Make sure the Sensor is up and you have deployed the required monitoring ports in inline mode.
Use the Quarantine Configuration Wizard to enable and configure Quarantine for specific Sensor monitoring ports.
Click the Devices tab.
Select the domain from the Domain drop-down list.
On the left pane, click the Devices tab.
Select the device from the Device drop-down list.
Select Setup → Quarantine → Port Settings.
From the Port drop-down list, select the Sensor monitoring port for which you want to configure Quarantine.
The current Quarantine configuration for the port are displayed.
Click Run Configuration Wizard.
This button is available only if the Sensor is up.
Configure Quarantine for the selected Sensor monitoring port using the Quarantine Configuration Wizard.
Note
Throughout this wizard, click Next to proceed to the next page. Click Cancel to exit the wizard without saving the changes.
Quarantine Configuration Wizard for monitoring ports.png)
Option
Definition
Use Global Settings
When selected, the Quarantine configuration from the admin domain is applied to this Sensor port. You can proceed to the next page in the wizard. However, you must have enabled Quarantine at the domain level.
To modify the Quarantine settings for the Sensor port, deselect Use Global Settings.
Would you like to quarantine endpoints that attempt intrusions?
When selected, enables the Quarantine feature for the selected port.
Would you like to intercept HTTP requests from quarantined endpoints and respond with a browser message explaining why they have been quarantined?
For the selected port, enables redirection to the Quarantine browser message and subsequently to the Remediation Portal.
Quarantine Zone
Lists the Quarantine Zones that are available for the port.
Release Logic
Automatic Release After a Specific Amount of Time — The Sensor automatically releases the host from quarantine after the time period you specify in the Release After field.
Keep in Quarantine Until Explicit Released — The Sensor quarantines the host until you manually release it.
Release After
Enter the quarantine time period (between 5 and 60 minutes), if you had selected Automatic Release After a Specific Amount of Time in the Release Logic field.
Quarantine Exceptions
Displays the details of the hosts and networks for which you do not want to quarantine.
Use Global Settings — When selected, the quarantine exceptions list from the admin domain is applied to the Sensor port. However, you must have enabled Quarantine with a quarantine exceptions list at the domain level. To customize the list for the Sensor port, deselect Use Global Settings.You can inherit the list of quarantine exceptions from the admin domain.
List Inheritance: Append — When selected, the quarantine exceptions list from the admin domain is displayed and you can add more entries to it.
List Inheritance: Override — Select to configure a separate quarantine exceptions list for the port.
New — Adds a new record to the quarantine exceptions list.
Type — Select based on how you plan to create the quarantine exceptions record. You can choose to enter the IPv4/IPv6 address of the host to be excluded, IPv4 network to be excluded, or select a IPv4 Endpoint, IPv6 Endpoint or IPv4 Network rule object.
Value — Based on your selection in the Type field, enter the IP address, network, or choose the rule object.
Description — Optionally, enter any notes regarding the quarantine exceptions record.
Edit — Select a record in the quarantine exceptions table and click this button to make changes to the Value and Description fields of that record.
Delete — Select a record in the quarantine exceptions table and click this button to delete it from the Manager database.
Import — If you have too many entries, then you can import them from a .csv file.
Finish
Saves the Quarantine configuration to the Manager database and exits the wizard.
Note
You must do a configuration update to the Sensors for these changes to take effect.
.png)