The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Adding or deleting rules to a network policy for SSL interception using the CLI

Prev Next

Use the commands in this section to add a rule to a network policy based on the IPv4 or IPv6 address and mask length or to delete a rule from a network policy using the CLI.

To add rules to a network policy:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Specify the IPv4 or IPv6 address and mask length in CIDR format for the network policy rule.

    hostname (config) # policymgr ssl-intercept network ip <IP_address> <mask>

    where:

    • <IP_address> is the destination IPv4 or IPv6 address or source IPv4 or IPv6 address. To match any IP address for the network port pair, enter any. Only IP addresses are supported.

    • <mask> is the IPv4 or IPv6 mask length in CIDR format prefixed by a slash (for example, /24). To match any mask length, enter any.

  3. Specify the network port pair for the policy rule.

    hostname (config) # policymgr ssl-intercept network ip <IP_address> <mask_length> interface <port-pair-name>

    where:

    • <port-pair-name> is the designation (A through F) that is configured on the appliance interface for inline deployment. To specify all the network port pairs, enter ALL.

  4. Specify the match condition.

    hostname (config) # policymgr ssl-intercept network ip <IP_address> <mask_length> 
    interface <port-pair-name> {decrypt | pass-through} {match-destination | match-source}
    • Enter match-destination to match the ip with destination ip.

    • Enter match-source to match the ip with source ip.

    • No value to match the ip with either

  5. Specify the type of action for the network policy rule.

    hostname (config) # policymgr ssl-intercept network ip <IP_address> <mask_length> interface <port-pair-name> {decrypt | pass-through}
    • Enter decrypt to decrypt HTTPS traffic that matches the rule. This is the default action for the network policy rule.

    • Enter pass-through to bypass traffic that matches the rule.

  6. Repeat the preceding steps to add additional rules.

  7. Verify the status of the network policy rules configuration for SSL interception.

    hostname (config) # show policymgr ssl-intercept network
    
    Total CIDR Rule Supported: 512
    Total CIDR Rule Configured: 2
    
    INTF   IP                                           VLAN   ACTION
    ALL    2002:470:84a7:1720:ae1f:6bff:fe12:3e03/128   ALL    decrypt   match-source
    ALL    4.4.4.2/32 11.14.32.0/24                     ALL    decrypt   match-destination
    

    The "Total CIDR Rule Configured" line displays the total number of rules that you added to a network policy.

  8. Save your changes.

    hostname (config) # write memory
To delete a rule from a network policy:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Delete the network policy rule.

    hostname (config) # no policymgr ssl-intercept network ip <IP_address> <mask_length> interface <port-pair-name>

    Where:

    • <IP_address> is the destination IPv4 or IPv6 address or source IPv4 or IPv6 address. To match any IP address for the network port pair, enter any.

    • <mask> is the IPv4 or IPv6 mask length in CIDR format prefixed by a slash (for example, /24). To match any mask length, enter any.

    • <port-pair-name> is the designation (A through F) that is configured on the appliance interface for inline deployment. To specify all the network port pairs, enter ALL.

  3. Repeat the preceding steps to delete additional rules.

  4. Verify the status of the network policy rules configuration for SSL interception.

    hostname (config) # show policymgr ssl-intercept network
    
    Total CIDR Rule Supported: 512
    Total CIDR Rule Configured: 1
    
    INTF   IP                                           VLAN   ACTION
    ALL    2002:470:84a7:1720:ae1f:6bff:fe12:3e03/128   ALL    decrypt   match-source
    

    The "Total CIDR Rule Configured" line displays the total number of rules that remain in a network policy.

  5. Save your changes.

    hostname (config) # write memory