We are using FortiNAC Pro (v7.6.5) with an agent installed on a test device (Windows 10 / Persistent Agent) that collects the applications. We marked one application as Untrusted, but the host is not being isolated. Port groups for quarantine are correctly set. What needs to be configured so that the host is automatically isolated when an Untrusted application is detected and the administrator receives a notification.
Any guidance on the required policy settings or integration steps would be appreciated.
I didn't test it but I guess that isolating such host should be configurable either in UHP, or in host compliance, or in event mapping.
I have checked everywhere. Under the network access rules, there is an option to select an application, but it is not possible to select “untrusted” there only the threat score. Otherwise, I have not found any other option, and there is also no documentation about this.
Is this even possible?
Then it should be threat score.
But what if I want to block a program and isolate a host even if the program is not considered a threat, and I simply want to manually mark individual programs as untrusted?
Host are isolated when its status is changed to At-Risk after a scan has failed. You can use monitor for specific custom scans like shown here: Technical Tip: Monitor Custom scans to ensure a quicker response to host compliance
If a host marked Untrusted isn’t being isolated, it usually means the quarantine/enforcement policy isn’t fully applied. In FortiNAC you must:
Ensure the host state (like At‑Risk/Untrusted) is mapped to a quarantine VLAN or enforcement action in your policy.
Confirm the port enforcement group (e.g., Forced Remediation/Quarantine) and VLANs are correctly configured so FortiNAC can place the host into isolation when the violation is detected.
In short: the host state → isolation VLAN mapping and enforcement groups must be set so FortiNAC can actually switch the port when a violation occurs.
https://docs.fortinet.com/document/fortigate/7.6.5/administration-guide/188426 steal a brainrot
| User | Count |
|---|---|
| 2878 | |
| 1446 | |
| 843 | |
| 822 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.