When you configure Quarantine at the admin domain and Sensor port level, you need to specify the Quarantine Zone which must be used to quarantine hosts. At the Sensor port level, you can retain the Quarantine Zone configured at the admin domain or override it with a different Quarantine Zone. To enable you to quickly configure Quarantine, some pre-defined Quarantine Zone are provided. If these do not meet your requirements, you can clone them and edit them. If not, create Quarantine Zone according to your requirement.
Notes:
You cannot edit or delete the pre-defined Quarantine Zone.
The pre-defined Quarantine Zone belongs to the root admin domain and is visible to all the child admin domains.
Syslog forwarding is not enabled for the access rules of the pre-defined Quarantine Zone.
You cannot edit or delete a Quarantine Zone defined at a parent domain.
You cannot delete a Quarantine Zone if it is applied to a domain or Sensor port.
A configuration update of the Sensors is required for the changes to a Quarantine Zone to take effect.
You can create or edit rule objects even when creating an access rule. However, for the sake of explanation, this section assumes that you have created the required rule objects prior to creating the access rules.
Click the Policy tab.
From the Domain drop-down list, select the domain you want to work in.
Select Intrusion Prevention → Objects → Quarantine Zones.
Option
Definition
Name
Displays the name of the Quarantine Zone
Description
Displays the description of the Quarantine Zone
Ownership and Visibility
Owner Domain
Indicates the admin domain to which a Quarantine Zone belongs. All the default Quarantine Zones belong to the root admin domain.
Visibility
Indicates the visibility level of the domain
Editable here
The status Yes indicates that the policy is owned by the current admin domain.
Last Updated
Time
Displays the time when the Quarantine Zone was last modified
By
Displays the user who modified the Quarantine Zone
New
Creates a Quarantine Zone
Copy
Clones a Quarantine Zone
Edit
Displays the details of a Quarantine Zone. You can also edit a Quarantine Zone belonging to the current admin domain.
Delete
Deletes a custom Quarantine Zone belonging to the current admin domain
You can sort the list in ascending or descending order based on any of the columns by clicking on the column heading. You can also view the Columns option to enable or disable the display of the columns by selecting or deselecting the relevant check-boxes.
To create a Quarantine Zone, click New.
Specify the details on the Properties tab.
Option
Definition
Name
Enter a unique name to easily identify the Quarantine Zone.
Description
Describe the Quarantine Zone for other users to identify its purpose.
Owner
Displays the admin domain to which a Quarantine Zone belongs
Visibility
When selected, makes the Quarantine Zone available to the corresponding child admin domains. However, the Quarantine Zone cannot be edited or deleted from the child admin domains.
Editable here
The status Yes indicates that the policy is owned by the current admin domain.
Statistics
Lasted Updated
Displays the timestamp when the Quarantine Zone was last modified
Last Updated By
Displays the user who last modified the Quarantine Zone
Rules
Displays the number of access rules currently defined in the Quarantine Zone
Next
Saves the changes made on the Properties tab and displays the Access Rules tab
Cancel
Reverts to the last saved configuration
On the Access Rules tab, click the appropriate button to insert a new rule.
Option
Definition
.png)
Inserts a new rule above the currently selected rule
.png)
Inserts a new rule below the currently selected rule
.png)
Clones the currently selected rule
.png)
Deletes the currently selected rule
.png)
Moves the currently selected rule one row up
.png)
Moves the currently selected rule one row down
Double-click on each column of the access rule and specify your choices.
Option
Definition
State
Displays whether an access rule is enabled or disabled. Sensor does not apply disabled rules. This option might help you during troubleshooting.
Description
Optionally enter additional information about the rule. This might help you to easily understand the logs forwarded to the syslog server.
Destination
Select the IPv4 Endpoint or the IPv4 Network rule object.
Click
to create a new rule object.Click
to edit or view a rule object.Service
Restricts traffic based on the IP protocol, ICMP codes, or the TCP/UDP port numbers.
Click
to create a new rule object.Click
to edit or view a rule object.Response
Specify if the Sensor should allow or block traffic that matches the rule. Select Drop to discard the traffic or click or select Permit to pass the traffic.
Consider that you want to log the matched traffic details only for specific access rules. Then, select Log to Syslog? for those rules.
Note
Ensure that in the Logging page of the Sensor, the Log traffic only if the matched rule is configured to log option is selected for the Logging field.
The Log to Syslog? option has no impact if you select any other option for the Logging field in the Logging page.
OK
Saves the Quarantine Zone access rules in the Manager database. The Quarantine Zone is listed in the Quarantine Zones list.
Save
Saves all the Quarantine Zone access rules
Cancel
Reverts to the last saved configuration
Following the steps above, you can Copy, Edit or Delete the custom Quarantine Zone.