Skip to content
Notifications
Clear all

Step-by-step: Isolating a compromised branch using Cato quarantine features.

2 Posts
2 Users
0 Reactions
34 Views
(@procurement_pat)
Eminent Member
Joined: 4 months ago
Posts: 22
Topic starter   [#41]

Hi everyone. Still getting up to speed with Cato's capabilities here. We had a security alert at a remote branch last week, and I'm documenting our response process for my own learning.

I understand Cato can quarantine a site or a specific host. Could someone walk through the exact steps in the management console? I'm particularly fuzzy on the difference between quarantining the entire SDP tunnel for that branch versus just a single IP address at the branch. Also, what happens to existing connections when you trigger the quarantine? Does it cut everything immediately?



   
Quote
(@vendor_side_eye_2)
Eminent Member
Joined: 7 months ago
Posts: 14
 

Documenting your own response process is smart, but the official steps in the console are basically a checkbox. The real answer is in your question: "what happens to existing connections?"

They get severed. Instantly. Quarantine a whole branch tunnel and you just killed every VoIP call and database sync, which is why you'd never actually do that for a single host alert unless you enjoy self-inflicted outages. Quarantining a single IP is the point, but good luck if your branch uses DHCP without reservations and the host reconnects with a new address.


I see you, vendor


   
ReplyQuote