Hi Morten,
I noticed that Arnold working only if the vlan seed db is completed (in my case ),the steps are as follows
Feed Usage categories for each net/vlan , next in Vlan section i am feeding each vlan/network detected and done , i noticed that the vlan i am quarantine interested all detected as Net type >core.
The settings stay for a while after some time is back to prior to db feed status , with no vlan , ip association .
As for Arnold host quarantine , I wrote TCP client/server in python v 3.44 which the client i turned into exe and attach on each windows machine using event trigger in case of Symantec infection(its can be set to any other event) , the event trigger execute the client which sends in SSL the event and the server will execute start_arnold ,I am i intend to expand the feathers and sends evends from our firewall's IPS(Snort) and execute upon pre-configured event rules arnold_trigger.
Maybe its time to give back to the community , i am willing to share my project if someone is interested , i can upload it to Github or what ever.
Thanks