Security fstool Commands

This topic lists fstool commands related to security.

key - Verify CounterACT Device MD5 Signature

Note: This command is not available in the FS-CLI.

Displays the CounterACT MD5 signature.

The MD5 signature is the message digest of the key certificate that is assigned to your CounterACT device. The signature appears in the Authorization Manager dialog box when you transfer your system to the Strong Authentication Mode. It is recommended that you verify that this key signature and the key signature of your CounterACT device are identical.

Usage: fstool key

config_sum - CounterACT Appliance Configuration Summary

Note: This command is not available in the FS-CLI.

Display a summary of the Forescout configuration.

Usage: fstool config_sum

Sample Output:

CounterACT/Enterprise Manager Configuration Summary

Version Information
Version: 9.1.3
Build number: 100

Build date: Tue Apr 29 22:04:22 2025 GMT
Host Information
Hostname: KK-12345

Domain name: qa.lab.forescout.com

Dns: x.x.x.x
Network Information
Gateway IPv4: x.x.x.x
Gateway IPv6: y:y:y:y:y:y:y:1 
ens192 IPv4: y:y:y:y:y:y:y:1  IPv4GW: x.x.x.x IPv6: manual
                                                              IPV6: y:y:y:y:y:y:y:y 
                                                              IPV6: y:y:y:y:y:y:y:y 
                                                              IPv6GW: y:y:y:y:y:y:y:1

Channel Configuration Information

Enterprise Manager Configuration
E-mail Privacy: No mail-relay configured

Mail relay:
Operator mail: No operator mail configured
Protected net: x.x.x.0-x.x.x.255, 1.x.x.0-1.x.x.255
Management Clients: all_ips_allowed

SSH Clients:: , 0..
---------------------------------------------------------------
Where x is defined as 0-255 and y is defined as 0000–FFFF.

ethset - Configure Interface Speed/Duplex

Modify the default auto negotiation speed and duplex values of Ethernet ports. The configuration should be set in run time and also for the next boot.

Usage: fstool ethset

An interactive dialog shows existing configuration, and prompts for changes.

Interfaces speed and duplex configuration:
Interface  Driver  Cur-Speed/Duplex  Conf-Speed/Duplex   Link Status
eth0       e100    100baseT/Half     Auto/Auto           link ok
eth1       e100    Auto/Full         Auto/Auto           link ok
CounterACT Interfaces Speed and Duplex Configuration Options:
1) Edit interfaces speed and duplex options
2) Blink interfaces
3) Quit
Choice (1-3) : 

Select 2Blink Interfaces to identify the Ethernet interfaces (ports). This duplicates the fstool ethtest command.

ethtest – Identify Ethernet Ports on Appliance

Usage: fstool ethtest

The following message appears:

Blinking eth0. Press ENTER for next interface

When the first message is displayed (Blinking eth0. …, check the Ethernet ports and mark the blinking port. Continue with the other ports.

data_reset - Reset System Data

Remove data by section or All.

Resetting the Enterprise Manager data releases all NAC Policy hosts and undoes all actions. Policies continue to function after executing the command.

Usage: fstool data_reset [all | orgh | intruder | vsite | npsources]

orgh
remove organizational headsups related tables
intruder
remove intruders related tables
vsite
remove vsite related tables
npsources
remove policy hosts tables
all
remove all the above tables

ifcount – Display Network Traffic

This tool displays network traffic on the specified interfaces; it works in two modes - by interface or by VLAN (during the display, the mode can be changed). The tool displays the total bits per second and the percentage of each of the following traffic categories:

  • Broadcast - incoming broadcast (destination MAC is broadcast and source MAC is not this Appliance).
  • Mirrored - destination MAC is of another machine (not this Appliance's MAC and not a broadcast MAC).
  • To my MAC - destination MAC is the Appliance's MAC.
  • From my MAC - traffic sent by this Appliance (source MAC is the Appliance's MAC, destination can be broadcast or unicast).

Usage: fstool ifcount <interface> [<interface>...]

Separate each interface/VLAN by a space.

Display commands:

Display Command Description

v

 

display in VLAN mode

I

display in interface mode

P

show previous

N

show next

q

quit displaying

Example

fstool ifcount ens192 …

Interface/Vlan Mode:

update=[11]     [ens192: 1 vlans] 
Interface/Vlan   Total       Broadcast   Mirrored    Management
 ens192.untagged   38Kbps       0.0%        67.2%     32.8%

sitedb –Backup and Restore Site Table

Note: This command is not available in the FS-CLI.

Usage: fstool sitedb [backup | version | restore <file>]

Backup
Back up site to file
Version
Display Forescout version information.
restore
Restore site from file.

www sso_config_reset – Reset Metadata Files

Although not a requirement, it is a best practice to reset metadata files prior to changing the external identity provider that the must work with.

Note: This command is not available in the FS-CLI.

Usage: fstool t www sso_config_reset

Run this command on Enterprise Manager.

After you run this command, re-perform the procedure  .

smime - Certificate Signing Utilities

Note: This command is not available in the FS-CLI.

Use the fstool smime command to generate Certificate Signing Requests (CSRs) that are submitted to a Certificate Authority (CA). After the CA returns a signed certificate, use this command to import the certificate into . For more information about enabling digital signing of email messages through the Console after a signed S/MIME certificate is imported, refer to   in the Guide.

The Certificate Authority can return the signed S/MIME certificate in several container file formats. Some of these formats contain just the signed certificate and public key, and some also contain a newly generated private key that must be installed with the signed certificate.

Usage:

fstool smime [gen | export | import pem < pem_file >]

gen
Generate a Certificate Signing Request (CSR).
export
Regenerate an existing Certificate Signing Request (CSR) based on previously entered parameters
import pem
Import a signed S/MIME certificate in PEM format when the Certificate Authority does not generate a new private key.
<pem_file>
The full path to the PEM file.
Import pfx
Import a signed certificate/key pair in PFX format when the Certificate Authority generates a new private key.
<pfx_file>
The full path to the PFX file.

Generating a new CSR

When you generate a new CSR, you are prompted for the following fields:

  • RSA key size [2048] :
  • DNS name of this Enterprise Manager [] :
  • Organization name [] :
  • Organizational unit name [] :
  • City or Locality name [] :
  • State or Province [] :
  • Two-letter country code for this unit [] :
  • Email address [] :

The email address field represents the Enterprise Manager, which applies the digital signature to emails. The certificate is generated for this email address. Once a signed certificate is installed on the Enterprise Manager, emails are sent with this certificate and the email address configured here appears in the From field. The address should be meaningful, so that users can recognize that it comes from the Forescout Enterprise Manager.

Converting CSR File Formats

If the Certificate Authority returns the signed certificate and public key as DER or P7B formatted files, convert it to PEM file format as in the following examples.

To convert from DER to PEM use the following command:

openssl x509 -inform der -in <der_file> -out <pem_file>

To convert from P7B to PEM use the following command:

openssl pkcs7 -print_certs -in <p7b_file> -text -out <pem_file>

If the Certificate Authority returns a pair of PEM or DER files, convert them to PFX file format as in the following examples.

To convert a pair of PEM files to a single PFX file, use the following command:

openssl pkcs12 -export -out < pfx_file > -inkey < private_pem > -in < public_pem >

To convert a pair of DER files to a single PFX file, first convert the DER files to PEM files using the following commands:

openssl x509 -inform der -in < public_der > -out < public_pem >

openssl rsa -inform der -in < private_der > -outform pem -out < private_pem >