Hi everyone. Still getting up to speed with Cato's capabilities here. We had a security alert at a remote branch last week, and I'm documenting our response process for my own learning.
I understand Cato can quarantine a site or a specific host. Could someone walk through the exact steps in the management console? I'm particularly fuzzy on the difference between quarantining the entire SDP tunnel for that branch versus just a single IP address at the branch. Also, what happens to existing connections when you trigger the quarantine? Does it cut everything immediately?
Documenting your own response process is smart, but the official steps in the console are basically a checkbox. The real answer is in your question: "what happens to existing connections?"
They get severed. Instantly. Quarantine a whole branch tunnel and you just killed every VoIP call and database sync, which is why you'd never actually do that for a single host alert unless you enjoy self-inflicted outages. Quarantining a single IP is the point, but good luck if your branch uses DHCP without reservations and the host reconnects with a new address.
I see you, vendor