FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
jie
Staff
Staff
Article Id 263770
Description This article describes how to restore the quarantine file blocked by the real-time scan.
Scope

FortiClient, Restore files in EMS for managed endpoints.

Solution

When a file is blocked by FortiClient real-time scan, it is visible in the Malware Protection -> Quarantine Files section.

 

1.PNG 

In EMS -> Quarantine Management -> Files, it is also possible to see this file visible here.

To allow this file,  select it, then select the 'Allowlist & Restore' button. Note that if the file was allowed before, this button does not show up anymore.

 

2.PNG

 

After selecting the button, the pop-up below appears. Select 'Yes' to allow this quarantined file.

 

3.PNG

 

Finally, go to EMS -> Quarantine Management -> Allowlist and double-check that the file is in this list.

 

4.PNG

 

Note:

For the EMS On-premise deployment, communication from FortiClients to EMS on port 10443 must be enabled as it is the default port used for the allowlist signature download. If the port is blocked, the FortiClient will not download the signature list and the file will not be restored.