The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable Layer 2 Assert Mode

Prev Next

The changes made on the Manager interface are also reflected on Sensor CLI. To view the status on the Sensor, enter status command.

Steps:

  1. To enable the Assert mode, click Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Layer 2 Bypass.

  2. In the Layer 2 Pass-Through Monitoring section, select Assert in the drop-down list against Layer 2 Mode.

  3. Check ARP Spoofing to enable it on the device.

  4. Click Save.

    Once applied, you can view the number of critical faults and current mode in the Layer 2 Pass-Through Status dialog at the bottom of the screen.

    Layer 2 Settings window
    Layer 2 Settings window


    Note the following status fields:

    • Occurrences: Displays the current number of threshold-breaching events

    • Current Mode: Displays the current mode of the device. Abnormal means that Layer 2 pass-through mode is enabled in the device. L2 Pass-Through Mode means pass-through mode is enabled.

    Note

    To view the status of Assert mode for Sensors in a stack, Click Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <Stackname-node id> → Troubleshooting → Layer 2 Bypass

    Note

    • The Manager interface does not allow you to move to ON/OFF mode once the layer 2 mode is set to Assert, then only Deassert is allowed.

    • If you set the mode to 'Assert', it gets applied to all the Member Sensors for a stack / HA.

    • The Layer 2 modes Assert/Dessert could only be set from Manager interface for Sensor versions 10.1.5.107 and above. For others, it is recommended to set these modes through CLI commands.