Configure an Appliance
This topic describes how to configure your Appliance. Most configuration definitions set here can later be changed through the Console. Refer to the Administration Guide for more information.
If the installation is interrupted or if you selected the wrong version, you need to re-image the Appliance with the relevant version of the ISO file. See Re-image Forescout Devices for more information.
Some variations may apply to virtual systems. See Forescout Virtual Systems for details.
To configure an Appliance:
- Power on the Appliance. The following menu appears:
Forescout <version>-<build> options: 1) Configure Forescout 2) Restore saved Forescout configuration 3) Identify and renumber network interfaces 4) Configure keyboard layout 5) Turn machine off 6) Reboot the machine Choice (1-6) :
- To identify the ports on the rear panel of the Appliance, select Identify and renumber network interfaces and press Enter. Text is displayed indicating which interface has been detected. The associated port LED blinks on the rear panel.
- Label the port on the panel so that it is easily identifiable, and press Enter. More text is displayed indicating the next detected interface. The associated port LED now blinks.
- Label this port as well and press Enter. This process continues until all active interfaces are detected and you have labeled the associated port for each active interface.
- Once all interfaces have been detected, press Enter.
Forescout <version>-<build> options: 1) Configure Forescout 2) Restore saved Forescout configuration 3) Identify and renumber network interfaces 4) Configure keyboard layout 5) Turn machine off 6) Reboot the machine Choice (1-6) :
- Type 1 and then press Enter.
Select High Availability mode: 1) Standard Installation 2) High Availability - Primary Node 3) Add node to existing Active Node (Primary or Secondary) Choice (1-3) [1] :
- Type 1 and then press Enter.
>>>>>> Forescout platform Initial Setup <<<<<< You are about to setup the Forescout platform. During the initial setup process you will be prompted for basic parameters used to connect this machine to the network. When this phase is complete, you will be instructed to complete the setup from the Console.Continue ? (yes/no) : - Type Yes, and then press Enter.
The following prompt appears when running a clean installation of this version. Certification Compliance Mode? (yes/no) [no] :
- Unless your organization needs to comply with Common Criteria and DoDIN APL certification, type No for Certification Compliance mode. See Certification Compliance for more information.
Would you like to enable disk encryption [yes/no] [no] :
- Optionally enable / disable disk encryption, and then press Enter.
>>>>>> Select Forescout Installation Type <<<<<< 1) Forescout Appliance 2) Forescout Enterprise Manager Choice (1-2) : - Type 1, and then press Enter. The setup is initialized. This may take a few moments.
- The Select Licensing Mode
screen appears for Forescout machines that support both Per-Appliance and Flexx
licensing modes.
41xx, 51xx, and 61xx series Forescout machines support only Flexx licensing mode. >>>>>> Select Licensing Mode <<<<<< 1) Per Appliance Licensing Mode 2) Flexx Licensing Mode Choice (1-2) [1]:The licensing mode is determined during purchase. Do not type a value until you have verified what licensing mode your deployment uses. Contact your Forescout representative to verify your licensing mode or if you entered the wrong mode Type 1 for the Per-Appliance Licensing Mode, and then press Enter.
Type 2 for the Flexx Licensing Mode, and then press Enter.
>>>>>> Enter Machine Description <<<<<< Enter a short description of this machine (e.g. New York office). Description [Appliance} : - Type a description for the machine, and then press Enter.
>>>>>> Set Administrator Password <<<<<< This password is used to log in as 'cliadmin' to the machine Operating System and as ’admin’ to the Console. The password must be between 6 and 24 characters long and should contain at least one non-alphabetic character. Administrator password : - Type the string that is to be your password (the string is not echoed to the screen) and press Enter. You are asked to confirm the password.
Administrator password (confirm) :
- Retype the password (the string is not echoed to the screen) and press Enter.
>>>>>> Set Host Name <<<<<< It is recommended to choose a unique host name.Host name :
- Type a host name and press Enter. The host name can be used when logging into the Console. In addition, it is displayed on the Console to help you identify the Forescout Appliance that you are viewing. The hostname should not exceed 13 characters. The
Management interfaceprompt is displayed (subsequent prompts are displayed after you enter a value for the preceding prompt):>>>>>> Configure Network Settings <<<<<< Management IP address : Network mask [255.255.255.0] : Default gateway : Domain name : DNS server addresses : Management IPv6 address or 'auto' or ’none’ :
- The number of management interfaces listed depends on the Appliance model.
- The Management IP address is the address of the interface through which components communicate. Add a VLAN ID for this interface only if the interface used to communicate between Forescout components is connected to a tagged port.
- If there is more than one DNS server address, separate each address with a space—Most internal DNS servers resolve external addresses as well, but you may need to include an external-resolving DNS server. As nearly all DNS queries performed by the Appliance will be for internal addresses, the external DNS server should be listed last.
- Type a value at the
Management interfaceprompt then and press Enter. - Type a value at each subsequent prompt and press Enter. After pressing Enter at the last prompt, the setup summary is displayed.
>>>>>> Setup Summary <<<<<< Role: Appliance Licensing Mode: Per Appliance licensing mode Encryption mode: No Certification Compliance mode: No Host name: <user_entered_value> Description: <user_entered_value> Management Interface: <user_entered_value >, eth<n> Default gateway: <user_entered_value> DNS server: <user_entered_value> Domain name: <user_entered_value> (T)est,(R)econfigure,(D)one : - To test the configuration, type T and press Enter. The test verifies the following:
- Storage I/O performance (Virtual systems only)
- Connected interfaces
- Connectivity of the default gateway
- DNS resolution
Results indicate if any test failed so that you can reconfigure if necessary.
If there are no failures, the following is displayed:
Checking eth0...OK. (10000Mb/s Full duplex) Checking default gateway...OK. Checking DNS resolution...OK. Press ENTER to review configuration summary
- Press Enter. The setup summary is displayed again.
- To complete the installation, type D and press Enter.
Finalizing Forescout setup, this will take a few minutes
After setup is complete, the following is displayed
Starting Forescout service -
After the service starts, the following is displayed:>>>>>> Forescout Initial Setup is Complete <<<<<< Console will guide you through the rest of the Appliance setup. Use the following URL to install the Console: https://<management_interface_IP>/install Press ENTER to clear the screen - Press Enter. After configuration, ensure that your Forescout device has a valid license. The default licensing state of your device depends on which licensing mode your deployment is using.
- Per-Appliance Licensing Mode: you can now start to work using the demo
license, which is valid for 30 days. During this period, you should receive a
permanent license from Forescout and place it in an accessible folder on your
disk or network. Install the license from this location before the 30-day demo
license expires. If necessary, you can request an extension to the demo
license.
If you are working with a Forescout virtual system, the demo license is not installed automatically at this stage. See Forescout Virtual Device Deployment in VMware for details.
You can be alerted that your demo license is about to expire in a number of ways. Refer to in the Administration Guide for more information about demo license alerts.
- Flexx Licensing Mode: the Entitlement administrator should receive an email when the license entitlement is created and available in the Forescout Customer Support Portal. Each customer is assigned at least one Entitlement administrator who has permissions to download license files, software and documentation in the Portal for all customer deployments. Once available, the Forescout administrator of the deployment can activate the license in the Console. Until the license is activated, Forescout features do not function properly. For example, policies are not evaluated and actions are not performed. No demo license is automatically installed during system installation.
See Licensing Mode for more information on licensing modes and to find out which mode you are using. Refer to
minute read