Quarantine
Last updated
Was this helpful?
Last updated
Was this helpful?
Two Fortigate Quarantine modes are available:
VLAN mode (default):
MAC address is moved into the Quarantine VLAN. The default quarantine VLAN has a DHCP server configured and no firewall policies. Devices in the quarantine network, can communicate to each other, but by default to nowhere else. Technically the Fortigate configures a mac to vlan mapping on the Fortiswitch.
Redirect Mode:
Devices stay in their configured VLAN, but are added to the QuarantinedDevices firewall address group. Block policies must be configured on the firewall to make this useful.
Quaranting devices or remove them from the Quarantine, by right-click on the device and select "Quarantine Host":
An overview of all quarantined devices is available as a dashboard: Dashboard -> User & Devices -> Quarantine
FortiSwitch Log entry: