This command is used to configure the destination MAC address in the heartbeat packets sent by the Active Fail-Open (AFO) kit. These packets will be used by Sensor to determine the status of the AFO kit.
Note
Starting with 10.1 Update 10 release, NS-series Sensor models NS9500 and NS7500 support third-party AFO Bypass Kit solutions. To view the list of supported vendors and their AFO kit models, see KB95945. If you are using these third-party AFO kits or Trellix AFO kits, you do not need to configure the MAC address, as the Sensors (NS9500 and NS7500) can automatically detect the heartbeat packets. The
set afocommand is useful only for those using other third-party AFO kits that are not included in KB95945.
Syntax:
set afo <port-pair | all> dst-mac <destination_mac>
Parameter | Description |
|---|---|
<port-pair> | A valid gigabit ethernet monitoring port-pair on the Sensor Valid port-pairs for NS9600, NS9500, NS7600, NS7500 Sensors are: g0/1-g0/2 |g0/3-g0/4 | g1/1-g1/2 | g1/3-g1/4 | g1/5-g1/6 | g1/7-g1/8 | g2/1-g2/2 | g2/3-g2/4 | g2/5-g2/6 | g2/7-g2/8 | g3/1-g3/2 | g3/3-g3/4 | g3/5-g3/6 | g3/7-g3/8 Valid port-pairs for NS3600 Sensor are: 1-2 | 3-4 | 5-6 | 7-8 | 9-10 | 11-12 | 13-14 |
<all> | Includes all the IFO-ACTIVE port-pairs |
<destination_mac> | The destination MAC address of the AFO kit which will be used by sensor to determine the status of the AFO kits. |
Example 1:
intruShell@NS7500> set afo g0/1-g0/2 dst-mac 22:44:66:88:10:12
The above command will set the destination MAC address on port-pair g0/1-g0/2.
Example 2:
intruShell@NS7500> set afo all dst-mac 22:44:66:88:10:12
The above command will set the destination MAC address on all the IFO-ACTIVE port-pairs.
Applicable to:
NS-series Sensors - NS9600, NS9500, NS7600, NS7500, and NS3600