FS CLI Commands

This topic lists commands available in FS-CLI. The FS-CLI contains a number of commands that are either unique to the FS-CLI or carry the same command name as in the Bash shell but behave differently.

? – View a List of Available Commands

Usage: ?

clear_shared – Clear Shared Directory Content

Note: This command is not available in the Bash shell.

Usage: clear_shared

crypt – Disk Encryption Tool

Use this command to encrypt log and database partitions.

Usage: crypt enable | disable | status

When you enable disk encryption:

  • Forescout services are stopped until the encryption process completes.
  • The log partition is deleted. Back up the logs if needed.
  • If you have a High Availability pair, verify the following:
    • You are directly connecting to this node’s miniroot shell via its own management IP (not the sync or VIP address).
    • Enable encryption on the Standby node first.
    • Ensure that the High Availability state is valid.
You cannot enable disk encryption in FIPS mode.

If you run crypt enable, and FIPS mode is active, the CLI issues the following warning message:

'fstool crypt enable' is not supported in FIPS mode. Before you enable disk encryption, you must first disable FIPS mode. When disk encryption has completed, you can enable FIPs mode again.

Once disk encryption is enabled (after reboot), the CLI issues the following warning message:

FIPS mode is currently disabled, but was enabled prior to enabling disk encryption. You can enable FIPS mode with the 'fstool fips' command.

date – OS Date

Display the current time.

dhclasstest – Test DHCP Fingerprint

Use this command to troubleshoot DHCP-related issues.

Usage: dhclasstest <command> <params>

Commands:

  • testfp - test specific fingerprint and/or vendor_id: Syntax: testfp [-h <ip>] [-f <fingerprint>] [-v <vendor_id] [-c] [-p] [-d] [-4] [-6] [-b] [-O]
  • testdb - test entire fingerprint database: Syntax: testdb [-o <os>] [-p] [-d] [-c] [-4] [-6] [-b] [-O]
  • dumpdb - dump entire database (FP_DB and FP_HASH contents): Syntax: dumpdb [-p] [-4] [-6] [-b] Parameters:
    -h <ip>
    Test using dhcp_fingerprint and dhcp_vendor for a specific host <ip>
    -f <fingerprint>
    Test a <fingerprint> value, e.g., "1,15,3,6,44,46,47,31,33,43,252,12"
    -v <vendor_id>
    Test a <vendor_id> value, e.g., "MSFT 5.0"
    -o <os>
    Test an <os> value, e.g., "100"
    -c
    Show all colliding Class and OS results for blank <fingerprint> or <vendor_id> values
    -d
    Show detailed output
    -4
    Use ipv4 database only (default)
    -6
    Use ipv6 database only
    -b
    Use both ipv4 and ipv6 databases
    -p
    Show OS/Class collisions and other database problems - enabled by default for dumpdb and testdb commands
    -O
    Test using old lookup method

dns – Configure/List CounterACT Name Server(s) (DNS)

Use this command to check DNS server settings and troubleshoot DNS-related issues.

Usage: dns [-l]

engine – Forescout Packet Engine Control

Use this command to troubleshoot, configure and maintain the Packet Engine Plugin.

Input parameters: [kill | reopenlog | dump_stack | dump_core | status | version]

reopenlog
Request engine to reopen log
dump_stack
Request engine to dump stack logs
cycle_core
Restart core purge cycle
dump_core
Request engine to dump core file
Kill
Forcibly terminates engine
Status
Engine status
Version
Engine version

exit – Exit CLI

Exit the FS-CLI.

fingerprintkey – Verify CounterACT Device Signature

Displays the CounterACT Device signature digest.

Usage: fstool fingerprintkey

The signature is the message digest of the key certificate that is assigned to your CounterACT device. The signature appears in the Authorization Manager dialog box when you transfer your system to the Strong Authentication Mode. Use this command to verify that this key signature and the key signature of your CounterACT device are identical.

list – List Directories and Log Files

Note: This command is not available in the Bash shell.

Use the list command to list directories and log files saved by Forescout in the 'log' folder, operating system logs saved in the 'oslog' folder, or shared files that were saved in the 'shared' folder.

See also monitor - Monitor Tail of Log File, search – Search For and Within Log Files and view – View Log Files.

Input parameters: [log | oslog | shared]

Log
View appliance log files
Oslog
View log files
Shared
View upload/download shared folder

Examples:

cliadmin@app> list log

d somefolder

- 292K sample_log.txt

cliadmin@app> list log:plugin/va

d store

1.1M va.log

In output, d indicates a directory, - indicates an individual file

monitor - Monitor Tail of Log File

Note: This command is not available in the Bash shell.

Monitor the tail end of the log files saved by Forescout in the 'log' folder, operating system logs saved in the 'oslog' folder, or shared files that were saved in the 'shared' folder. This allows you to see if anything in the file has changed.

See also list – List Directories and Log Files, search – Search For and Within Log Files and view – View Log Files.

Examples:

monitor log:watch_dog.log

monitor log:plugin/va/va.log

monitor oslog:audit/audit.log

password – Change CLI Password For Current User

Allows the current user to change their CLI Password. You set the rules for the composition and length of this password in the Console at Tools > Options > User Profiles > Password and sessions.

quit – Exit CLI

Note: This command is not available in the Bash shell.

Exit the FS-CLI.

rename_admin_user – Rename Admin User

Use this command to rename the cliadmin (FS-CLI) or admin (Bash shell) user.

Usage: rename_admin_user <new admin user name>

resolve - Resolve Host Address by Name

Allows an admin user to get the IP address for a specific hostname, which may be helpful for troubleshooting.

Usage: resolve [-f] host_name

Usage: resolve -u name1=ip1 name2=ip2 …

search – Search For and Within Log Files

Note: This command is not available in the Bash shell.

Use this command to search inside log files saved by the .

See also list – List Directories and Log Files, monitor - Monitor Tail of Log File and view – View Log Files.

Usage:

search <pattern/regex> <parent_dir>:filename

search <string> <parent_dir>:filename

Examples:

cliadmin@app> search test1 log:filename

cliadmin@app> search "Sending.*pid" log:daemon/www.log

cliadmin@app> search "kernel: IPv4:" oslog:messages

cliadmin@app> search support shared:uploaded_file

shell – Return to Bash Shell from FS-CLI

This command allows you to exit the FS-CLI and access the operating system’s Bash shell.

ssh_root_password_login – Control Root User Log In

Use this command to control root user log in to a Forescout device via SSH.

Usage: ssh_root_password_login [disable | enable]

You are prompted for your FS-CLI and sudo passwords.

Enhance the security of your deployment by controlling the user's ability to perform a root user log in, via SSH, to Forescout devices (Enterprise Manager and Appliances), whether physical devices or virtual devices.

  • A new installation of the (version 8.2.2 or above) has, by default, the root user log in capability prohibited (disabled).
  • An upgrade of the from version 8.2.1 or below to version 8.2.2 or above) keeps the existing control of the root user log in capability. In other words, if before the upgrade, this capability was allowed (enabled) in the /etc/ssh/sshd_config file of the SSH server, then after the upgrade this capability remains allowed (enabled). However, if before the upgrade, this capability was prohibited (disabled) in the/etc/ssh/sshd_config file of the SSH server, then after the upgrade this capability remains prohibited (disabled).

    Forescout recommends prohibiting (disabling) use of the root user log in capability on your Forescout devices.

    You must log in to each Appliance CLI and submit this command.

ssh -t server – Configure Thresholds for SSH Rekeying

Allows you to configure thresholds for SSH rekeying.

Usage: ssh -t server -o Rekey_Limit “<max_data>” “<max_time>”

max_data
The maximum data transfer, before rekey. The default value is 1 Gigabyte. Use K, M, and G to designate Kilobytes, Megabytes, or Gigabytes. For example: “10” represents 10 bytes, while “10G” represents 10 Gigabyte.
max_time
The maximum time interval between rekeys. The default value is 1 hour. Use h, m, and s to designate hours, minutes, and seconds. For example: “20m” represents twenty minutes, and “1h5m3s” represents one hour, five minutes, and three seconds. The value “none” disables the time threshold for rekeying.

To reset to default thresholds, submit the command without values: ssh -t server -o RekeyLimit:

In a High Availability environment, there are separate settings for the Forescout partition and the miniroot. The command should be run separately on each High Availability node and on the partition.

summary – Detailed Appliance Summary

Note: This command is not available in the Bash shell.

Use the command to display detailed information about the Appliance, for troubleshooting or when contacting Forescout Support.

tech-support – Technical Support Utility

Use the command to send logs to Forescout Customer Support. During communication with Forescout Customer Support, they may recommend that you run this command to help troubleshoot issues.

unmanage – Disconnect CounterACT from Enterprise Manager

Use this command to disconnect an Appliance from the Enterprise Manager.

user – Configure User Roles and Permissions

Note: This command is not available in the Bash shell.

You can add a new CLI user and grant the user permissions to perform specific operations within the CLI. You can also update permissions for existing users.

  • CLI Admin. Has full permissions to perform all operations.
  • Operator. Similar to CLI Admin, but cannot add users or update permissions.
  • Auditor. Can run the tech-support command.
  • SecureFTP. Access Appliances via SFTP only and access log/shared/OS log files

Usage:

user [add | add-external | auth | del | list | lock | session | set-extpasswd | ssh-passwd | update]

add
Add a new user
add-external
Add a new external user (e.g. RADIUS or LDAP)
auth
Authentication configuration
del
Delete existing user
list
List CLI users
lock
Authentication failure records
lock list – List authentication failure records
lock list <user> - List authentication failure records for user
lock reset <user> - Reset authentication failure records for user
session
Manage/View user sessions
session list – List all user sessions
session kill <user> - Kill the user’s sessions
session killall – Kill all user sessions except this one
set-extpasswd
Set privileged password for external users
ssh-passwd
Disable/Enable ssh login-by-password for all users
update
Update user

view – View Log Files

View log files saved by the in the 'log' folder, operating system logs saved in the 'oslog' folder, or shared files that were saved in the 'shared' folder.

See also list – List Directories and Log Files, monitor - Monitor Tail of Log File and search – Search For and Within Log Files.