Fortinet black logo

Administration Guide

FortiSwitch quarantine setup example

FortiSwitch quarantine setup example

FortiNDR supports quarantining devices that are connected to a FortiSwitch which is managed by FortiGate. FortiSwitch is connected to a FortiGate and is configured in FortiLink mode. FortiNDR will utilize FortiGate’s incoming webhook to provide the device's MAC address for quarantine/undo quarantine.

For information about configuring FortiLink, see Configuring FortiLink.

To setup FortiSwitch quarantine on FortiNDR:
  1. Following the steps for creating a webhook on FortiGate in FortiGate quarantine webhook setup example. Note that the CLI script for quarantine and undo quarantine should be updated.

    Note

    The CLI script for quarantine and undo quarantine should be updated.

  2. Register webhooks on FortiNDR .
    Note

    The device settings such as IP and Port are the IP and port of the managing FortiGate device.

  3. Click the Test button to test the current configuration.

  4. Click OK.

FortiSwitch quarantine setup example

FortiNDR supports quarantining devices that are connected to a FortiSwitch which is managed by FortiGate. FortiSwitch is connected to a FortiGate and is configured in FortiLink mode. FortiNDR will utilize FortiGate’s incoming webhook to provide the device's MAC address for quarantine/undo quarantine.

For information about configuring FortiLink, see Configuring FortiLink.

To setup FortiSwitch quarantine on FortiNDR:
  1. Following the steps for creating a webhook on FortiGate in FortiGate quarantine webhook setup example. Note that the CLI script for quarantine and undo quarantine should be updated.

    Note

    The CLI script for quarantine and undo quarantine should be updated.

  2. Register webhooks on FortiNDR .
    Note

    The device settings such as IP and Port are the IP and port of the managing FortiGate device.

  3. Click the Test button to test the current configuration.

  4. Click OK.