Skip to content
Playbook Connectors on Content Hub

Isolate OT devices on a FortiGate

Moves an OT or IoT asset into an isolation address group on a FortiGate and releases it after approval.

@ftnt-dspilleMaintainer v1.0.1 Platform 7.4.0+ Published Oct 6, 2026 Updated Oct 6, 2026
Download JSON · 50 KB

ot-device-isolation-1.0.1.json

sha256:c6c4e8317f817455bb5f36dceaec83715131dac727e75ca31bc9daa5805baf83

Sanitized by the pipeline and shipped inactive. Follow the before turning it on.

Contains an OT or IoT device by moving it into an isolation address group on a FortiGate, and releases it again. The policies on that group do the blocking.

  • Step 1. Prep Fortigate (run once): creates address objects for your assets, the isolation address group and the firewall policies for it. The policies are pushed over SSH.
  • Add device to OT Isolated Group: after an analyst confirms, adds the asset's address to the group and marks the asset Isolated.
  • Remove device from OT Isolated Group: waits for an approval, then removes the address and marks the asset Active.

Needs the FortiGate connector. The SSH step reads the login from the global variables FGT_SSH_Username and FGT_SSH_Password, so create them first. Review the policy script in the Set vars step against your own interfaces and VDOM.

The release approval step ships unassigned. Assign it to your approver team before you activate the playbook, so the person who asks for the release is not the one who approves it.

Something wrong with this item? Sign in to report

Report a problem

Sensitive data, copied content, broken imports, anything that shouldn't be here.

At least 10 characters. Please don't paste the sensitive value itself.0/1000