Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rezafathi
Contributor II

quarantine hosts

Hello,

 

when I put a host on quarantine, it has network and internet access. why is that happen?

Reza F.
Reza F.
6 REPLIES 6
AEK
SuperUser
SuperUser

Hi Reza

Do you have a firewall policy allowing traffic from qtn.root or wqt.someting to internet?

Or do you have a firewall policy allowing traffic from "any" interface to internet?

If you have this then you just need to change it.

AEK
AEK
rezafathi
Contributor II

No i do not have these policies.

Reza F.
Reza F.
Sheikh
Staff
Staff

Hello @rezafathi ,

 

It appears that your firewall policy permits access to the internet from the Quarantine subnet. Please check this technical document for troubleshooting.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-ban-or-quarantine-an-IP-with-FortiV...

 

regards,

 

Sheikh

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
rezafathi

Ip ban works fine but mac ban not working

Reza F.
Reza F.
ebilcari
Staff
Staff

If these are WiFi hosts than you need to enable Device detection and Quarantine host at SSID level like shown here. If you check after the host get quarantined they will be shown as part of interface wqt.root (not the WiFi SSID) and by default should not exist a policy that allows network access for this interface.

quarantined.png

In case of wired hosts the interface of quarantine is part of the FortiLink named "quarantine.fortilink".

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
AEK
SuperUser
SuperUser

Hi Reza

You can debug the flow and see why the quarantined host is allowed internet access.

When a host is in quarantine, run a ping from this host to any public IP (e.g.: 1.1.1.1), and in the meantime run the below commands from FortiGate:

diag debug flow filter addr <quarantined_host_IP>
diag debug flow filter proto 1
diag debug flow show function-name enable
diag debug flow show iprope enable
diag debug flow trace start 50
diag debug enable

Once you have the output please share it and we should find the information.

AEK
AEK
Labels
Top Kudoed Authors