The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

layer2 mode

Prev Next

This command enables you to configure the Layer 2 mode.

Syntax:

layer2 mode <assert | deassert> <port>

Parameter

Description

assert

Forces the Sensor port into Layer 2 Pass-Through Mode (also known as L2 Mode). This helps in troubleshooting network issues. When this command is used, the Sensor stays in L2 Mode until one of two events occurs: either during the Sensor reboot or when the layer2 mode deassert command is issued.

deassert

Forces the Sensor port out of Layer 2 Pass-Through Mode. It is used to re-establish IPS processing after the layer2 mode assert command is issued. This command must not be used to force a Sensor out of L2 Mode if L2 Mode was triggered by a Sensor software failure. Using the command in this manner triggers a Sensor reboot.

port

Sets the port for which assert or deassert action needs to be performed.

Valid port numbers for NS7x00, NS7x50, NS7500, NS7600, NS9x00, NS9500, and NS9600 Sensors are: G0/1 | G0/2 |G0/3 | G0/4 | G1/1 | G1/2 | G1/3 | G1/4 | G1/5 | G1/6 | G1/7 | G1/8 | G1/9 | G1/10 | G1/11 | G1/12 | G2/1 | G2/2 | G2/3 | G2/4 | G2/5 | G2/6 | G2/7 | G2/8 | G2/9 | G2/10 | G2/11 | G2/12 | G3/1 | G3/2 | G3/3 | G3/4 | G3/5 | G3/6 | G3/7 | G3/8

Valid port numbers for NS3600 are: 1-2 | 3-4 | 5-6 | 7-8 | 9-10 | 11-12 | 13-14

Default Value:

On

Sample Output:

IntruDbg#> layer2 mode assert g0/1-g0/2

Note

To check the Layer 2 configuration on individual interface, run show layer2 portlevel command.

Applicable to:

NS3600, NS7x00, NS7x50, NS7500, NS7600, NS9x00, NS9500, NS9600 Sensors