Security fstool Commands
This topic lists fstool commands related to security.
key - Verify CounterACT Device MD5 Signature
Displays the CounterACT MD5 signature.
The MD5 signature is the message digest of the key certificate that is assigned to your CounterACT device. The signature appears in the Authorization Manager dialog box when you transfer your system to the Strong Authentication Mode. It is recommended that you verify that this key signature and the key signature of your CounterACT device are identical.
Usage: fstool key
config_sum - CounterACT Appliance Configuration Summary
Display a summary of the Forescout configuration.
Usage: fstool config_sum
Sample Output:
CounterACT/Enterprise Manager Configuration Summary
Version Information
Version: 9.1.3
Build number: 100
Build date: Tue Apr 29 22:04:22 2025 GMT
Host Information
Hostname: KK-12345
Domain name: qa.lab.forescout.com
Dns: x.x.x.x
Network Information
Gateway IPv4: x.x.x.x
Gateway IPv6: y:y:y:y:y:y:y:1
ens192 IPv4: y:y:y:y:y:y:y:1 IPv4GW: x.x.x.x IPv6: manual
IPV6: y:y:y:y:y:y:y:y
IPV6: y:y:y:y:y:y:y:y
IPv6GW: y:y:y:y:y:y:y:1
Channel Configuration Information
Enterprise Manager Configuration
E-mail Privacy: No mail-relay configured
Mail relay:
Operator mail: No operator mail configured
Protected net: x.x.x.0-x.x.x.255, 1.x.x.0-1.x.x.255
Management Clients: all_ips_allowed
SSH Clients:: , 0..
---------------------------------------------------------------
Where x is defined as 0-255 and y is defined as 0000–FFFF.
ethset - Configure Interface Speed/Duplex
Modify the default auto negotiation speed and duplex values of Ethernet ports. The configuration should be set in run time and also for the next boot.
Usage: fstool ethset
An interactive dialog shows existing configuration, and prompts for changes.
Interfaces speed and duplex configuration: Interface Driver Cur-Speed/Duplex Conf-Speed/Duplex Link Status eth0 e100 100baseT/Half Auto/Auto link ok eth1 e100 Auto/Full Auto/Auto link ok CounterACT Interfaces Speed and Duplex Configuration Options: 1) Edit interfaces speed and duplex options 2) Blink interfaces 3) Quit Choice (1-3) :
Select 2Blink Interfaces to identify the Ethernet interfaces (ports). This duplicates the fstool ethtest command.
ethtest – Identify Ethernet Ports on Appliance
Usage: fstool ethtest
The following message appears:
Blinking eth0. Press ENTER for next interface
When the first message is displayed (Blinking eth0. …, check the Ethernet ports and mark the blinking port. Continue with the other ports.
data_reset - Reset System Data
Remove data by section or All.
Resetting the Enterprise Manager data releases all NAC Policy hosts and undoes all actions. Policies continue to function after executing the command.
Usage: fstool data_reset [all | orgh | intruder | vsite | npsources]
ifcount – Display Network Traffic
This tool displays network traffic on the specified interfaces; it works in two modes - by interface or by VLAN (during the display, the mode can be changed). The tool displays the total bits per second and the percentage of each of the following traffic categories:
- Broadcast - incoming broadcast (destination MAC is broadcast and source MAC is not this Appliance).
- Mirrored - destination MAC is of another machine (not this Appliance's MAC and not a broadcast MAC).
- To my MAC - destination MAC is the Appliance's MAC.
- From my MAC - traffic sent by this Appliance (source MAC is the Appliance's MAC, destination can be broadcast or unicast).
Usage: fstool ifcount <interface> [<interface>...]
Separate each interface/VLAN by a space.
Display commands:
| Display Command | Description |
|---|---|
|
|
display in VLAN mode |
|
|
display in interface mode |
|
|
show previous |
|
|
show next |
|
|
quit displaying |
Example
fstool ifcount ens192 …
Interface/Vlan Mode:
update=[11] [ens192: 1 vlans] Interface/Vlan Total Broadcast Mirrored Management ens192.untagged 38Kbps 0.0% 67.2% 32.8%
sitedb –Backup and Restore Site Table
Usage: fstool sitedb [backup | version | restore <file>]
www sso_config_reset – Reset Metadata Files
Although not a requirement, it is a best practice to reset metadata files prior to changing the external identity provider that the must work with.
Usage: fstool t www sso_config_reset
Run this command on Enterprise Manager.
After you run this command, re-perform the procedure .
smime - Certificate Signing Utilities
Use the fstool smime command to generate Certificate Signing Requests (CSRs) that are submitted to a Certificate Authority (CA). After the CA returns a signed certificate, use this command to import the certificate into . For more information about enabling digital signing of email messages through the Console after a signed S/MIME certificate is imported, refer to in the Guide.
The Certificate Authority can return the signed S/MIME certificate in several container file formats. Some of these formats contain just the signed certificate and public key, and some also contain a newly generated private key that must be installed with the signed certificate.
Usage:
fstool smime [gen | export | import pem < pem_file >]
Generating a new CSR
When you generate a new CSR, you are prompted for the following fields:
- RSA key size [2048] :
- DNS name of this Enterprise Manager [] :
- Organization name [] :
- Organizational unit name [] :
- City or Locality name [] :
- State or Province [] :
- Two-letter country code for this unit [] :
- Email address [] :
The email address field represents the Enterprise Manager, which applies the digital signature to emails. The certificate is generated for this email address. Once a signed certificate is installed on the Enterprise Manager, emails are sent with this certificate and the email address configured here appears in the From field. The address should be meaningful, so that users can recognize that it comes from the Forescout Enterprise Manager.
Converting CSR File Formats
If the Certificate Authority returns the signed certificate and public key as DER or P7B formatted files, convert it to PEM file format as in the following examples.
To convert from DER to PEM use the following command:
openssl x509 -inform der -in <der_file> -out <pem_file>
To convert from P7B to PEM use the following command:
openssl pkcs7 -print_certs -in <p7b_file> -text -out <pem_file>
If the Certificate Authority returns a pair of PEM or DER files, convert them to PFX file format as in the following examples.
To convert a pair of PEM files to a single PFX file, use the following command:
openssl pkcs12 -export -out < pfx_file > -inkey < private_pem > -in < public_pem >
To convert a pair of DER files to a single PFX file, first convert the DER files to PEM files using the following commands:
openssl x509 -inform der -in < public_der > -out < public_pem >
openssl rsa -inform der -in < private_der > -outform pem -out < private_pem >
minute read