Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ismailurek2
Contributor

FortiDeceptor quarantine with FortiGate - attacker quarantined too early

Hello,

 

I am working with quarantine actions on FortiDeceptor and noticed something important. When I integrate FortiDeceptor with FortiGate for quarantine, if an attacker connects to a decoy (for example via RDP), the attacker is immediately quarantined.

 

The issue is that this prevents me from observing the attacker’s techniques and tactics in more detail, since the quarantine is triggered right away.

 

Is there any configuration or adjustment that allows FortiDeceptor to delay quarantine or to give the attacker more time to interact with the decoy before FortiGate enforces the quarantine action?

 

Thanks in advance for your guidance.

 

Regards,

İsmail Ürek

2 REPLIES 2
AEK
SuperUser
SuperUser

Hi Ismail

Can you share the related trigger?

AEK
AEK
ismailurek2

Hi @AEK ,

When I connect to the Windows 10 machine via RDP, I am immediately quarantined. The relevant logs are located below.rdp_quarantine_2_log.pngrdp_quarantine_3_log.pngrdp_quarantine_log.png

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors