Forescout eyeSight License Enforcement

After a term license expires, functionality degrades over time and stops completely 30 days after expiration unless a new license is applied.

For term licenses, expiration behavior follows this timeline:

  • Day 0 (license expiration): An alert and permanent banner appear.
  • 15 days after expiration: Functionality declines. Alerts and banners continue to display; existing policies run, but users cannot modify or create new policies.
  • 30 days after expiration: Functionality stops completely. Policies and plugins no longer work until a new license is applied.

See Receiving Flexx License Alerts for details.

If you add a Recovery Enterprise Manager to an Enterprise Manager while a license is in the grace period, the grace period does not apply for the Recovery Enterprise Manager and the license will be invalid.

When license enforcement begins, the license becomes invalid and certain Console configuration changes are restricted, as detailed below. If the Forescout eyeSight License becomes invalid, all other licensed products become invalid as well, even if their term has not yet expired.

License enforcement applies anytime a license is invalid. Under certain circumstances, this may occur even though the license is not expired. For example, if you remove an Appliance from a deployment, the Appliance functions as a Standalone Appliance without a valid license.
  • If the Forescout eyeSight License is invalid, users cannot:
    • Add or edit new policies
    • Add or edit Segments
    • Add or edit endpoint discovery rules
  • If the Forescout eyeSight eyeControl License or one of the Forescout eyeSight (Undefined variable: product-names.eyeExtend) Licenses is invalid, users cannot:
    • Add or edit properties/actions supported by the invalid license
    • Save imported policies that contain properties/actions supported by the invalid license. You must first remove these properties/actions.
    • Add properties supported by an invalid (Undefined variable: product-names.eyeExtend) module license to discovery rules.
    • Configure the following RADIUS settings (invalid eyeControl license):

      Add authentication sources

      Add, edit or import pre-admission authorization rules

      Add, edit or import entries to the MAC Address Repository

    • Add, edit or import registered guests from the Guest Registration pane (invalid Forescout eyeControl license)
  • If the Forescout eyeSight eyeRecover License is invalid, Console users cannot:
    • Enable failover clusters
    • Configure failover detection time for failover clusters
    • Define a failover scope for failover clusters
  • If the Forescout Platform eyeSegment License is invalid:
    • Mirrored traffic data is not uploaded for processing and analysis
    • Access to the eyeSegment application is denied

For term license expiration, existing policies continue to run only until 30 days after expiration; after that point, policies and plugins stop until a new license is applied.

When you remove an Appliance from a deployment, the Appliance functions as a Standalone Appliance with an invalid license and license enforcement will apply. Refer to License Management in the Forescout eyeSight Administration Guide for more information.