The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deleting rules from a network whitelist using the CLI

Prev Next

Use the CLI commands in this procedure to delete a policy configuration rule from a network whitelist on the Network Security appliance using the CLI.

Important

After you remove a rule from a network whitelist, use the policymgr refresh-policy command in the CLI configuration mode to refresh the policy configuration.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • You have added one or more rules to a network whitelist to the Network Security appliance. For details about how to add network whitelist rules, see Adding rules to a network whitelist using the CLI.

To delete a rule from a network whitelist:
  1. Go to CLI configuration mode.

    hostname > enable hostname # configure terminal

  2. To delete the policy configuration for the destination IP address:

    hostname (config) # no policymgr network dst <IPAddress> <maskLength> [vlan <vlanID>]

  3. To delete the policy configuration for the source IP address:

    hostname (config) # no policymgr network src <IPAddress> <maskLength> [vlan <vlanID>]

  4. To delete the policy configuration for the host IP address:

    hostname (config) # no policymgr network host <IPAddress> <maskLength> [vlan <vlanID>]

  5. Repeat the previous step for each additional rule you want to delete.

  6. Save your changes.

    hostname (config) # write memory

  7. Refresh the policy configuration.

    hostname (config) # policymgr refresh-policy

  8. Verify the configuration for a network whitelist.

    hostname (config) # show policymgr networks

Example

This example shows how to remove the policy configuration for the destination IP address and mask length from a network whitelist.

hostname (config) # no policymgr network dst 23.1.1.2/32

hostname (config) # policymgr refresh-policy

hostname (config) # show policymgr networks

Whitelist Entries: 2 / 256

Whitelist: 

VLAN     INTF     MONITOR    IP           MODE(source|destination|host)
ALL      ALL      no         1.1.1.1/32   host
ALL      ALL      n/a        23.1.1.1/32  src