About Command Line Access
This reference guide describes how to use the Forescout® command line interface (CLI) on the Forescout eyeSight.
This guide covers important and useful FS-CLI and fstool commands for use with Forescout Enterprise Managers and Appliances to aid in system installation and administration. Still, it should not be considered a comprehensive listing of all commands available to the user.
FS-CLI
FS-CLI is a proprietary Forescout command line interface that is designed to comply with security certification requirements. When FS-CLI is enabled, you can run FS CLI Commands via the CLI. When FS-CLI is not enabled, a different set of commands is available. See The fstool Command Set by Categories for available commands.
The FS-CLI is installed by default in all eyeSight systems:
- If you performed a clean installation, FS-CLI is installed and running when you access the CLI.
- If you performed an upgrade, FS-CLI is installed, but the operating system's Bash shell is still running when you access the Forescout device CLI. To exit the Bash shell and enter FS-CLI, submit the command
fstool cliin the Bash shell.
To exit the FS-CLI and access the operating system's Bash shell, submit the command shell in the FS-CLI.
To enable FS-CLI:
- Log in to the CounterACT Appliance CLI (Bash shell) as root.
- Run:
fstool cli install. Once enabled, you can access FS-CLI directly via SSH as the cliadmin user.
If not enabled, you can access FS-CLI manually:
- Log in to the CounterACT Appliance CLI (Bash shell) as root.
- Run:
fstool cli
To return to the Bash shell: Run: shell
User Roles and Permissions
You can add new CLI users and grant user permissions to perform specific operations within the CLI. You can also update permissions for existing users. See user--Configure User Roles and Permissions
FS-CLI in Certification Compliance Mode
When Forescout eyeSight is running in Certification Compliance mode, FS-CLI is the only command line interface available, and the user cannot access Bash or operating system shell commands. For more information about Certification Compliance mode, refer to Certification Compliance in the Forescout eyeSight Installation Guide.
See user - Configure User Roles and Permissions for more information.
Entering CLI Commands
After successful login, enter the ? character to list available commands.
Submit commands in the format shown in this guide and other Forescout documentation. Most commands are shown with the optional fstool prefix. This prefix can be omitted when you enter commands in FS-CLI, but must be included when you enter commands in the Bash shell.
For example, the following commands yield the same result in FS-CLI:
fs-cli@em1>fstool ntp test
fs-cli@em1>ntp test
Entering Privileged Commands
When working in the FS-CLI shell (vs. the BASH shell) of a Forescout device, users must provide their Linux sudo password to run fstool commands that are classified as privileged. This mitigates unauthorized usage of these commands.
- The password to provide is the user's own Linux sudo password (their login credential)
- When user attempts to execute a privileged fstool command, the user is then prompted to enter their Linux sudo password
- Once the user enters their password, it is cached for 5 minutes per session (the default cache period). There is no caching between SSH sessions.
The following example shows the sudo prompt when a user, working in the CLI shell of a Forescout device, attempts to run a privileged fstool command:
cliadmin@ em>shell [sudo] password for cliadmin testadmin@ em>user list [sudo] password for testadmin:
minute read