The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

layer2 mode

Prev Next

This command configures the Layer 2 mode.

Syntax:

layer2 mode <assert><deassert><off><on>

assert

Forces the Sensor into Layer 2 Passthru Mode (also known as L2 Mode). This helps in troubleshooting network issues. When this command is used, the Sensor stays in L2 Mode until one of two events occurs: either during Sensor reboot or when the layer2 mode deassert command is issued.

deassert

Forces the Sensor out of Layer 2 Passthru Mode. It is used to re-establish IPS processing after a layer2 mode assert command is issued. This command should not be used to force a Sensor out of L2 Mode if L2 Mode was triggered by a Sensor software failure. Using the command in this manner will trigger a Sensor reboot.

off

Resets the layer 2 mode configuration. If an error occurs in the higher layer processing of the collection subsystem, the Sensor reboots immediately instead of entering Layer 2 mode. This command is issued when the Sensor is already forwarding traffic in Layer 2 mode. The Sensor will reboot immediately, attempting to recover full detection functionality.

on

Enables the Layer 2 mode feature. If a failure occurs in the higher layer processing of the collection subsystem, it configures the Sensor to forward all traffic at Layer 2. This command does not force the Sensor to start forwarding traffic in Layer 2 mode immediately.

Default Value:

On

Sample Output:

intruShell@john> layer2 mode assert

intruShell@john> show layer2 mode

Mode : enable-immediate

Duration : 10 minutes

Threshold : 1

Occurrences : 0

Note

The status command can also be used to check the Layer 2 mode status.

intruShell@john> layer2 mode deassert

intruShell@john> status

Layer 2 Status : normal (IDS/IPS)

Applicable to:

NS-series Sensors and Virtual IPS Sensors.