The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

show policymgr interfaces

Prev Next

Displays the current policy for interfaces on the appliance.

Syntax

show policymgr interfaces

Parameters

None

Example

The example shows the current policy for interfaces on a Network Security model with four interface pairs.

hostname # show policymgr interfaces

Policy enabled: yes

Interface A
  Active      : yes
  op mode     : block (enforcing)
  fail-safe   : close
  policy      : mixed
  tolerance   : 1
  Ports       : pether3  pether4
  QinQ        : no
  QinQ-evet   : 0x88a8
  Mirror:
    Non-SSL   : yes
    SSL       : yes  TCP Port : 456  vlan : 545
    Port      : pether9

Interface B
  Active      : yes
  op mode     : block (enforcing)
  fail-safe   : close
  policy      : mixed
  tolerance   : 1
  Ports       : pether5  pether6
  QinQ        : no
  QinQ-evet   : 0x88a8
  Mirror:
    Non-SSL   : no
    SSL       : no
    Port      :

Interface C
  Active      : yes
  op mode     : tap (tapping)
  fail-safe   : close
  policy      : mixed
  tolerance   : 1
  Ports       : pether7  pether8 
  QinQ        : no
  QinQ-evet   : 0x88a8
  Mirror:
    Non-SSL   : no
    SSL       : no
    Port      :

Interface D
  Active      : yes
  op mode     : tap (tapping)
  fail-safe   : close
  policy      : mixed
  tolerance   : 1
  Ports       : pether9  pether10
  QinQ        : no
  QinQ-evet   : 0x88a8
  Mirror:
    Non-SSL   : no
    SSL       : no
    Port      :

User role

Admin, Operator, or Monitor

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Before Release 6.4. The mirror-port output field was added in Release 7.7 to display mirror ports that are configured to receive a copy of traffic from monitoring interfaces, and then forward that traffic to another analysis device. The mirror-port output field was replaced with the mirror output fields in Release 8.3 to display port mirroring for all traffic types (including SSL encrypted traffic) and SSL decryption mirroring.