Configures when a specific A or B monitoring interface is for out-of-band TAP mode blocking with TCP reset, UDP, or HTTP enabled on the appliance interface.
Important
You must use the
policymgr interface <port-pair-name> re-configurecommand for the changes to take effect.
Syntax
policymgr interface <port-pair-name> drop out-interface {ether1 | ether2}
Parameters
<port-pair-name>
Designation (A or B) that is configured on the appliance interface.
ether1
Configures the ether1 management interface to block packets that are sent in response to outbound traffic by the Network Security appliance.
ether2
Configures the ether2 management interface to block packets that are sent in response to outbound traffic by the Network Security appliance.
Example
The following example shows how to configure the ether2 management interface to block packets that are sent in response to outbound traffic by the Network Security appliance.
hostname (config) # policymgr interface A drop out-interface ether2 hostname(config) # policymgr interface A re-configure
User role
Admin or Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Before Release 7.5