User Access and Services fstool Commands

This topic lists fstool commands related to user access and services.

clients - Enable Console Access to CounterACT Devices

Edit Forescout Console addresses that are allowed to access CounterACT devices.

IP addresses of the Console that are allowed to connect to the CounterACT device must be listed during the Enterprise Manager installation. These addresses are set up so the Console is allowed to communicate with the CounterACT device.

If these addresses were defined incorrectly during installation, the Console cannot connect to the CounterACT device. When you try to log in, you receive a message indicating that the connection timed out. You can correct the Console IP addresses to enable access to the CounterACT device.

Usage: fstool clients

An interactive dialog lists IP addresses that can connect to the CounterACT device.

Enterprise Manager access list
-----------------
192.0.2.0 - 192.0.2.31
192.0.2.63 - 192.0.2.127
(A)dd,(D)elete,(S)ave,(Q)uit :

If you choose (A)dd or (D)elete, you are prompted for a range of IP addresses:

Range start:
Range end:

To define a single IP address, enter it at the Range start prompt. At the Range end prompt, press Enter.

If you (A)dd or (D)elete IP addresses, remember to (S)ave your changes before you (Q)uit the dialog.

kbd – Change the Forescout Keyboard

Change the Forescout keyboard layout to support localization (language).

passwd – Update or Reset Admin Password

Use this command to update or reset the password of the admin-level user.

Users who know the current admin-level login credentials can change the admin password.

Your system is provided with a predefined root admin user, whose password is set during installation. Only users who know this password can reset the admin-level password.

Update the Admin password from the Enterprise Manager. This tool is designed for administrators with root privileges on the Enterprise Manager.

Usage:

Fstool passwd [--reset]

You are prompted for the current admin password before you can change it.

When the optional --reset flag is used, you are prompted for the root admin password before you can make any changes.

By default, the admin password must be between 6 and 24 characters. To change the minimum and maximum password length, use the fstool set_property command to modify the following properties.

fs.admin.passwd.min_len
Minimum number of characters in the admin user password.
fs.admin.passwd.max.len
Maximum number of characters in the admin user password.

service – Display Service Status

CounterACT application control, to start, stop or display status of service.

Usage:

fstool service [start | stop | restart | status | shutdown]

ssh - Update SSH Access to Enterprise Manager

To Add, Delete, and Save the list of IP addresses that can access the Enterprise Manager via SSH connection.

SSH access allows you to remotely control the Enterprise Manager. Suppose you specified the wrong list of IP addresses from which SSH access should be allowed during installation. In that case, you require physical access to the machine to perform tasks such as re-installation, reboot, and fstool commands.

This has to be done on all Enterprise Managers.

Usage: fstool ssh

An interactive dialog lists current SSH access IP addresses. For example:

SSH access list
----------------
192.0.2.1
192.0.2.2
(A)dd,(D)elete,(S)ave,(Q)uit :

If you (A)dd or (D)elete IP addresses, remember to (S)ave your changes before you (Q)uit the dialog.

snapsend – Send Files to Forescout SnapShot Server

Note: This command is not available in FS-CLI.

Usage:

fstool snapsend file [file...]

snapshot – Create Snapshot

Create and optionally send a snapshot.

The snapshot created is a ZIP file to be sent to Forescout support for analysis. An option allows the snapshot to be sent automatically to the Forescout public server. To enable this, contact Forescout support.

unlock - Unlock Console User

Use this command to unlock a console user.

If a user, especially an admin user is locked, use this command to unlock it.

Use any user with cliadmin privileges for this command.

This command is available when running in FS-CLI in Certification Compliance mode.

To unlock a user:

  1. Log in to the CounterACT device CLI.

  2. Run: fstool unlock_console_user <user>

    If successful, the following message appears:

    User '<user>' unlocked successfully.