Miscellaneous fstool Commands

This topic lists additional, miscellaneous fstool commands.

addradius - Add RADIUS Server to VPN/Switch 802.1X Plugin

Note: This command is not available in FS-CLI.

Usage:

fstool addradius [vpn | switch802_1x]

Supported_platforms: UNIX

anomaly - Display Anomaly IPs or Channels

For example, the system thinks it detects unilateral traffic, or unsuccessful response.

Usage:

fstool anomaly [-i | -c]

-i
Display IPs with anomalies
-c
Display channels with anomalies

chmod – Toggle Appliance Operation Mode

Note: This command is not available in FS-CLI.

Toggle the Enforcement Node between Partial Enforcement and Full Enforcement.

Usage: fstool chmod

conf - Repeat Forescout Configuration Procedure

Example:

*** Forescout Enterprise Manager Configuration ***
You are about to configure Forescout Management Server. When prompted, press <Enter> to accept the default

dns - Configure Appliance Name Servers DNS

The display shows:

Either 'yes' or 'no' are acceptable here.
 Continue (yes/no)? [yes]:

ha – High Availability Utilities

Usage: fstool ha [-vhH] command [<flags>] [<params>

Note: To change hostnames on an HA cluster, use the fstool ha_setup command.

Command can be one of the following:

 
CommandDescription

install [-f] [-t <template file>] <template arguments>

Install HA template files

verify [-W(arn only)] [-T(ext format)] <target file> [<Warn only>]

Check for bad characters in configuration file

properties [-H] [-t <property file>]

Show HA status properties

status [-t <property file>]

Show HA status properties

snapshot [-v] [-d <dir>] [<extra files>..]

Generate a snapshot

template [-f] [-t <template file>] <target file> <template file> [<var1> <value1> ..]

Configure files using templates, avoid using $ characters. Use %..%;-f for forcing.

diag

diagnoses High Availability status and services and provides advanced log output regarding High Availability status or failure

maint [-e]

<enable maintenance>

maint [-d]

<disable maintenance task>

maint [-s]

<display maintenance task status - enabled/disabled> - to facilitate maintenance operations, this command can disable the cluster/pair mechanism and ignore failover during maintenance procedures

ha_setup - High Availability Setup

Usage: fstool ha_setup

Note: This command is only available from the High Availability miniroot.

help – List fstools with Description

List available fstool commands.

hwstat – Test Hardware Status

Note: This command is not available in FS-CLI.

A daemon periodically collects hardware status data about the Appliance and records the data in the syslog. The stop option deactivates the daemon and clears the data. Restart stops the daemon to clear the data and restarts the daemon to resume hardware status data collection. The status option retrieves the data from the log.

Usage: fstool hwstat [start | stop | restart | status]

start
Activate the daemon.
stop
Deactivate the daemon and clear data.
restart
Stop the daemon, clear data, and restart the daemon.
Status
Display current data.

Sample output:

$fstool hwstat status 
- hwstat service is up 
- ACPI is enabled:
       * CPU temperature notification - NOT Supported.
       * Power off notification       - Supported.
 - RAID driver install on host - mptscsih:
       * RAID error notification     - Supported.
 - Local disk space usage - reports when usage is above 98%.
 - Interfaces Status:
       eth5:link-ok,100Mb/s Speed,Half Duplex
       eth6:no-link       eth7:no-link       eth0:link-ok,100Mb/s Speed,Full Duplex
       eth1:link-ok,100Mb/s Speed,Full Duplex
       eth2:link-ok,100Mb/s Speed,Full Duplex
       eth3:link-ok,100Mb/s Speed,Full Duplex       
````````eth4:no-link

pe – Set Configuration Parameters for Packet Engine

Configure the behavior of the Packet Engine Plugin on the Appliance.

Usage: fstoolpe

CommandDescription

pe get_conf_params <infix>

Print conf_params whose names include <infix>

pe get_conf_param <full_name>

Print (the single) conf_param whose name is <full _name>

pe set_conf_param <full_name> <value>

Set (the single) conf_param whose name is <full_name> to <value>. Use double-quoted value if it includes shell-characters e.g. '*'

plugin – Plugin Control Tool

Usage: fstool plugin plugin_name args...

sc_config - Windows SecureConnector Advanced Log Configuration

Commands for Windows SecureConnector advanced log configuration and other advanced options.

Usage: sc_config -c <command> [parameters]

-c
Provide one of the following commands:
sc_msg –h <all|none|ip[,ip[,ip..]]>
Enable logging the Protocol messages between SC and HPS.
close_sc -h <ip>
Close the connection with the SC running on endpoints with [ip].
get_logs -h <ip>
Copies the zipped log files from the host to the shared path on CA.
get_dump -h <ip>
Copies the zipped dump file from the host to the shared path on CA.
set_config -h <ip> -l <int,0-5> -m <int> -t <int>
Configure SecureConnector logging mechanism.
-l
Changes the SecureConnector log level
-m
Changes the maximum number of log files that the SecureConnector is allowed to create. A log file's maximum size is ~40MB.
If a new log needs to be created after we reached this number, the oldest log is deleted.
-t
Determines the recording time, after which the log settings are returned to their original values. By default, the changes are permanent.

Examples:

fstool sc_config -c sc_msg -h all

fstool sc_config -c sc_msg -h none

fstool sc_config -c sc_msg -h 10.0.0.1

fstool sc_config -c sc_msg -h 10.0.0.1,10.0.0.2

fstool sc_config -c close_sc -h 10.0.0.1

fstool sc_config -c get_logs -h 10.0.0.1

fstool sc_config -c get_dump -h 10.0.0.1

fstool sc_config -c set_config -h 10.0.0.1 -l 5 -m 4 -t 60

setmapiport – Set MAPI Service Port

Note: This command is not available in FS-CLI.

Supported platforms: UNIX.

Usage: fstool setmapiport [clear] [-h | help]

To set a new list, insert ip:port list. Format the list as follows:

a.b.c.d:port/TCP, e.f.g.h:port/TCP

Specify clear to erase the current list.

smtpp – Toggle SMTP Privacy

By default, e-mail anomalies displayed in the Console and shown in Console reports hide certain information contained in the mail to protect the privacy of the sender. When you disable this mechanism the sender, receiver, and subject of the mail are displayed.

Usage: fstool smtpp

You are prompted to change the current setting. The packet engine is restarted.

sw_javacli - Get Information on the Switch Plugin JavaCLI

This command allows you to access the Switch Plugin's sw_javacli.log file.

Usage: fstool sw_javacli [debug <debug-level> | stats <device-ip> | status]

debug <debug-level>
Enable designated debug level
stats <device-ip>
Prints the stats for the Java CLI part of the Switch Plugin to the sw_javacli.log file for the specified device. Not designating a device-ip prints the stats for all devices.
status
Displays the status of the Java CLI part of the Switch Plugin

sw netconf – Debug Configured Switches Using NETCONF

Typically this command is used under the direction of your Forescout support representative.

Usage: fstool sw netconf

Sample interaction:

CounterACT Utility Tool
 ~~~~~~~~~~~~~~~~~~~~~~~
 Get NETCONF XMLs from Configured Switches
Please wait, reading switch list from database...
 Open database - Success
The following switches are configured to work on the appliance:
1. 10.39.1.250 using SNMP version [2] vendor [alcatel]
2. 10.39.1.248 using NETCONF vendor [juniper]
3. 10.34.1.250 using SNMP version [2] vendor [extreme]
Select a switch for NETCONF XML query by entering its number in the list. 
For multiple switch selection, separate numbers by commas.
Select switch: 2
Open session to switch [10.39.1.248] vendor[juniper]
Take NETCONF XMLs on (a) all XMLs (s)elected XMLs or XMLs (f)ile:
trying . >>/tmp/10.39.1.248.juniper.walk

Select (a) or (s) or (f) as instructed by your Forescout Support representative. Complete the form and submit it to our support team for debugging assistance.

sw snmpwalk – Debug Configured Switches Using SNMP

Typically this command is used under the direction of your Forescout support representative.

Usage: fstool sw snmpwalk

Sample interaction:

CounterACT Utility Tool
Get SNMPWALK from Configured Switches
Please wait, reading switch list from database...
Open database - Success
The following switches are configured to work on the appliance:
1. 10.33.1.253 using SNMP version [2] vendor [cisco]
2. 10.34.1.250 using SNMP version [2] vendor [extreme]
3. 10.33.1.250 using SNMP version [2] vendor [cisco]
 Select a switch for SNMPWALK by entering its number in the list. For multiple switch selection, separate numbers by commas.
 Select switch: 2
Selected switch [10.34.1.250] model [extreme]
Take SNMPWALK on (s)elected OIDs, (a)ll OIDs, or OID (f)ile:
trying . >>/tmp/10.34.1.250.extreme.walk

Select (a) or (s) or (f) as instructed by your Forescout Support representative. Complete the form and submit it to our support team for debugging assistance.

sw_remove_mac_notif_trap_remove - Remove Mac-Notification Remove Traps

Use this command to remove mac-notification remove SNMP traps from a switch:

Usage :fstool sw_remove_mac_notif_trap_remove -h <ip> - Host IP

-h <ip> -Host IP

-c <community> - community

-v <version> - SNMP Version

sw traps – Configure Cisco Switches for MAC traps

The command configures Cisco switches for MAC notification traps:

Usage: fstool sw traps -h <hostname_IP> -c <community> -s <state> -v <SNMP_version> [-1 | -2]

Where -1 enables trap notification and -2 disables trap notification.

tty - Manage Built-in tty

Note: This command is not available in FS-CLI.

Usage: fstool tty <command>

Command can be one of:

status [<tty dev>]
Show status
set [<tty dev> <baud rate>]
Configure the tty