Map IP Reuse Domains to Command Center

Networks in plant/production, building automation, and other Operational Technology environments often contain duplicate sites and network structures. IP addresses repeat, or overlap, across the network.

To support these networks, the eyeSight - eyeInspect solution uses IP Reuse Domains to distinguish several instances of an overlapping IP address. You define a unique IP Reuse Domain for each repeated segment or network branch. IP addresses are unique in each IP Reuse Domain.

  • In eyeSight, IP Reuse Domains are assigned to Appliances. Identical segments are distinguished from each other by the IP Reuse Domain of the Appliance that manages each segment.
  • In eyeInspect, IP Reuse Domains are defined in the Command Center Console and assigned to selected Sensors.

After you Configure Operational Technology Plugin Connections to the Command Center, you must correlate the IP Reuse Domains defined in the two platforms.

Use this procedure to map the IP Reuse Domains defined in Forescout Platform (eyeSight) to the IP Reuse Domains defined in Forescout Platform (eyeInspect). Repeat this procedure when you change IP Reuse Domain definitions in either platform.

Refer to the IP Reuse Domains Mapping Implementation End-to-End Configuration in the Working with Overlapping IPs How-to Guide for the complete configuration process for this implementation.

To map IP Reuse Domains to the Command Center:

  1. Review the IP Reuse Domains defined for Forescout Platform from the Forescout Console, by selecting Tools > Options > Forescout Devices > Overlapping IPs Management. The table shows the segments in each IP Reuse Domain. Select Export to export IP Reuse Domain information.
  2. Select Tools > Options > Operational Technology, and then select the Overlapping IP Addresses tab.
  3. Select the Use IP Reuse Domain Mapping option.
  4. To define mapping between an IP Reuse Domain defined in the Forescout Internal Network and IP Reuse Domains defined in the eyeInspect Command Center:
    1. Select Add , or select an existing rule and then select Edit.
    2. In the Internal Network IP Reuse Domain drop-down list, select an IP Reuse Domain.
    3. In the Command Center IP Reuse Domains drop-down list, select an IP Reuse Domain. Domains are shown for all connected Command Centers.
    4. Select OK.
  5. Repeat previous steps for all other mappings. All non-mapped Command Center IP Reuse Domains will default to the Global IP Reuse Domain of Forescout Platform.
  6. Select Apply to save the mappings.

Avoid Host Duplication When Installing or Upgrading the OT Plugin

When the OT Plugin exchanges host data between eyeInspect Command Center (CC) and eyeSight, duplicate host records can appear if the IP Reuse Domain (IRD) mapping is not configured at the correct time. To prevent this, follow the steps outlined in the installation and upgrade pages.

Clean Up Existing Duplicates

If duplicate host records already exist (from a mapping change applied at the wrong time or a past upgrade):

  1. Confirm the IP Reuse Domain (IRD) mapping is now correct on both eyeInspect and eyeSight for all Command Centers.

  2. In eyeSight, remove the stale, untagged, or incorrectly tagged host records manually. This can be done from Forescout Console by right clicking the host and selecting Delete. Do not wait for retention expiry if the duplicates are actively causing confusion in reports or alerts.

  3. After the next sync cycle, verify that only one record per physical host remains.