You can quarantine endpoints to block all the traffic originating from the specified IP address seen on the selected device for the selected time. While adding an endpoint to quarantine, you can also re-direct the quarantined endpoint to the configured remediation portal.
Click the Analysis tab and select the domain from the Domain drop-down list.
Select Quarantine. The Quarantine page is displayed.
Click Add. The Add to Quarantine pop-up is displayed.
Add to Quarantine.png)
Update the following fields:
Option
Definition
IP Address
Enter the IP address of the endpoint.
Device
Select the specific device of the endpoint whose traffic originating from the IP address you want to block.
Quarantine Duration
Select the quarantine duration from the drop-down list.
Remediate
Select the checkbox to redirect the configured endpoint to the configured remediation portal.
Note
You can configure the remediation portal settings in Devices → Global → IPS Device Settings → Quarantine → Remediation Portal.
Remediation cannot be configured for IPv6 address. The checkbox and the information icon for remediation is not displayed if you enter an IPv6 address in the IP Address field.
Click Quarantine. The endpoint is added and displayed in the Quarantine page.