The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring the Network Security appliance to forward traffic to a mirror port using the CLI

Prev Next

Use the commands in this section to configure port mirroring. The interface pair that serves as the mirror port must be configured in tap mode. The monitoring interface pair can be configured in inline mode (monitor or block mode) or tap mode. In inline block mode, all traffic is forwarded to the other analysis device.

For details about how to forward traffic from a mirror port, see the Network Security System Administration Guide.

Note

If the monitoring interface pair is configured in tap mode, the mirroring of SSL decrypted traffic cannot be enabled.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • A minimum of two interface pairs on the Network Security appliance

  • Mirror port interface pair configured in tap mode

To add a mirror port on an interface:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. View the interface configuration settings.

    hostname (config) # show policymgr interfaces
  3. Specify the monitoring interface pair and the mirror port.

    hostname (config) # policymgr interface <interfacePair> mirror port <portName>

    where <interfacePair> is the interface pair from which traffic will be forwarded, and <portName> is the port that will receive the mirrored traffic.

  4. Verify your changes.

    In the following example, the "Mirror Port:" line of the command output displays "pether9" to show that a mirror port is configured for Interface A.

    hostname (config) # show policymgr interfaces
    
    Policy enabled: yes
    
    Interface A
      Active      : yes
      op mode     : block (enforcing)
      fail-safe   : close
      policy      : mixed
      tolerance   : 1
      Ports       : pether3  pether4
      QinQ        : no
      QinQ-evet   : 0x88a8
      Mirror:
        Non-SSL   : no
        SSL       : no
        Port      : pether9
    .........

    Note

    Use the policymgr interface <interfacePair> mirror enable command if you want to enable port mirroring for all traffic types (including SSL encrypted traffic) on the monitoring interface. For details about how to enable port mirroring for all traffic types, see Adding or deleting port mirroring for all traffic using the CLI.

  5. Save your changes.

    hostname (config) # write memory
To clear a mirror port from an interface:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Clear the mirror port from an interface.

    hostname (config) # policymgr interface <interfacePair> mirror clear

    where <interfacePair> is the interface pair from which traffic will be forwarded.

  3. Verify your changes.

    In the following example, the "Mirror Port:" line of the command output is cleared.

    hostname (config) # show policymgr interfaces
    
    Policy enabled: yes
    
    Interface A
      Active      : yes
      op mode     : block (enforcing)
      fail-safe   : close
      policy      : mixed
      tolerance   : 1
      Ports       : pether3  pether4
      QinQ        : no
      QinQ-evet   : 0x88a8
      Mirror:
        Non-SSL   : no
        SSL       : no
        Port      :
    .........