User Guide
OmniAccess SafeGuard OS Administration Guide
105
Chapter 2: Accessing and Managing the System
Configuring System Recovery
Because there is only one SafeGuard device in the typical deployment model, the device
must be configured for fail-passthru mode. When in fail-passthru mode, the device sets
the protection mode to pass-thru if a critical error occurs.
When the protection mode is set to pass-thru mode, policy enforcement, visualization,
and malware detection are not enabled in addition to any high availability features.
Table 17 depicts the protection modes in greater details for the SafeGuard Switch or
Controller.
To configure the system recovery mode, use the
system recovery command in Global
Configuration mode.
system recovery [reboot | fail-passthru]
Table 17 Supported Protection Modes
Protection
Mode
When Used SafeGuard Controller SafeGuard Switch
Pass-thru
Mode
First time set up
and cabling
Acts as a transparent
bridge. All security
functionality is
bypassed.
Acts as a standard L2/
L3 switch. All security
functionality is
bypassed.
Monitor Mode
Testing and
trials
Authentication, captive portal, visualization,
malware detection and protection and user-
based policy checking is applied to all data
traffic, but enforcement is ignored.
Protect Mode
Typical
Deployment
Authentication, captive portal, visualization,
malware detection and protection and user-
based policy checking is applied to all data
traffic, and actively enforced.
Syntax Description reboot The switch will be rebooted on system fault.
This is the default setting.
fail-
passthru
Sets the switch to fail-passthru mode. If a
critical error occurs, the device will be set
to pass-thru mode.










