Fortinet white logo
Fortinet white logo

FortiDLP Console User Guide

Isolate and deisolate

Isolate and deisolate

Requirements: Windows, macOS, or Linux.

The isolate action allows you to block a managed node's inbound and outbound TCP and UDP network traffic. If you later want to reverse this action, you can deisolate the managed node.

The isolate action can be executed manually, as described below, or automatically through policies.

Note

For legacy actions, FortiDLP will not prevent you from undoing the action of another operator. When following the steps to deisolate a node, ensure you undo the appropriate action.

How to isolate a managed node
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Filter for the relevant node. For guidance on this, see Nodes.
  3. In the Table tab, select the table row of the node.
  4. On the Node profile page, click Perform action.
  5. In the Actions dialog box, do the following:
    1. Click Isolate.
    2. Click Isolate again.

The node will display with a "Isolated" badge.

How to deisolate a managed node
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. In the Dashboard tab, click the [n] isolated nodes widget.

  3. In the Table tab, select the table row of the relevant node.
  4. At the top of the Node profile page , click Deisolate.

Isolate and deisolate

Isolate and deisolate

Requirements: Windows, macOS, or Linux.

The isolate action allows you to block a managed node's inbound and outbound TCP and UDP network traffic. If you later want to reverse this action, you can deisolate the managed node.

The isolate action can be executed manually, as described below, or automatically through policies.

Note

For legacy actions, FortiDLP will not prevent you from undoing the action of another operator. When following the steps to deisolate a node, ensure you undo the appropriate action.

How to isolate a managed node
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Filter for the relevant node. For guidance on this, see Nodes.
  3. In the Table tab, select the table row of the node.
  4. On the Node profile page, click Perform action.
  5. In the Actions dialog box, do the following:
    1. Click Isolate.
    2. Click Isolate again.

The node will display with a "Isolated" badge.

How to deisolate a managed node
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. In the Dashboard tab, click the [n] isolated nodes widget.

  3. In the Table tab, select the table row of the relevant node.
  4. At the top of the Node profile page , click Deisolate.