The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring inline operational modes using the CLI

Prev Next

Use the CLI commands in this procedure to configure operational modes for an inline policy on an interface.

Note

You must use the policymgr interface <port-pair-name> re-configure command for the changes to take effect.

To configure operational modes for an inline policy on the Network Security appliance:
  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Specify the relevant operational mode for each port pair.

    • To operate without inline functionality in TAP mode:

      hostname (config) # policymgr interface <port-pair-name> op-mode tap

      where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

      Note

      TAP mode is the default for out-of-band monitoring.

    • To allow traffic to pass through the appliance or sensor:

      hostname (config) # policymgr interface <port-pair-name> op-mode bypass

      where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

    • To monitor all packets without any blocking and generate alerts about potential infections:

      hostname (config) # policymgr interface <port-pair-name> op-mode monitor

      where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

    • Specify inline blocking attacks.

      • (Recommended) To allow all packets to pass through the appliance or sensor in case of a failure of software, hardware, or power:

        hostname (config) # policymgr interface <port-pair-name> op-mode block fail-safe open

        where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

      • To block all traffic in case of a failure of hardware or power:

        hostname (config) # policymgr interface <port-pair-name> op-mode block fail-safe close

        where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

        caution.png

        If you select the fail-safe close inline blocking type, you must use active end-to-end monitoring of the device to enable the re-routing of traffic around the device in the event of a hardware or power failure.

  3. Reapply the configuration to the specified interface.

    hostname (config) # policymgr interface <port-pair-name> re-configure

    where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  4. Verify the settings of the operational modes.

    hostname (config) # show policymgr interfaces
    Policy enabled: yes
    Interface A
    Active      : yes
    op mode     : tap (tapping)
    fail-safe   : close
    policy      : mixed
    tolerance   : 1
    mirror-port :
    Ports       : pether3  pether4
    QinQ        : no
    QinQ-evet   : 0x88a8
  5. Save your changes.

    hostname (config) # write memory
    Saving configuration file ... Done!