policymgr interface <port-pair-name> op-mode block

Prev Next

Configures inline blocking and a fail-safe mode on the appliance interface.

This command is not supported on SmartVision Edition appliances, which are Network Security appliances with SmartVision Edition appliance licenses. The SmartVision Edition sensor is also called Trellix Network Security, SmartVision Edition.

Important

You must use the policymgr interface <port-pair-name> re-configure command for the changes to take effect.

Caution

If you configure the fail-safe close inline blocking, you must use active end-to-end monitoring of the device to enable the rerouting of traffic of the device fails.

Syntax

policymgr interface <port-pair-name> op-mode block [fail-safe {open | close}]

Parameters

<port-pair-name>

Designation (A or B) that is configured on the appliance interface.

[fail-safe {open}]

Allows all packets to pass through the appliance in case software, hardware, or power fails.

[fail-safe {close}]

Blocks all traffic in case of software, hardware, or power fails. This parameter should only be used if the device is actively monitored.

Examples

The following example configures inline blocking on the specified interface.

hostname (config) # policymgr interface A op-mode block
hostname (config) # policymgr interface A re-configure 

The following example sets the fail-safe for inline blocking on the specified interface

hostname (config) # policymgr interface B op-mode block fail-safe open
hostname (config) # policymgr interface B re-configure

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Before Release 7.5