Fortinet black logo

CLI Reference

config user quarantine

config user quarantine

Configure quarantine support.

config user quarantine
    Description: Configure quarantine support.
    set firewall-groups {string}
    set quarantine [enable|disable]
    config targets
        Description: Quarantine entry to hold multiple MACs.
        edit <entry>
            set entry {string}
            set description {string}
            config macs
                Description: Quarantine MACs.
                edit <mac>
                    set mac {mac-address}
                    set description {string}
                    set drop [disable|enable]
                    set parent {string}
                next
            end
        next
    end
    set traffic-policy {string}
end

config user quarantine

Parameter

Description

Type

Size

Default

firewall-groups

Firewall address group which includes all quarantine MAC address.

string

Not Specified

quarantine

Enable/disable quarantine.

option

-

enable

Option

Description

enable

Enable quarantine.

disable

Disable quarantine.

traffic-policy *

Traffic policy for quarantined MACs.

string

Not Specified

* This parameter may not exist in some models.

config targets

Parameter

Description

Type

Size

Default

entry

Quarantine entry name.

string

Not Specified

description

Description for the quarantine entry.

string

Not Specified

config macs

Parameter

Description

Type

Size

Default

mac

Quarantine MAC.

mac-address

Not Specified

00:00:00:00:00:00

description

Description for the quarantine MAC.

string

Not Specified

drop

Enable/disable dropping of quarantined device traffic.

option

-

disable

Option

Description

disable

Sends quarantined device traffic to FortiGate.

enable

Blocks quarantined device traffic to FortiGate.

parent

Parent entry name.

string

Not Specified

config user quarantine

Configure quarantine support.

config user quarantine
    Description: Configure quarantine support.
    set firewall-groups {string}
    set quarantine [enable|disable]
    config targets
        Description: Quarantine entry to hold multiple MACs.
        edit <entry>
            set entry {string}
            set description {string}
            config macs
                Description: Quarantine MACs.
                edit <mac>
                    set mac {mac-address}
                    set description {string}
                    set drop [disable|enable]
                    set parent {string}
                next
            end
        next
    end
    set traffic-policy {string}
end

config user quarantine

Parameter

Description

Type

Size

Default

firewall-groups

Firewall address group which includes all quarantine MAC address.

string

Not Specified

quarantine

Enable/disable quarantine.

option

-

enable

Option

Description

enable

Enable quarantine.

disable

Disable quarantine.

traffic-policy *

Traffic policy for quarantined MACs.

string

Not Specified

* This parameter may not exist in some models.

config targets

Parameter

Description

Type

Size

Default

entry

Quarantine entry name.

string

Not Specified

description

Description for the quarantine entry.

string

Not Specified

config macs

Parameter

Description

Type

Size

Default

mac

Quarantine MAC.

mac-address

Not Specified

00:00:00:00:00:00

description

Description for the quarantine MAC.

string

Not Specified

drop

Enable/disable dropping of quarantined device traffic.

option

-

disable

Option

Description

disable

Sends quarantined device traffic to FortiGate.

enable

Blocks quarantined device traffic to FortiGate.

parent

Parent entry name.

string

Not Specified