The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure fail-open switch parameters

Prev Next

You can configure various parameters on your fail-open switch. All configuration options, status, and statistics are accessible from the fail-open switch Command Line Interface (CLI). After you have configured basic network settings — IP address, gateway, and subnet mask — you will be able to access the fail-open switch through SSH. SSH is enabled on every fail-open switch by default and can be disabled through the CLI.

Note

Your fail-open switch only supports IPv4 addresses.

The steps below explain the configuration of parameters for your fail-open switch.

Steps:

  1. Connect an RJ-11 cable to the front of the module.

  2. Connect the other end to a computer running a terminal emulation software, such as HyperTerminal or PuTTY.

  3. Launch the terminal emulation software, and set the communications parameters as shown below:

    • Baud rate: 9600

      Note

      It is recommended not to alter the baud rate of the Management port.

    • Data bits: 8

    • Parity: None

    • Stop bits: 1

    • Flow control: None

  4. Power up the fail-open switch.

    The CLI banner and login prompt appear.

  5. At the login prompt, type Trellix00 and press Enter.

  6. At the password prompt, type Trellix00 and press Enter.

    The fail-open switch CLI prompt appears.

  7. Configure or modify parameters related to fail-open switch access and its ports using the commands listed.

    Command

    Description

    set_ip xxx.xxx.xxx.xxx

    Configures fail-open switch IPv4 address

    Reboot the fail-open switch for the new IPv4 address to take effect.

    set_netmask xxx.xxx.xxx.xxx

    Configures fail-open switch subnet mask

    Reboot the fail-open switch for the new subnet mask to take effect.

    set_gateway xxx.xxx.xxx.xxx

    Configures default gateway IPv4 address

    Reboot the fail-open switch for the new gateway IPv4 address to take effect.

    set_link <port> <on/off>

    Sets the port of a 1G Copper fail-open switch to auto-negotiate

    For the <port> use mon0, mon1, net0, or net1.

    set_link <port> off fd 100m

    Sets the port to 100 Mbps full-duplex

    For the <port>, use the syntaxes specified above.

    set_link <port> <enable/disable>_autoneg

    Sets the port of a 1G Fiber fail-open switch to auto-negotiate

    For the <port>, use mon0, mon1, net0, or net1.

    Note

    10G Fiber fail-open switches do not have such a command since auto-negotiate is enabled by default.

  8. Configure or modify parameters for other settings of the fail-open switch using these commands.

    Command

    Description

    set_ssh_state <on/off>

    Enables or disables the SSH status on the fail-open switch

    set_web_https_state <on/off>

    Enables or disables web access to the fail-open switch interface

    set_snmp_srv_ip

    Configures SNMP server IPv4 address

    The SNMP server IPv4 address can also be set in the web interface.

    set_trap <parameter> <on/off>

    Enables or disables the following SNMP traps:

    • appl fail – Application state change

    • bypass – Bypass state change trap

    • mon link – Monitoring port state change trap

    • net link – Network port state change trap

    • error – Error notification trap

    • update – Update complete trap

  9. View essential fail-open switch parameters using the commands listed. If your fail-open switch parameters have never been configured before, you will see factory settings.

    Command

    Description

    get_ip

    Displays fail-open switch IPv4 address

    get_netmask

    Displays fail-open switch subnet mask

    get_gateway

    Displays default gateway address

    get_ssh_state

    Displays the SSH status, which is enabled by default

    get_snmp_srv_ip

    Displays the SNMP server IPv4 address

    get_params

    Displays fail-open switch parameters

    get_web_https_state

    Displays the status of web access to the fail-open switch interface

    get_link <port>

    Displays port status

    For the <port>, use mon0, mon1, net0, or net1.