About the HCL BigFix Integration

eyeSight integrates with HCL BigFix® patch management to provide an automated, simplified patching process that is administered from a single Console. It provides real-time visibility and enforcement to deploy and manage patches to all endpoints – on and off the corporate network. BigFix security software identifies all of a company’s PCs, laptops, and servers, and then monitors and flags IT, administrators, when devices are not in compliance with corporate IT security standards. BigFix can make security fixes across 500,000 machines in a matter of minutes.

HCL BigFix does support Certification Compliance Mode.

Use Cases

Use Case Description
BigFix Agent compliance Installation and configuration of the BigFix Agent helps ensure full compliance on all supported endpoints within your network.
Policies designed for BigFix enforcements You can manage and automate your BigFix solution using policies to identify whether or not an endpoint is patched with all security updates. This includes a variety of commercial compliance standards and prevents network access via eyeSight for non-compliant devices.
Collect and customize BigFix host properties This module continually assesses device hygiene and continuously monitors an endpoint's security posture. eyeSight can get a customizable number of additional host details from Unix/Windows/Mac platforms, including chassis type, memory information, disk details, and more.
Configure multiple HCL BigFix servers A large site may have too many endpoints for one BigFix server to handle. A common strategy to overcome this limitation is to have multiple BigFix servers and have an endpoint be arbitrarily assigned to one of them. The request is to handle this multiserver single site topology. A large deployment can have up to eight BigFix servers.

Support for Dual-Stack Environments

eyeSight detects endpoints and interacts with network devices based on both IPv4 and IPv6 addresses. However, IPv6 addresses are not yet supported by this module. The functionality described in this document is based only on IPv4 addresses. IPv6-only endpoints are typically ignored or not detected by the properties, actions, and policies provided by this module.