policymgr interface <port-pair-name> drop out-interface

Prev Next

Configures when a specific A or B monitoring interface is for out-of-band TAP mode blocking with TCP reset, UDP, or HTTP enabled on the appliance interface.

Important

You must use the policymgr interface <port-pair-name> re-configure command for the changes to take effect.

Syntax

policymgr interface <port-pair-name> drop out-interface {ether1 | ether2}

Parameters

<port-pair-name>

Designation (A or B) that is configured on the appliance interface.

ether1

Configures the ether1 management interface to block packets that are sent in response to outbound traffic by the Network Security appliance.

ether2

Configures the ether2 management interface to block packets that are sent in response to outbound traffic by the Network Security appliance.

Example

The following example shows how to configure the ether2 management interface to block packets that are sent in response to outbound traffic by the Network Security appliance.

hostname  (config) # policymgr interface A drop out-interface ether2
hostname(config) # policymgr interface A re-configure 

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Before Release 7.5