Fortinet black logo

EMS Administration Guide

Quarantining an endpoint from FortiOS using EMS

Quarantining an endpoint from FortiOS using EMS

In FortiOS 6.0, an administrator can quarantine FortiClient endpoints using EMS by enabling the Quarantine FortiClient via EMS option. The following lists the requirements for this feature:

  • The FortiClient endpoint is connected to FortiGate and managed by EMS
  • The FortiClient endpoint and FortiGate use the same FortiAnalyzer
  • The EMS managing the FortiClient endpoint is configured on the FortiGate. FortiOS allows configuration of up to three EMS servers to allow endpoint control in different locations.

    Configuring Quarantine FortiClient via EMS requires using the FortiOS CLI to set the following fields: automation-stitch and forticlient-ems. See the FortiOS CLI Reference.

If Quarantine FortiClient via EMS is enabled, the following occurs when an indicator of compromise (IOC) is detected on an endpoint in the Security Fabric:

  1. An IOC is detected on an endpoint.
  2. FortiOS sends the endpoint information to EMS with instructions to quarantine the endpoint.
  3. EMS identifies and quarantines the endpoint based on the request from FortiOS.

You can remove the endpoint from quarantine using EMS as described in Quarantining an endpoint or using FortiOS by following the procedure described below:

  1. The administrator identifies that EMS has quarantined an endpoint from one of the following:
    1. FortiClient on the endpoint
    2. Quarantine Management or FortiClient Monitor in FortiOS
    3. Endpoints pane in EMS
  2. The administrator removes the endpoint from quarantine in FortiOS.
  3. FortiOS sends the endpoint information to EMS with instructions to remove the endpoint from quarantine.
  4. EMS identifies and removes the endpoint from quarantine based on the request from FortiOS.

Quarantining an endpoint from FortiOS using EMS

In FortiOS 6.0, an administrator can quarantine FortiClient endpoints using EMS by enabling the Quarantine FortiClient via EMS option. The following lists the requirements for this feature:

  • The FortiClient endpoint is connected to FortiGate and managed by EMS
  • The FortiClient endpoint and FortiGate use the same FortiAnalyzer
  • The EMS managing the FortiClient endpoint is configured on the FortiGate. FortiOS allows configuration of up to three EMS servers to allow endpoint control in different locations.

    Configuring Quarantine FortiClient via EMS requires using the FortiOS CLI to set the following fields: automation-stitch and forticlient-ems. See the FortiOS CLI Reference.

If Quarantine FortiClient via EMS is enabled, the following occurs when an indicator of compromise (IOC) is detected on an endpoint in the Security Fabric:

  1. An IOC is detected on an endpoint.
  2. FortiOS sends the endpoint information to EMS with instructions to quarantine the endpoint.
  3. EMS identifies and quarantines the endpoint based on the request from FortiOS.

You can remove the endpoint from quarantine using EMS as described in Quarantining an endpoint or using FortiOS by following the procedure described below:

  1. The administrator identifies that EMS has quarantined an endpoint from one of the following:
    1. FortiClient on the endpoint
    2. Quarantine Management or FortiClient Monitor in FortiOS
    3. Endpoints pane in EMS
  2. The administrator removes the endpoint from quarantine in FortiOS.
  3. FortiOS sends the endpoint information to EMS with instructions to remove the endpoint from quarantine.
  4. EMS identifies and removes the endpoint from quarantine based on the request from FortiOS.