Configure the Enterprise Manager

 

If the installation is interrupted or if you selected the wrong version, you would need to re-image the Appliance with the relevant version of the ISO file. See Re-image Forescout Devices for more information.

To configure the Enterprise Manager:

The following prompts are samples. Some Forescout devices may come pre-installed with earlier / later versions that have slightly different prompts.
  1. Power on the Enterprise Manager. The following menu appears.
    Forescout <version>-<build> options:
    1) Configure Forescout
    2) Restore saved Forescout configuration
    3) Identify and renumber network interfaces
    4) Configure keyboard layout
    5) Turn machine off
    6) Reboot the machine
    Choice (1-6):
                         
  2. To identify the ports on the rear panel of the Enterprise Manager, type 3, and then press Enter. Text is displayed indicating which interface has been detected. The associated port LED blinks on the rear panel.
  3. Label the port on the panel so that it is easily identifiable, and then press Enter. More text is displayed indicating the next detected interface. The associated port LED now blinks.
  4. Label this port as well and press Enter. This process continues until all active interfaces are detected and you have labeled the associated port for each active interface.
  5. Once all interfaces have been detected, press Enter.
    Forescout <version>-<build> options:
    1) Configure Forescout Device
    2) Restore saved Forescout configuration
    3) Identify and renumber network interfaces
    4) Configure keyboard layout
    5) Turn machine off
    6) Reboot the machine
    Choice (1-6) :
                         
  6. Type 1, and then press Enter.
    Select High Availability Mode:
    1) Standard Installation
    2) High Availability - Primary Node
    3) Add node to existing Active Node (Primary or Secondary) 
    Choice (1-3) [1] :
  7. Type 1, and then press Enter.
    >>>>>> Forescout platform Initial Setup <<<<<< You are about to setup the Forescout platform. During the initial setup process you will be prompted for basic parameters used to connect this machine to the network.  When this phase is complete, you will be instructed to complete the setup from the Console.Continue ? (yes/no) :
    
  8. Type Yes, and then press Enter.
    The following prompt appears when running a clean installation of this version.
    Certification Compliance Mode? (yes/no) [no] :
    
  9. Unless your organization needs to comply with Common Criteria and DoDIN APL certification, type No for Certification Compliance mode, and then press Enter. See Certification Compliance for more information.
     Would you like to enable disk encryption [yes/no] [no] :
  10. Optionally enable / disable disk encryption, and then press Enterr.
    >>>>>> Select Installation Type <<<<<<
    1) Forescout Appliance
    2) Forescout Enterprise Manager
    Choice (1-2) :
                         
  11. Type 2 to install the Forescout Enterprise Manager, and then press Enter. The setup is initialized. This may take several moments.
  12. The Select Licensing Mode screen appears for Forescout machines that support both Per-Appliance and Flexx licensing modes.
    61xx, 51xx, and 41xx series Forescout machines support Flexx licensing mode only.
    >>>>>> Select Licensing Mode <<<<<<
    1) Per Appliance Licensing Mode
    2) Flexx Licensing Mode
    Choice (1-2) [1]:
                         
    The licensing mode is determined during purchase. Do not type a value until you have verified what licensing mode your deployment uses. Contact your Forescout representative to verify your licensing mode or if you entered the wrong mode

    Type 1 for the Per-Appliance Licensing Mode, and then press Enter.

    Type 2 for the Flexx Licensing Mode, and then press Enter.

    >>>>>> Enter Machine Description <<<<<<
    Enter a short description of this machine (e.g. New York office).
    Description [Enterprise Manager} :
                         
  13. Enter a description for the machine, and then press Enter.
    >>>>>> Set Administrator Password <<<<<<
    This password will be used to log in as 'cliadmin' to the machine Operating System and as ’admin’ to the Console.
    The password should be between 6 and 24 characters long and should contain at least one non-alphabetic character.
     Administrator password :
  14. Type the password (the string is not echoed to the screen), and then press Enter. You are asked to confirm the password:
    Administrator password (confirm) :
  15. Retype the password (the string is not echoed to the screen), and then press Enter.
    >>>>>> Set Host Name <<<<<<
    It is recommended to choose a unique host name.
    Host name :
    
  16. The hostname should not exceed 13 characters. Type a host name, and then press Enter. The host name can be used when logging in to the Console. In addition, it is displayed on the Console to help you identify the Forescout device that you are viewing. .

    The Management interface prompt is displayed. Subsequent prompts are displayed after you enter a value for the preceding prompt:

    >>>>>> Configure Network Settings <<<<<<
    Management IP address : 
    Network mask : [255.255.255.0]
    Default gateway : 
    Domain name : 
    DNS server addresses :
    Management IPv6 address or 'auto' or ’none’:
     
    • The number of management interfaces listed depends on the Enterprise Manager model.
    • The Management IP address is the address of the interface through which Forescout components communicate. Add a VLAN ID for this interface only if the interface used to communicate between Forescout components is connected to a tagged port.
    • If there is more than one DNS server address, separate each address with a space. Most internal DNS servers resolve external addresses as well but you may need to include an external-resolving DNS server. As nearly all DNS queries performed by the Enterprise Manager will be for internal addresses, the external DNS server should be listed last.
  17. Type a value at the Management interface prompt, and then press Enter.
  18. Type a value at each subsequent prompt and press Enter. After pressing Enter at the last prompt, the setup summary is displayed:
    >>>>>> Enterprise Manager Setup Summary <<<<<<
    Role:                 		Enterprise Manager
    Licensing Mode:			Per Appliance licensing mode
    Encryption mode:		No	
    Certification COmpliance mode:	No
    Host name:            		<user_entered_value>
    Description:          		<user_entered_value>
    Management Interface: 		<user_entered_value> [eth<n>]
    Default gateway:      		<user_entered_value> 
    DNS server:           		<user_entered_value>
    Domain name:          		<user_entered_value>
    (T)est,(R)econfigure,(D)one :
    
  19. To test the configuration, type T and press Enter. The test verifies the following:
    • Storage I/O performance (Virtual systems only)
    • Connected interfaces
    • Connectivity of the default gateway
    • DNS resolution

    Results indicate if any test failed so that you can reconfigure if necessary.

    If there are no failures, the following is displayed:

    Checking eth0...OK. (10000Mb/s Full duplex)
    Checking default gateway...OK.
    Checking DNS resolution...OK. 
    
     Press ENTER to review configuration summary
    
  20. Press Enter. The setup summary is displayed again.
  21. To complete the installation, type D, and then press Enter.
    Finalizing CounterACT setup, this will take a few minutes
    After setup is complete, the following is displayed:
    Starting Forescout service -

    After the service starts, the following is displayed:

    >>>>>> Forescout Platform Initial Setup is Complete <<<<<<
    Console will guide you through the rest of the Enterprise Manager setup.
    Use the following URL to install the Console:    
    https://<management_interface_IP>/install
    Press ENTER to clear the screen
    
  22. Press Enter. After configuration, ensure that your Forescout device has a valid license. The default licensing state of your Forescout device depends on which licensing mode your deployment is using.
  • Per-Appliance Licensing Mode: you can now start to work using the demo license, which is valid for 30 days. During this period, you should receive a permanent license from Forescout and place it in an accessible folder on your disk or network. Install the license from this location before the 30-day demo license expires. If necessary, you can request an extension to the demo license.
    • If you are working with a Forescout virtual system, the demo license is not installed automatically at this stage. See Forescout Virtual Device Deployment in VMware for details.
    • You will be alerted that your demo license is about to expire in a number of ways. Refer to   in the Administration Guide for more information about demo license alerts.
  • Flexx Licensing Mode: the Entitlement administrator should receive an email when the license entitlement is created and available in the Forescout Customer Support Portal. Once available, the Forescout administrator of the deployment can activate the license in the Console. Until the license is activated, Forescout features will not function properly. For example, policies will not be evaluated and actions will not be performed. No demo license is automatically installed during system installation.

See Licensing Mode for more information on licensing modes and to find out which mode you are using. Refer to

 

License Management in the Administration Guide for information about licensing management and licensing modes.