Use Automatic Overlapping IP Addresses for the Command Center

IP Reuse Domains distinguish each instance of an overlapping IP address. Within each IP Reuse Domain, IP addresses are unique and cannot overlap.

The Automatic Overlapping IP Addresses option is available as an alternative to Mapping IP Reuse Domains to the Command Center, when mapping a specific IP Reuse Domain to a specific Appliance is not required, so that automatic load balancing can be applied.

Use the Automatic Overlapping IP Addresses implementation for a highly distributed Overlapping IP environment, in which there are a large number of monitoring sensors, and there is no need for an Appliance to reside in that environment. Although some of the capabilities of the IP Reuse Domains Mapping Implementation will be unavailable, the Automatic Overlapping IP implementation supports a large number of monitoring sensors without the need to use multiple Enterprise Managers.

For this option, there is no one-to-one relation between an Appliance and an IP Reuse Domain. A single Appliance may manage endpoints from multiple IP Reuse Domains. You cannot control which Appliance manages which IP Reuse Domain because the process is automatic.

For Operational Technology endpoints, when a host name is provided, the Host Column in the Forescout Console NAC view displays this name.

When no host name is provided, the Host Column displays the following format (in the external IP Reuse Domain):

<IPv4>@<IRD ID>@<CC host>

Where:

<IRD ID> is the Operational Technology IP Reuse Domain internal id (normally a number)

<CC host> is the Command Center host name or IP address, depending on how the endpoint was added to the Operational Technology Plugin.

This option enables you to select endpoints in Forescout policies or list endpoints in Asset Inventory View using the following properties:

  • OT IP Reuse Domain
  • OT Sensor Names
  • External IP Reuse Domain.

This option also enables you to group endpoints in Assets View (part of the Forescout Web Client) using the following properties:

  • OT IP Reuse Domain
  • OT Sensor Name
  • External IP Reuse Domain.
Note: Refer to the Automatic Overlapping IP Addresses End-to-End Configuration for the complete configuration process for this implementation.

To enable Automatic Overlapping IP Addresses for the Command Center:

  1. Select Tools > Options > Operational Technology,, and then select the Overlapping > IP Addresses tab.
  2. Select the Use Automatic Overlapping IP Addresses option.
  3. Select OK.
  4. Select Apply.