policymgr drop-interface <interface> gateway <IP_address>

Prev Next

Enables a gateway for an out-of-band drop interface. For the gateway change to take effect, use the command policymgr interface <port-pair-name> re-configure.

When you use ether2 as the out-of-band drop interface and the appliance is connected to a next-hop L3 device, this command configures the next-hop IP address to reach the original client and/or the server network.

Syntax

[no] policymgr drop-interface <port-pair-name> {ether1 | ether2 } gateway <IP_address>

Parameters

no

Use the no form of this command to disable enabling a gateway for an out-of-band block interface

<port-pair-name>

Designation (A or B) that is configured on the appliance interface.

<IP_address>

Enter the IPv4 or IPv6 address for the gateway. To match any IPv4 address for the network port pair, enter any.

{ether1}

Configures the ether1 management interface as the gateway.

{ether2}

Configures the ether2 management interface as the gateway.

Examples

The following example configures the drop interface on ether1:

hostname (config) # policymgr drop-interface ether2 gateway 1.1.1.1

The following example configures the ether2 interface with an IP address in the same subnet as the gateway IP address:

hostname (config) # interface ether2 ip address 1.1.1.1/24

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Before 7.5