The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring the gateway for an out-of-band drop interface using the CLI

Prev Next

Use the CLI commands in this procedure to configure the gateway for an out-of-band drop interface.

Note

You must use the policymgr interface <port-pair-name> re-configure command for the changes to take effect.

To configure the gateway for an out-of-band drop interface on the Network Security appliance:
  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Configure the drop interface on ether1 or ether2 and specify the gateway IP address.

    hostname (config) # policymgr drop-interface <port-pair-name> <interface> gateway <IP_address>

    <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  3. Configure the selected interface (ether1 or ether2) with an IP address in the same subnet as the gateway IP address.

    hostname (config) # interface <interface> ip address <IP_address_with_subnet>
  4. Reapply the configuration to the specified interface.

    hostname (config) # policymgr interface <port-pair-name> re-configure
  5. Verify the updated settings.

    hostname (config) # show policymgr drop configuration
    Policy drop filter configuration:
    
    Drop Out Interface : ether2
    Gateway            :
    
    Drop Out Interface : ether1
    Gateway            : 10.128.59.1
  6. Save your changes.

    hostname (config) # write memory
    Saving configuration file ... Done!