The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring notification of inline packet inspection process state changes (CLI)

Prev Next

You can configure an IPS platform to send email notifications whenever the state of the inline packet inspection process state changes. This option can be configured through the Network Security appliance CLI only.

Prerequisites

Before you configure an IPS platform for email notification when the inline packet inspection process starts or stops, perform the following prerequisite tasks:

  • Log in to the appliance CLI as Operator or Admin.

  • Use the fenotify default timezone CLI command in configuration mode to set the default time zone for FireEye notifications. For more information, see the Network Security System Administration Guide and the CLI Command Reference.

  • Configure email settings for administrative events, as described in "Configuring Administrative Email Settings Using the CLI" in the Network Security User Guide.

    hostname (config) # email ?
    auth               Set authentication options for sending email
    autosupport        Set handling of automatic support email
    dead-letter        Configure settings for saving undeliverable emails
    domain             Override domain from which emails appear to come
    mailhub            Set the mail relay to be used to send emails
    mailhub-port       Set mail port to be used to send emails
    notify             Set handling of events and failures via email
    return-addr        Set the username in the return address for email notifications
    return-host        Include hostname in return address for email notifications
    send-test          Send test email to all configured event and failure recipients
    ssl                Configure security options for email
Procedure
To configure email notifications for inline packet inspection process state changes:
  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Check the email settings for administrative events by using the show email command.

    In the following example, email notifications for administrative events are configured to be sent to the email address my-first.my-last@my-domain.com.

    hostname # show email
    Mail hub:         172.16.2.27
    Mail hub port:    25
    Domain override:  www.my-domain-override.com
    Return address:   do-not-reply
    Include hostname in return address: yes
     
    Current reply address: do-not-reply@my-host.www.my-domain-override.com
     
    Security mode:        tls-none
    Verify server cert:   yes
    Supplemental CA list: default-ca-list
     
    SMTP authentication: disabled
     
    Dead letter settings:
      Save dead.letter files: yes
      Dead letter max age:    14 days
     
    Email notification recipients:
      my-first.my-last@my-domain.com (all events, in detail)
     
    Autosupport emails
      Enabled:       	 yes
      Recipient:     	 eng-autosupport@fireeye.com
      Mail hub:      	 owa.fireeye.com
      Security mode:        tls-none
      Verify server cert:   yes
      Supplemental CA list: default-ca-list
      SMTP authentication:  disabled
  3. Enable or disable notifications when the inline packet inspection process stops. Enter one of the following forms of the email notify event command:

    • To enable notifications when the inline packet inspection process stops, enter the email notify event command, and specify the inline‑engine‑down parameter.

    • To disable this notification option, you would use the no form of the command.

    The following example command enables notifications when inline packet inspection processing stops.

    hostname (config) # email notify event inline-engine-down
  4. Enable or disable notifications when the inline packet inspection process starts. Enter one of the following forms of the email notify event command:

    • To enable notifications when the inline packet inspection process starts, enter the email notify event command, and specify the inline‑engine‑up parameter.

    • To disable this notification option, you would use the no form of the command.

      hostname (config) # email notify event inline-engine-up
  5. Save your changes.

    hostname (config) # write memory