The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Fail-open kit related issues

Prev Next

This section discusses issues related to fail-open kit in the customer's environment.

Applicable to Sensor models: NS-series

Problem scenarios

  1. Reset the password and all the parameters to factory default.

  2. Passive fail-open does not bypass even though the fail-open kit Sensor is down/Sensor is rebooted.

  3. Passive fail-open does not come up and continuously flaps.

  4. Active fail-open does not come up and continuously flaps.

  5. Active fail-open to Sensor link flaps continuously.

Data/Information Collection

  1. Execute the following commands in the Sensor:

    • show

    • status

    • show intfport <port> (multiple times)

    • show inlinepktdropstat <port>

    • show sensor-load

  2. Check the following details:

    • Active fail-open type (model) and configuration

    • Cables and SFP type

    • Physical connection details (network topology)

    • Peer device port configuration

  3. Trace the Sensor files.

  4. Check the infoCollector tool for the logs including the configuration backup (This is optional in case the issue is required to be reproduced locally.)

Following are the troubleshooting steps for the problem scenarios stated above:

Problem 1: Reset the password and all the parameters to factory default

If you have forgotten the password and do not know the correct password, perform the following steps to reset the password and all the other parameters of the Active Fail-Open kit.

  1. On the fail-open switch, press the PB0 push button for three seconds to enter the main menu seen in the display panel.

    GUID-E2B9680C-E6CD-4890-8A33-38FC81A3FC03-low.png
  2. Do a short press on the PB0 push button to move to the next submenu in the list.

    Note

    Perform this step till you move to the OP submenu.

  3. Push the PB1 push button with a short press to select and view the options in the OP submenu.

  4. Do a short press on the PB0 push button to move to the next option in the OP submenu.

    Note

    Perform this step till you move to the DEFAULT option.

  5. Push the PB1 push button with a short press to select the DEFAULT option.

When the option DEFAULT is selected, it sets the default factory parameters.

In the display panel, you can view small lines ( _ _ _ _ _ ) which indicates that default factory parameters are successfully set. As a result, the password is also reset to the default password.

Problem 2: Passive fail-open does not bypass even though the fail-open kit Sensor is down/Sensor is rebooted

  1. Check if the Sensor is up and in good state.

  2. In the Physical Ports page of the Manager, check the following configurations:

    • Port is configured to Inline Fail Open - Passive

    • Auto-Negotiate is selected.

  3. If peer device port does not support MDIX, use an appropriate cable to bring up the link during the Sensor bypass. If it does not work, check the Passive Fail-Open Kit for any hardware issues.

  4. While using Passive Fail-Open Kit, make sure to disable the STP on the peer device ports to avoid auto renegotiate.

Note

While using Passive Fail-Open Kit, each Sensor port individually negotiates with peer port initially when the Sensor is in inline mode. When the Sensor goes to bypass mode, the peer device port re-negotiates with each other. Make sure to enable Portfast on peer devices to minimize network outage.

Problem 3: Passive fail-open does not come up and continuously flaps

  1. Check if the Sensor is up and in good state.

  2. In the Physical Ports page of the Manager, check the following configurations:

    • Port is configured to Inline Fail Open - Passive

    • Auto-Negotiate is selected.

    • Appropriate cable is used. The cable type should be Cat5e and above for copper, and for fiber single-mode/multi-mode depending on the SFP used.

  3. Check the control cable connection and the right controller port.

  4. Check if the SFPs are according to Trellix's recommendations.

  5. Check for bad/defective cable and SFPs.

  6. Check if the peer device port is working and if the port settings are set to Auto-Negotiate.

  7. Ensure local port testing (by connecting monitoring ports back to back).

  8. Swap the working SFP and cables from another port pair.

  9. If all the above steps fail, RMA the Sensor.

Problem 4: Active fail-open does not come up and continuously flaps

  1. Check if the Sensor is up and in good state.

  2. Use Trellix recommended transceivers (normal SFP for 1G, SPF+ for 10G, and QSP for 10G ports).

  3. Check the Active Fail-Open Kit monitoring port setting (specifically Auto-Negotiate and speed settings). It should be the same as Sensor monitoring ports and peer device.

  4. Ensure local loopback port testing (by connecting monitoring ports back to back).

  5. Swap the working SFP and cables from another port pair.

  6. Check the load on the Sensor.

  7. If all the above steps fail, RMA the Sensor.

Steps to Configure and Debug active fail-open

When configuring the Active Fail-Open Kit, in case of flapping issues, the configuration on the network peer ports must match with the one on Active Fail-Open Kit-Sensor monitoring port pair.

  1. Ensure the power to the Optical Bypass Switch is on.

  2. Using a DB-9 RS232 programming cable. Connect a PC that is running the HyperTerminal to the Optical Bypass Switch.

  3. Launch a terminal emulation software like HyperTerminal, and set the following communication parameters:

    • Bits per second: 19200

    • Stop bit: 1

    • Data bits: 8

    • Flow control: None

    • Parity: None

  4. Click OK. The CLI banner and login prompt are displayed.

  5. Type the default username and password. (The default username and password is Trellix00 and is case-sensitive).

  6. Once you are logged in, use the following commands in the table to configure and troubleshoot the Active Fail-Open Kit:

    Command

    Description

    a

    Set the timeout value.

    To set the Timeout value, do the following:

    • Type a and press Enter.

    • TimeOut period (1-254 sec) — Type the number of seconds between each heartbeat (1-254 seconds) and press Enter. Default = 1.

    • Retry Count (1-254) — Type the number of missed heartbeats allowed before the Bypass Switch enters the On mode. Default = 3.

    Note

    The Retry Count must be greater than or equal to the Timeout period.

    b

    Set Switch parameters.

    To set speed duplex and auto-negotiation, LFD, bypass detect:

    • 1= Turn On.

    • 0 = Turn Off.

    • Fail Mode Open/Close= 1

    Note

    The LFD and Bypass detecting mode settings cannot be changed.

    c

    Set TAP mode.

    • Type c and press Enter.

    • Type 1 to set the tap mode On, or 0 to set the tap mode Off. Default = Off.

    d

    Show configuration.

    Type d and press Enter. The following is displayed:

    • LFD = On

    • Timeout Period= 1

    • Bypass Detect= Off

    • Retry Count= 3

    • Fail Mode= Open

    • Bypass State= Off

    • TAP Mode= Off

    e

    Show port status.

    Type e and press Enter. The following is displayed:

    • Port A= Up/Down

    • Port B= Up/Down

    • Port 1= Up/Down

    • Port 2= Up/Down

    f

    Set Switch name.

    • Type f and press Enter.

    • At the prompt, type the Switch name, which can be 8 characters long.

    z

    Reset to Factory Defaults.

  1. Check if the Sensor is up and in a good state.

  2. Use Trellix recommended transceivers (normal SFP for 1G, SPF+ for 10G, QSFP+ for 40G, and QSP28 for 100G ports).

  3. Check the Active Fail-Open Kit monitoring port setting (specifically Auto-Negotiate and speed settings). It should be the same as Sensor monitoring ports and peer device.

  4. Check the Sensor ports (by connecting monitoring ports back to back).

  5. Swap the working SFPs and cables from the other working port pair.

  6. Swap the working Active Fail-Open Kit to confirm whether a hardware problem exists.

  7. Check the load on the Sensor to make sure that Sitera is dropping the HB packets from the Active Fail-Open Kit. To test if the Sitera is dropping the HB packets, contact Trellix Support for further assistance.