Quarantine
Create and edit quarantine locations in the Security Fabric. Quarantine supports SMB, NFS, AWS S3, Azure File Share, Azure Blob Storage, Google Cloud Storage, MS One Drive and SFTP mount types. To view the quarantine information, go to Security Fabric > Quarantine .
Quarantine is only available in the Primary node of an HA cluster |
The following options are available:
Create New |
Select to create a new quarantine location. |
Edit |
Select an entry from the list and then select Edit in the toolbar to edit the entry selected. When editing an entry you can select to test connectivity to ensure that the quarantine location is accessible. |
Delete |
Select an entry from the list and then select Delete in the toolbar to remove the entry selected. |
Test Connection |
Test the selected entry's connection. The result is displayed in the banner at the bottom right corner. |
The following information is displayed:
Name |
The name of the quarantine location. |
Type |
The mount type. |
Share Path |
The file share path. |
Enabled |
Displays if the quarantine location is enabled. |
Status |
Displays the quarantine access status. One of the following states:
Click Test Connection to show the connection status (AWS S3, Azure Blob Storage, Google Cloud Storage, MS One Drive and SFTP). |
To create a new quarantine entry:
- Go to Security Fabric > Quarantine.
- Click the Create New button from the toolbar.
- Configure the following options:
Enabled
Select to enable quarantine location.
Quarantine Name
Enter the quarantine name.
Mount Type
Select the mount type from the dropdown list. The following options are available:
- CIFS (SMB v1.0, v2.0, v2.1, v3.0 and v3.1)
- NFSv2, NFSv3, NFSv4
AWS S3, AWS S3 BJ, AWS S3 NX
- Azure File Share. See Azure File System .
- Azure Blob Storage. See Azure Blob Storage.
Google Cloud Storage. See:Google Cloud
MS One Drive. See Microsoft OneDrive
SFTP
Server Name/IP
Enter the server fully qualified domain name (FQDN) or IP address.
Share Path
Enter the file share path. In the format
/path1/path2
.Username
Enter a user name. For a domain user, use the format
domain_name\user_name
.Password
Enter the password.
Confirm Password
Enter the password a second time for verification.
Keep Original File At Current Location
Select to keep the original file at the current location when a file is quarantined from a network share. By default, the original file is kept at its current location when being moved.
NOTE: Configuring this setting may affect when the original files are kept, deleted and transferred after a network share scan. For detailed information, see Configure Network share to keep, delete or transfer files in the FortiSandbox Best Practice guide.
Enable/Disable
Enable: Keep the original file at its network share location.
Disable: Allow FSA to delete the original file from the network share location.
By default, the original file is kept at its current location.
A Copy of Original File
Select to keep the original file at the current network share location without change. By default, the original file is kept at its current location without change.
A Placeholder File Showing File is Quarantined
Select to allow FortiSandbox remove the original file from the network share location and .quarantine files generated for non CLEAN files.
Description
Enter an optional description for the quarantine location entry.
- Select OK to save the entry.
To edit a quarantine:
- Go to Security Fabric > Quarantine.
- Select a quarantine.
- Click the Edit button from the toolbar.
- Make the necessary changes.
- Click OK to save the entry.
To delete a quarantine:
- Go to Security Fabric > Quarantine.
- Select a quarantine.
- Click the Delete button from the toolbar.
- Click Yes I'm sure button from the Are you sure confirmation box.