Use the CLI commands in this procedure to configure operational modes for an inline policy on an interface.
Note
You must use the policymgr interface <port-pair-name> re-configure command for the changes to take effect.
Enable the CLI configuration mode.
hostname > enable
hostname # configure terminal
Specify the relevant operational mode for each port pair.
To operate without inline functionality in TAP mode:
hostname (config) # policymgr interface <port-pair-name> op-mode tap
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Note
TAP mode is the default for out-of-band monitoring.
To allow traffic to pass through the appliance or sensor:
hostname (config) # policymgr interface <port-pair-name> op-mode bypass
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.To monitor all packets without any blocking and generate alerts about potential infections:
hostname (config) # policymgr interface <port-pair-name> op-mode monitor
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Specify inline blocking attacks.
(Recommended) To allow all packets to pass through the appliance or sensor in case of a failure of software, hardware, or power:
hostname (config) # policymgr interface <port-pair-name> op-mode block fail-safe open
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.To block all traffic in case of a failure of hardware or power:
hostname (config) # policymgr interface <port-pair-name> op-mode block fail-safe close
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.
If you select the fail-safe close inline blocking type, you must use active end-to-end monitoring of the device to enable the re-routing of traffic around the device in the event of a hardware or power failure.
Reapply the configuration to the specified interface.
hostname (config) # policymgr interface <port-pair-name> re-configure
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Verify the settings of the operational modes.
hostname (config) # show policymgr interfaces Policy enabled: yes Interface A Active : yes op mode : tap (tapping) fail-safe : close policy : mixed tolerance : 1 mirror-port : Ports : pether3 pether4 QinQ : no QinQ-evet : 0x88a8
Save your changes.
hostname (config) # write memory
Saving configuration file ... Done!