Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rcpdkc
Contributor II

Fortinac Check Dns

Hello, how can I quarantine the user's DNS address in fortinac if it is an address other than the DNS address I specified?

10 REPLIES 10
AEK
SuperUser
SuperUser

Hello

I'm not sure to understand what you mean by user's DNS,

but here is how you can quarantine a USER:

  • Go to menu Users & Hosts > Hosts
  • Right-click on the user(s)
  • Click the Disable Users sub menu

On the other hand you can quarantine a HOST this way:

  • Users & Hosts > Hosts
  • Right-click the host(s)
  • Click the Disable sub-menu

Once you do that, the disabled host should go to dead-end/isolation, and any host that the user logs-on will go to dead-end/isolation.

AEK
AEK
rcpdkc
Contributor II

 When Windows changes the DNS manually and this DNS address is not the one I specified 

 

ndumaj
Staff
Staff

Hello,

well it depends, you can also manually disable that host via host view list or what I can suggest is to use Persistent agent and add custom scan for domain joined users.
https://docs.fortinet.com/document/fortinac/9.4.0/administration-guide/156414/endpoint-compliance

BR

- Happy to help, hit like and accept the solution -
ebilcari
Staff
Staff

If I understood this correctly, you want to disable port/host in case it uses a DNS other than specified. Since this is not a static configuration value (checked via registry, processes) it can't be identified by the agent scans. It's better to use the Firewall to report this behavior as an incident and than map it to an Action in FNAC to disable the host or mark it as at risk.

 

sec incidents.PNG

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
rcpdkc

I tried to check with registry but can't because it matches another value

AEK

I fully agree with @ebilcari , the solution is to detect the traffic at firewall level and to send the event to NAC so it isolates the client.

AEK
AEK
rcpdkc
Contributor II

I don't quite understand how to do this

ebilcari

You can check this video on Fortinet Video Library for more details.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
rcpdkc

I don't have this menu, is it licence related?

Labels
Top Kudoed Authors