The Banned User List - Fortinet FortiGate Series Administration Manual

Hide thumbs Also See for FortiGate Series:
Table of Contents

Advertisement

NAC quarantine and the Banned User list

The Banned User list

680
edit icmp_flood
set quarantine both
end
end
For more information, see the
The Banned User list shows all IP addresses and interfaces blocked by NAC quarantine.
The list also shows all IP addresses, authenticated users, senders, and interfaces blocked
by Data Leak Prevention (DLP). The system administrator can selectively release users or
interfaces from quarantine or configure quarantine to expire after a selected time period.
All sessions started by users or IP addresses on the Banned User list are blocked until the
user or IP address is removed from the list. All sessions to an interface on the list are
blocked until the interface is removed from the list.
You can configure NAC quarantine to add users or IP addresses to the Banned User list
under the following conditions:
Users or IP addresses that originate attacks detected by IPS - To quarantine users
or IP addresses that originate attacks, enable and configure Quarantine Attackers in
an IPS Sensor Filter. For more information, see
IP addresses or interfaces that send viruses detected by virus scanning - To
quarantine IP addresses that send viruses or interfaces that accept traffic containing a
virus, enable Quarantine Virus Sender in a protection profile. For more information,
see
"Anti-Virus options" on page
Users or IP addresses that are banned or quarantined by Data Leak Prevention -
Set various options in a DLP sensor to add users or IP addresses to the Banned User
list. For more information, see
sensor" on page
585.
To view the Banned User list, go to User > Monitor > Banned User.
Figure 424: Banned User list
Clear
Current Page
Current Page The current page number of list items that are displayed. Select the left and right
arrows to display the first, previous, next or last page of banned users or IP
addresses.
Clear icon
Remove all users and IP addresses from the Banned User list.
#
The position number of the user or IP address in the list.
Application
The protocol that was used by the user or IP address added to the Banned User
list.
Protocol
FortiGate CLI
Reference.
"Configuring filters" on page
489.
"Adding or editing a rule or compound rule in a DLP
FortiGate Version 4.0 MR1 Administration Guide
540.
Delete
01-410-89802-20090903
http://docs.fortinet.com/
Feedback
User

Advertisement

Table of Contents
loading

Table of Contents