Disabling an Ingress Port Per Policy Rule (S-, K-Series)

A policy rule can be set to disable an ingress port, if a hit occurs for that rule, using the disable-port option of the set policy rule command. This per policy rule disable-port feature can be set to:

To disable a port for the first use of any policy profile rule, see Disabling an Ingress Port on First Profile Rule Use (S-, K-Series).

Use the clear policy disabled-ports to clear ports from the disabled state due to a policy rule hit on those ports.

Use the show policy disabled-ports command to display ports that have been disabled due to first profile rule use.