Machine Administration fstool Commands

This topic lists fstool commands related to machine administration.

acpi - Enable/Disable ACPI Shutdown

Enables/disables ACPI (Advanced Configuration & Power Interface). After ACPI is disabled, press the power button, and the machine cleanly shuts down the Enterprise Manager service and powers off. The default is Enabled.

Usage: fstool acpi

The command acts as a toggle – you are prompted to change the current status.

Reboot is required to implement changes.

asymnet - Enable/Disable Network Asymmetry Test

Note: This command is not available in the FS-CLI.

The asymmetry test verifies that the sees symmetric traffic, for every session, on both incoming and outgoing monitoring interfaces.

Usage: fstool asymnet

The command acts as a toggle: you are prompted to change the current status.

The Packet Engine is restarted to implement changes.

backup - Backup a Forescout System

Note: This command is not available in the FS-CLI.

The backup data includes the following:

  • Configuration
  • License
  • Operating System configuration
  • Plugins

This includes, for example:

  • IP address
  • Root password
  • License information
  • Channel
  • E-mail
  • Internal network parameters
  • Basic and advanced NAC Policy definitions
  • Legitimate traffic definitions
  • Report schedules

The backup does not include event data.

Usage: fstool backup <backup-file>

Note: Stop the Forescout engine before running the fstool backup/restore command (use: fstool service stop ).

To proceed correctly, the backup procedure requires the following files to be located under /usr/local/forescout/lib/perl/forescout/:

  • util.ph
  • db.ph
  • if.ph
  • help.ph
  • event_log.ph
  • plugin.ph
  • getopts.pl to be found under /usr/lib/perl5/5.6.0/

restore – Restore from FSB File to Another Forescout System

Restores from an FSB (Forescout Backup) file to another Forescout system, using the following syntax:

fstool backup/restore <full path file name>

The fstool backup/restore command should be run only after the Appliance has been stopped (use: fstool service stop)

Non-configured system

When accessing a non-configured system or a new system from production, the restore option is available in a menu that appears on the screen, as in the following example:

Options:
1) Configure Forescout-[version-number]
2) Restore saved Forescout-[version-number] configuration
3) Identify network interfaces
4) configure a keyboard layout
5) Turn machine off
Choice (1-5) :

Choosing the Restore saved Forescout configuration option initiates an interactive restore procedure, where the backup file can be searched over a USB storage device, CD-ROM, floppy diskette or to display a shell prompt.

After the restore procedure is completed, the installation log is written to:

/tmp/CounterACT-install.log

To complete the procedure, reboot the system.