The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

clear afo dst-mac

Prev Next

This command clears the previously configured destination MAC address on the specified port-pairs.

Note

Upon clearing the configuration, when you execute the command show afo status, the AFO Destination MAC column in the output will display the status of IFO-ACTIVE port-pair(s) as Auto Detected. If you plan to reconfigure the destination MAC address in the heartbeat packets sent by the Active Fail-Open (AFO) kit, you can use the command set afo port-pair and dst-mac.

Syntax:

clear afo <port-pair | all> dst-mac

Parameter

Description

<port-pair>

Set the port-pair for which the status is to be displayed.

Valid port-pairs for NS9600, NS9500, NS7600, NS7500 Sensors are: g0/1-g0/2 | g0/3-g0/4 | g1/1-g1/2 | g1/3-g1/4 | g1/5-g1/6 | g1/7-g1/8 | g2/1-g2/2 | g2/3-g2/4 | g2/5-g2/6 | g2/7-g2/8 | g3/1-g3/2 | g3/3-g3/4 | g3/5-g3/6 | g3/7-g3/8

Valid port-pairs for NS3600 Sensor are: 1-2 | 3-4 | 5-6 | 7-8 | 9-10 | 11-12 | 13-14

<all>

Display the status of all the IFO-ACTIVE port-pairs.

Example 1:

intruShell@NS7500> clear afo g0/1-g0/2 dst-mac

The above command clears the destination MAC address configuration on port-pair g0/1-g0/2.

Example 2:

intruShell@NS7500> clear afo all dst-mac

The above command clears the destination MAC address configuration on all the IFO-ACTIVE port-pairs.

Applicable to:

NS-series Sensors NS9600, NS9500, NS7600, NS7500, and NS3600.