The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Layer 2 mode on drops at Switch/NIC ports

Prev Next

Layer 2 drops feature monitors drops at various points that impact the customer traffic. It provides the capability for Sensor to enter into Layer 2 mode upon detecting heavy drops at the switch/NIC ports and prevent network outage.

To prevent any adverse impact on monitoring Layer 2 drops, Trellix recommends to factor in either of the following considerations:

  • Avoid enabling Layer 2 drops and packet capture at the same time on Sensor appliance.

  • Ensure sufficient filters are added to limit the packets captured such that it does not cause drops in the NIC when both the features are enabled.

You can configure the settings for Layer 2 mode on drops with set l2OnDrops (enable|disable|sensitivity-level) from Sensor CLI. After configuring the required settings, show l2OnDropsConfig can be used to view the status of Layer 2 mode.

The following table describes the various configuration settings available for Layer 2 mode on drops:

Parameter

Description

enable

Puts the Sensor to Layer 2 mode when high drops are seen.

disable

Disables Layer 2 mode on drops.

sensitivity-level

Configures the sensitivity level for Layer 2 mode on drops.

The Sensor monitors these drops periodically. If number of drops exceeds the drop count threshold value in consecutive occurrences and the configured sensitivity level is met, then the Sensor is put in to Layer 2 mode.

The following table consists of actual Drop Count Threshold and Number of Consecutive Occurrences for various Sensitivity Levels:

Sensitivity Level

Drop Count Threshold

Number of Consecutive Occurrences

Low

50000

5

Medium

30000

4

High

10000

3

Note

  • Layer 2 on drops is applicable only to NS-series Sensors.

  • The Layer 2 mode must be 'ON' to configure set l2OnDrops (enable|disable|sensitivity-level).

  • If you want to restore the Sensor automatically to normal state, you have to configure latency-monitor restore-inline.

It must be considered that too many drops due to packet capture can influence Layer 2 drops action depending on the configuration.

Note

Packet capture feature is a debugging tool that is provided to help you with troubleshooting problems, auditing, to gain insights, and to use the incoming NIC.