The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

clear afo dst-mac

Prev Next

This command clears the previously configured destination MAC address on the specified port-pairs.

Note

Upon clearing the configuration, when you execute the command show afo status, the AFO Destination MAC column in the output will display the status of IFO-ACTIVE port-pair(s) as Auto Detected. If you plan to reconfigure the destination MAC address in the heartbeat packets sent by the Active Fail-Open (AFO) kit, you can use the command set afo port-pair and dst-mac.

Syntax:

clear afo <port-pair | all> dst-mac

Parameter Description
<port-pair> Set the port-pair for which the status is to be displayed.

Valid port-pairs for NS-series Sensors are: g0/1-g0/2 | g1/1-g1/2 | g1/3-g1/4 | g1/5-g1/6 | g1/7-g1/8 | g2/1-g2/2 | g2/3-g2/4 | g2/5-g2/6 | g2/7-g2/8 | g3/1-g3/2 | g3/3-g3/4 | g3/5-g3/6 | g3/7-g3/8

<all> Display the status of all the IFO-ACTIVE port-pairs.

Example 1:

intruShell@NS7500> clear afo g0/1-g0/2 dst-mac

The above command clears the destination MAC address configuration on port-pair g0/1-g0/2.

Example 2:

intruShell@NS7500> clear afo all dst-mac

The above command clears the destination MAC address configuration on all the IFO-ACTIVE port-pairs.

Applicable to:

NS-series Sensors NS9500 and NS7500