Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pgoe
New Contributor

Forticlient Mac: How to un-quarantine a file?

The forticlient (for mac) user interface does not allow any operation on the quarantined files. How to un-quarantine a file on Forticlient 5.0.6.131 for Mac (10.9.1)? Quarantined files are apparently stored under the path: /Library/Application Support/Fortinet/FortiClient/data/quarantine but the files are prepended by some metadata such as the original path, an indication of the process accessing the file, and the identification of the contained virus, followed by an encrypted version of the file. How can I restore the original file for further analysis? Additionally: the bin folder has several executables: some of them are obvious (e.g. racoon) and information on their common-line use is generally available on the web, but for others (scanunit, vulscan) documentation is missing. can anyone point me to the documentation? Thanks, Peter
6 REPLIES 6
Ertan
New Contributor

I don' t know the mac interface, but I feel it is more or less same as windows version. So, don' t you have a restore button in your quarantine view? You can get there from AntiVirus view by clicking " Threats Quarantined" link. Don' t know about documentation. Ertan
pgoe
New Contributor

@Ertan The button you mention is deactivated (greyed out)
Chris_Lin_FTNT

Does the GUI have enough permission? I thought FortiClient GUI usually not running as admin in MAC. Can you check?
pgoe
New Contributor

@ Chris.Lin: Thanks for the suggestion. Several processes are running: FortiClient (Console) and FortiClientAgent. These run as the logged in user (which may or may not be a member of admin and wheel groups). The scanunits run as root. As an experiment, I launched the FortiClient console as " root" , it still has the buttons greyed out. The console should not permanently run as root - that would be a security risk, but it would need to request for admin password to temporarily gain elevated privs on a as needed basis. As an additional experiment I made the quarantined virus file writable to all ( sudo chmod 666 Untitled.txt.0 ). This did not help either. So the question is still open/unresolved - and the lack of technical documentation (for MacOS - is not helping) -- Peter
Ertan
New Contributor

I know that you need to gain permission even under windows 7-8 to do certain operations. Changing parental control settings is one of them. Not sure, but maybe you need to elevate your permissions within FortiClient Console rather than running it as root. Elevated state continues until you close the Console in my case.
pgoe
New Contributor

Ertan, you provided the correct hint: One has to first click on the lock icon in the main window (bottom left). This is hidden once one has clicked on the quarantined threats. Not the best UI design... but now I won' t forget... QUESTION ANSWERED
Labels
Top Kudoed Authors