This command displays the status of VLAN-based reconnaissance.
The Attack Details panel in the Manager Attack Log displays VLAN ID in reconnaissance alert messages. The VLAN ID is included in fault notifications and reports.
Note
In case of a fail-over pair, the feature has to be enabled on both the Sensors.
For more information, see the Trellix Intrusion Prevention System Product Guide.
Syntax:
show vlanbasedrecon status
Sample Output:
intruShell@john> show vlanbasedrecon status
Vlan Based Reconnaissance attack detection disabled
Applicable to:
NS-series Sensors