Assets portal
The Assets Portal is a web-based search and discovery tool that lets you leverage extensive network information collected and correlated by Forescout products. This includes not only endpoint information, but also policy violations, login information, User Directory details, organizational mapping details, and endpoint device connections.
The information is valuable to groups across your organization, including:
- Security teams: Use an IP address to quickly locate and shut down switch ports and eliminate a security threat (from the Console).
- IT departments: Use an IP address to locate and contact users when maintenance is required at the endpoint.
- Help Desk: Effortlessly link IP addresses, computer hardware addresses, and switch ports to employees, in real time.
By using the portal, response time is shortened, translating into efficient remediation and crisis management.
In addition, you can clear event detections, and stop policy actions from the portal.
The Appliance runs a web server to operate the portal. (Access to the portal page requires a secured HTTPS connection, because the information displayed is sensitive.) During the installation of the Appliance, a default self-signed certificate is created for this purpose. However, the certificate was not signed by a known CA, which causes the web browser to display a security warning when network users attempt to use the portal. See The Certificates pane for details. You can turn off this option and transmit via HTTP.
The Assets Portal runs in Internet Explorer, Chrome, and Firefox version 2 and above.
To access the portal from the Home view of the Console, right-click an endpoint in the Detections pane and select Information>Show in Assets Portal.
Search tools in the Assets Portal
To access the portal from the Home view of the Console, right-click an endpoint in the Detections pane and select Information>Show in Assets Portal.
Powerful search tools provide immediate access to an extensive range of endpoint and user information.
- Wild card searches: Search items are highlighted on the results page.
- Exact searches.
- Searches per category. For example, you can search by IP addresses, MAC addresses, Email addresses or DNS host names, and User Directory names.
From the Search Results page, you can easily pinpoint problematic endpoints, events, and users. In addition, action tools let you control endpoints directly from the portal.
The Assets Portal search result page indicates how many Appliances have been queried and how many responded to your Assets Portal search.
Hold your cursor over this string to view a tooltip that details this information.
Appliances disconnected at the time of the search are not queried. If you search for a specific address, the Appliance to which the IP address is assigned is queried. Other Appliances are ignored.
Expand information discovered by the Assets Portal
By default, Forescout eyeSight automatically discovers the following information about endpoints and displays that information in the Assets Portal:
- Domain User names
- NetBIOS host names
- MAC addresses
- DNS names
- Basic User Directory Plugin properties (this plugin is bundled with the Forescout eyeSight)
- Switch Plugin properties (this plugin is bundled with the Forescout eyeSight)
You can update the default to include additional information, for example, properties that are only available via the policy (Nmap details). See Endpoint Discovery Rules for details. You can also broaden the scope and capacity of the portal when you install plugins/modules. For example, if you installed the VPN Concentrator Plugin, related VPN properties are displayed in the portal. See Base Modules, Content Modules, and (Undefined variable: product-names.eyeExtend) Modules for details.
Assets Portal information can be imported and exported by using standard import and export tools from your web browser.
Access the Assets Portal
To access the Assets Portal, see Logging In to Forescout Web Portals.
minute read