Skip to main content
ismailurek2
New Member
September 11, 2025
Question

FortiDeceptor quarantine with FortiGate - attacker quarantined too early

  • September 11, 2025
  • 1 reply
  • 381 views

Hello,

 

I am working with quarantine actions on FortiDeceptor and noticed something important. When I integrate FortiDeceptor with FortiGate for quarantine, if an attacker connects to a decoy (for example via RDP), the attacker is immediately quarantined.

 

The issue is that this prevents me from observing the attacker’s techniques and tactics in more detail, since the quarantine is triggered right away.

 

Is there any configuration or adjustment that allows FortiDeceptor to delay quarantine or to give the attacker more time to interact with the decoy before FortiGate enforces the quarantine action?

 

Thanks in advance for your guidance.

 

Regards,

İsmail Ürek

1 reply

AEK
SuperUser
SuperUser
September 11, 2025

Hi Ismail

Can you share the related trigger?

AEK
ismailurek2
New Member
September 22, 2025

Hi @AEK ,

When I connect to the Windows 10 machine via RDP, I am immediately quarantined. The relevant logs are located below.rdp_quarantine_2_log.pngrdp_quarantine_3_log.pngrdp_quarantine_log.png