command

    Description

    set_ip xxx.xxx.xxx.xxx

    Configures fail-open switch IPv4 address.

    Reboot the fail-open switch for the new IPv4 address to take effect.

    get_ip

    Displays fail-open switch IPv4 address.

    set_netmask xxx.xxx.xxx.xxx

    Configures fail-open switch subnet mask.

    Reboot the fail-open switch for the new subnet mask to take effect.

    get_netmask

    Displays fail-open switch subnet mask.

    set_gateway xxx.xxx.xxx.xxx

    Configures default gateway IPv4 address.

    Reboot the fail-open switch for the new gateway IPv4 address to take effect.

    get_gateway

    Displays default gateway address.

    set_link <port> <on/off>

    Sets the port of a 1G Copper fail-open switch to auto-negotiate.

    For the <port> use mon0, mon1, net0, or net1.

    get_link <port>

    Displays port status.

    For the <port> use mon0, mon1, net0, or net1.

    set_link <port> off fd 100m

    Sets the port to 100 Mbps full-duplex.

    For the <port>, use the syntaxes specified above.

    set_link <port> <enable/disable>_autoneg

    Sets the port of a 1G Fiber fail-open switch to auto-negotiate.

    For the <port> use mon0, mon1, net0, or net1.

    Note

    10G Fiber fail-open switches do not have such a command since auto-negotiate is enabled by default.

    set_ssh_state <on/off>

    Enables or disables the SSH status on the fail-open switch.

    get_ssh_state

    Displays the SSH status, which is enabled by default.

    set_web_https_state <on/off>

    Enables or disables web access to the fail-open switch interface.

    get_web_https_state

    Displays status of web access to the fail-open switch interface.

    set_snmp_srv_ip

    Configures SNMP server IPv4 address.

    The SNMP server IPv4 address can also be set in the web interface.

    get_snmp_srv_ip

    Displays the SNMP server IPv4 address.

    set_trap <parameter> <on/off>

    Enables or disables the following SNMP traps:

    • appl fail – Application state change.

    • bypass – Bypass state change trap.

    • mon link – Monitoring port state change trap.

    • net link – Network port state change trap.

    • error – Error notification trap.

    • update – Update complete trap.

    get_stat

    Displays the statistics of the fail-open switch.

    get_params

    Displays fail-open switch parameters.

    stop_all_sessions

    Stops all opened sessions