The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

setfailopencfg internal/external-failopen bypass/inline

Prev Next

This command enables users to configure the behavior of the port pair after Sensor reboot.

setfailopencfg internal/external-failopen bypass/inline

Parameter

Description

inline

If the Sensor has a link down and is rebooted (setfailopencfg restore-inline is disabled/enabled, but is not triggered at the time of reboot), the port-pair restores itself into inline state (by getting enabled and coming up).

bypass

The port pairs stay in the bypass mode (by staying disabled and not coming up).

This configuration is persisted across Sensor reboots.

For the port pairs to be restored from bypass to inline mode, the following conditions should be met:

  • The operating mode is inline-fail-open (fail-open support is built in or passive fail-open kits are connected).

  • If a passive fail-open kit is used, the kit is connected to the Sensor.

  • If the port pair goes into the bypass mode due to monitoring port link down or a missing cable.

When this feature is enabled or you change the time interval, the Sensor checks and attempts to restore the port pairs to the inline mode immediately. Consider the following scenarios.

Scenario1: Change of time interval

The feature is enabled at 11.00 with the default time interval of 5 minutes At 11.03, the port link goes down for a few milliseconds and is then restored. At 11.04, the time interval is changed to 10 minutes. The Sensor checks the port pair and restores the port pair to the inline mode at 11.14. Subsequently, the Sensor checks the port pairs every 10 minutes (unless the time interval is changed again), that is, the next attempt to restore from bypass to inline mode takes place at 11.24.

Scenario 2: Feature enabled/disabled

The feature is enabled at 11.00 with a default time interval of 5 minutes. At 11.03, the port link goes down for a few milliseconds and is then restored. At 11.04, the feature is disabled. At 11.05, the port pair is admin down. The feature is enabled at 11:07, the Sensor checks the port pair but restores the port pair to the inline mode at 11:12.

Note

If you manually disable the port’s administrative status, the port continues to remain in the bypass mode even though this feature is enabled.

The Sensor sends a notification to the Manager with a revised timestamp for every failed attempt to restore a port pair from bypass to the inline mode (typically due to link negotiation failure with peer devices). If the restore to inline from bypass operation is successful, the Manager clears prior (bypass) notifications, if any, for that port pair.