The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring Inline operational modes using the Web UI

Prev Next

Use the Operational Modes area in the Policy Settings page to configure operational modes for an inline policy on an interface using the Web UI.

NX_InterfacesOperateModes_Scap.png

Mode

Description

Tap

Operate without inline functionality. This mode is the default for out-of-band monitoring.

Bypass

Starting with version 7.1.0, Network Security appliances have the ability to bypass packets larger than 1650 bytes rather than dropping them.

Block

Types of inline blocking attacks:

  • FS Open (fail-safe open)—In case of a failure of software, hardware, or power, all packets are allowed to pass through the appliance or sensor (recommended).

  • FS Close (fail-safe close)—In case of a failure of hardware or power, all traffic is blocked.

    Caution

    If you select the FS Close (fail-safe close) inline blocking type, you must use active end-to-end monitoring of the device to enable the re-routing of traffic around the device in the event of a hardware or power failure.

Monitor

Monitor all packets without any blocking and generate alerts about potential infections.

To configure operational modes for an inline policy on the Network Security appliance:
  1. In the Web UI, choose Settings > Inline Operational Modes.

  2. Select the relevant operational mode for each port pair in the Operational Modes area:

    • Tap

    • Bypass

    • Block—Select one of the following types of block attacks:

      • FS Open (fail-safe open)

      • FS Close (fail-safe close)

    • Monitor

  3. To configure the appliance with the selected operational modes, click Update: Operational Modes. The following message appears:

    NX_InterfacesOperateModesConfirm_Scap.png