There are two methods to quarantine hosts:
Configure the Sensor to quarantine hosts automatically when they generate specific attacks.
Manually quarantine specific hosts that are listed in the Attack Log.
Quarantine configurations — To manually quarantine hosts from Attack Log, you must configure Quarantine on the Sensor inline monitoring port that detected the corresponding attack from the host. You can have a different configuration for each port of a port-pair. As part of this configuration, you specify a Quarantine Zone for a monitoring port. The Sensor restricts the hosts to be quarantined to this zone. That is, the hosts are isolated in this zone thereby preventing further damage.
Note
If you have enabled XFF header parsing for your Sensor, any quarantining of an attacking host is carried out on the original source IP address and not the IP address obtained from the IP header.
For the Sensor to automatically quarantine hosts, two levels of configurations are required. One is the Sensor port configuration as explained above. The second level configuration is enabling Quarantining for the required attacks. Only a sub-set of the attacks are eligible for Quarantining. In the IPS and Reconnaissance policies applied on the Sensor port, locate the eligible attacks and enable Quarantining for the ones that you need.
To implement Quarantine, you configure it for the required inline monitoring ports.
Important
The Sensor internally maintains data related to your network hosts in a table referred to as the host table. This table also contains data such as the hosts that are quarantined, the duration of the quarantine, and so on. If the Sensor reboots, the quarantine data in the Sensor's host table is cleared. So, hosts that were in quarantine before the reboot will now be out of quarantine.
You will have to re-quarantine the hosts that you had manually quarantined before the reboot. You manually quarantine hosts from Attack Log.
For hosts that were quarantined because of attacks, the Sensor will quarantine them again only when it detects those attacks from the hosts.
Quarantine Zones — Quarantine zones contain a ordered set of firewall-type Access Control List (ACL) rules. These rules define what a host can and cannot access when in quarantine. In effect, you use these rules to isolate hosts to only the allowed network resources. For example, you can restrict hosts only to the remediation portal for the duration of the quarantine. These ACL rules are referred to as Access Rules.
In each Access Rule, you specify the destination IP address or IP network, the service, and the response action the Sensor should take if the destination and service match. The response action can be to allow or drop the matched traffic.
When a Sensor identifies a host to be quarantined, it applies the quarantine zone specified for the corresponding monitoring port. When the host sends some traffic, the Sensor matches this traffic against the access rules in the quarantine zone in a top-down fashion. If the traffic matches with an Access Rule, it allows or drops the traffic as specified. Like in ACL, the Sensor does not match the remaining rules after the match. If none of the rules match, then the Sensor permits the traffic. You can also configure the Sensor or the Manager to forward the details of matched traffic to a syslog server.
There are some pre-defined quarantine zones available. You cannot directly modify them or delete them. If these quarantine zones do not meet your requirements, you can clone and then modify them. If required, you can also create an entirely new quarantine zone.
Redirection of hosts — When a quarantined user accesses a location, the Sensor can be configured to redirect HTTP traffic and display a message. Further, you can configure the Sensor to send the user to a remediation center. The message can display the reason for quarantine, the duration, the current user details and so on.
Duration of quarantine — You can specify the number of minutes a host needs to be quarantined. Alternatively, you can quarantine a host until you manually release it from the Quarantine page. In case of automatic quarantining by the Sensor, you specify the quarantine period when enabling Quarantine for a Sensor port. In case of manual quarantining from Attack Log, you specify the duration when you quarantine the host.
Quarantine Exceptions — There can be some hosts that you might want to exclude from automatic or manual quarantine. You can define an allow list of hosts that are to be exempted per monitoring port. These allow lists are referred to as Quarantine Exceptions.