The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Adding or deleting port mirroring for all traffic

Prev Next

You can add or delete port mirroring for all traffic types (including SSL encrypted traffic) on the Network Securitymonitoring interface pair by using the Network Security appliance Web UI or CLI:

When you add port mirroring for all traffic types (including SSL traffic) on at least one monitoring interface pair, the Network Security appliance will forward a copy of the network traffic that it processed to another port on the same appliance that is configured in tap mode. The SSL traffic remains encrypted when it is forwarded to another analysis device. When you delete port mirroring for all traffic types on a monitoring interface pair, the Network Security appliance will not forward a copy of the traffic to a mirror port.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • A minimum of two interface pairs on the Network Security appliance

  • Specify the monitoring interface pair and the mirror port. Use the policymgr interface <interfacePair> mirror port <portName> command. Verify that the interface pair that serves as the mirror port is in tap mode. Use the show policymgr interfaces command.

    For details about how to configure a mirror port on an interface, see Configuring the Network Security appliance to forward traffic from a mirror port using the CLI.