Created on
07-12-2023
09:54 PM
Edited on
08-22-2024
10:10 PM
By
Jean-Philippe_P
Description | This article describes how to restore the quarantine file blocked by the real-time scan. |
Scope |
FortiClient, Restore files in EMS for managed endpoints. |
Solution |
When a file is blocked by FortiClient real-time scan, it is visible in the Malware Protection -> Quarantine Files section.
In EMS -> Quarantine Management -> Files, it is also possible to see this file visible here. To allow this file, select it, then select the 'Allowlist & Restore' button. Note that if the file was allowed before, this button does not show up anymore.
After selecting the button, the pop-up below appears. Select 'Yes' to allow this quarantined file.
Finally, go to EMS -> Quarantine Management -> Allowlist and double-check that the file is in this list.
Note: For the EMS On-premise deployment, communication from FortiClients to EMS on port 10443 must be enabled as it is the default port used for the allowlist signature download. If the port is blocked, the FortiClient will not download the signature list and the file will not be restored. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.