Policy preferences

The preferences set here are applied to all connected Appliances. Preferences cannot be set individually for each Appliance.

To access the NAC options select Tools > Options, and then select NAC.

Defining authentication servers

Policies can be created to verify network users have been authenticated via specific authentication servers.

The following authentication servers are supported:

  • HTTP (80/TCP)
  • Telnet (23/TCP)
  • NetBIOS-SSN (139/TCP)
  • Microsoft-DS (445/TCP)
  • Microsoft-MAPI (135/TCP)
  • FTP (21/TCP)
  • IMAP(143/TCP)
  • POP3(110/TCP)
  • rlogin (513/TCP)

After you configure authentication servers, they are automatically deployed. These servers are automatically opened and added as Virtual Firewall rules. View these rules in the Firewall Policy pane.

images/image168.png

HTTP Redirection options

Each Appliance can support up to 200 hijack actions per minute.

Several options are available for handling HTTP traffic from Tools > Options > NAC > HTTP Redirection.

NAC > HTTP Redirection

Defining HTTP Redirect exceptions

You may need to refrain from redirecting business essential Internet sites or refrain from blocking access to important files on the Internet. This can be performed by creating HTTP redirect exceptions.

By default, user web sessions going to the Internet and Intranet are redirected. An option is available to only handle Internet traffic. See Redirecting Web and Intranet Sessions.

You can define exceptions in two ways:

Global URL Exceptions

Endpoint users who browse to URLs in this list are not redirected by Forescout eyeControl even when an HTTP action is applied to the endpoint.

A number of URL strings are included in the list of global HTTP redirection exceptions by default. These strings are included to prevent endpoint users from receiving browser errors related to various issues, such as proxy servers, certificate revocation, and captive portals. These strings can be edited or removed.

By default, the following URLs are never redirected:

  • windowsupdate.microsoft.com
  • windowsupdate.com
  • update.microsoft.com
  • updates.microsoft.com
  • exchange

This enables access to Microsoft Windows Update servers and prevents redirection of the Exchange server when used via the web interface. These URLs cannot be seen or edited by the user.

  1. Select Tools > Options > NAC > HTTP Redirection.
  2. Select Global… in the HTTP Redirection Exceptions section to open the Global dialog box.

    Global dialog box

  3. Select Add.
  4. In the New URL Text dialog box, select an option from the Look in URL drop-down menu.
    • Filename
    • Address
  5. Select Contains or Exact.
  6. In the Text field, enter the URL address or filename to search for.
  7. Select OK
Note: If the address contains one string from the defined list, the user is not redirected.

Redirecting web and Intranet sessions

By default, all user sessions are redirected regardless of whether the traffic goes to the Internet or to the Intranet. An option is available to redirect Internet traffic only.

  • In the Global dialog box, select Only redirect HTTP traffic going to the Internet. User sessions to the Intranet are not redirected.

IP address exceptions per action

Configuring HTTP Redirection Exceptions per action lets you define IP address ranges or segments that are not affected by a specific HTTP action. For example, create a policy that displays a customized message in end user web browsers using the HTTP Notificationimages/image172.png action, except for endpoint IP addresses between 192.168.10.15 and 192.168.10.30.

Add IP address ranges or segments to a repository of HTTP exceptions that can later be applied to individual actions.

This feature applies to the following HTTP actions:

HTTP Localhost LoginHTTP Localhost Login

HTTP LoginHTTP Login

HTTP NotificationHTTP Notification

HTTP Redirection to URLHTTP Redirection to URL

Start SecureConnectorStart SecureConnector

Windows Self RemediationWindows Self Remediation

You can add an HTTP Redirection exception per action in the following ways:

Note: If you want to apply global HTTP exceptions to all network users, you can work with Global URL Exceptions.

When multiple HTTP actions, each containing HTTP Redirection Exceptions, are simultaneously applied to an endpoint, only the exceptions for the first HTTP action received by Forescout eyeControl are applied. Additional HTTP Redirection Exceptions are only applied when there are no other HTTP actions applied to the endpoint.

Add an exception to the repository

Exceptions that you create in the repository can be applied in the Exceptions tab of HTTP actions.

  1. Select Tools > Options > NAC > HTTP Redirection.
  2. Select Per Action... in the HTTP Redirection Exceptions area.

    Per Action dialog

  3. Select Add.
  4. Enter a name for the exception in the Add IP Range dialog box.
  5. Select Add to add an IP address range or segment, and then select OK.
  6. Select OK in the Add IP Range dialog box.
  7. Select OK in the Per Action dialog box.

Apply an exception to an action

  1. In the relevant HTTP action configuration, navigate to the Exceptions tab.
  2. Select Add. In the dialog box that opens, Select the name of the HTTP exception from the Select IP Range drop-down menu, and select OK. The exception is displayed in the Exceptions table.

Redirect using web server DNS name

When Forescout eyeControl redirects a browser to the captive web server, it can either use the web server IP address or its DNS name. Using the DNS name is recommended when using encrypted HTTPS transactions. The web server can have a certificate installed, avoiding the browser warning when interacting over HTTPS with an uncertified web server. For the DNS option to work properly, the endpoints must resolve this name using their defined DNS servers.

  1. Select Tools > Options > NAC > HTTP Redirection.
  2. Select Attempt redirect using the DNS name to redirect using the DNS name.

Global redirect via HTTPS

Redirect via HTTPS is selected by default and cannot be changed.

Redirected traffic includes information sent to network users via the HTTP actions, as well as authentication credentials sent back to the Appliance. For example, when you use the HTTP Localhost Login action, authentication credentials are sent back to the Appliance using the method that you defined.

If you transmit via HTTPS, network users see a security alert in their web browser when they attempt to access the web. The alert indicates that the site's security certificate was not signed by a known Certificate Authority (CA). (A default self-signed certificate is installed during product installation). You can generate a known CA Security Certificate to avoid this situation. See Generating and Importing a Trusted Web Server Certificate and HTTP Redirection for details.

Skip HTTP redirect confirmation message

You can instruct Forescout eyeControl to not display the confirmation message that appears by default at the endpoint after the HTTP action is successfully completed. When this happens, endpoint users are automatically redirected to the page they originally browsed to.

  1. Select Tools > Options > NAC > HTTP Redirection.
  2. In the HTTP Redirection Settings area, select Auto-redirect on success.

Defining proxy ports for HTTP notification

If your organization is configured to access the web through a proxy, you must enable the ports.

  1. In the HTTP pane, select Monitor Proxy Ports for HTTP Notifications.
  2. Enter the ports in the Proxy Ports List field. Use the following format: 80/TCP, 8080/TCP, 8888/TCP.
  3. Select Applyr.

Customize HTTP pages

Redirected web pages are generated by eyeSight users to interact with endpoints when specific actions are performed. At the endpoint, a default or customized web page replaces the page otherwise displayed. The content inside the page is configured when defining policy actions. See Working with Actions for details.

Use the User Portal Builder when customizing the web pages displayed by the following eyeSight eyeControl actions:

  • HTTP Login
  • HTTP Notification

For more information, see The Forescout User Portal Builder.

When you upgrade from versions earlier than 8.0.0, customizations created using the legacy Forescout Customization Tool are preserved for these interfaces and are upgraded to the User Portal Builder. However, customization files that are configured manually and then copied to the Forescout file system in versions earlier than 8.0.0 are not available after upgrade. Use the User Portal Builder to recreate these customizations.

Use the legacy Customization Tool when customizing the web pages displayed by the following Forescout actions:

  • HTTP Localhost Login
  • Start SecureConnector
  • Start Macintosh Updates
  • Start Windows Updates
  • Windows Self Remediation
  • Compliance Center

For more information, see The Legacy Customization Tool.

When you upgrade from versions earlier than 8.0.0, all customizations for these interfaces are upgraded.

Email preferences

The Send Email action automatically delivers email to administrators when a policy is matched. If there is extensive activity as a result of your policy, the recipients may receive an overwhelming number of emails.

The following tools are available to help you manage email deliveries:

  • Define the maximum number of email alerts delivered per day (from midnight)
  • Define the maximum number of events that are listed in each email

For example, you can define that you only want to deliver five emails per day, and that each email will contain up to 50 events. The limits defined apply to each email recipient, and for both the Send Email and Send email to host actions.

Customizing endpoint identity change thresholds and detection mechanisms

IP addresses associated with a specific MAC address may change frequently. This may happen, for example, if several VPN users receive different IP addresses for the same MAC address. eyeSight ignores these changes for the purpose of rechecking the same endpoints and carrying out actions on them.

By default, IP address changes are ignored when up to 20 changes occur within a 5-minute period on the same MAC address.

Before the threshold is passed:

  • All actions are released from the original IP address and no actions are applied to the new IP address when the change occurs.
  • However, eyeSight activates the Admission based activation option for the IP address

    The detection is displayed in the Detections pane with the same MAC addresses and the most current IP address detected.

After the threshold has passed: If there is an IP address change after the threshold has passed:

  • The MAC address is ignored as a mechanism for identifying the endpoints in any policy.
  • The MAC is automatically added to a list of ignored addresses which can be modified manually by adding or deleting MAC addresses as needed.
  • All new detections on the MAC are displayed individually per IP address.

Select Tools > Options > NAC > Identity. Use the options in this pane to update the default IP address threshold. You can also apply the ignore mechanism and threshold definitions to NetBIOS host name changes detected on the same IP address.

Count
The number of IP address changes that can occur before the threshold is passed.
Period
The time period during which identity changes can occur before the threshold is passed.
Ignore period
Endpoint identity change will be ignored for this period.
Ignored host identities
The MAC addresses that are ignored during detection. The threshold for IP address changes on this MAC has been passed. The MAC is automatically added to a list of ignored addresses. You can edit and remove MAC addresses from the list.
Link & Sync Identities
If selected, Forescout will link and sync assets that have identical hostnames in their Fully Qualified Domain Names (FQDNs).
NetBIOS Hostname
Apply the ignore mechanism and threshold definitions to NetBIOS names that change on the same IP address.

Time settings

Select Tools > Options > NAC > Time Settings to set the time settings.

images/image185.png

Network Admission Resolve Delay
A delay time between the detection of network admission events and the onset of the policy evaluation. This delay increases the chances that the rule evaluation will start when more details can be learned on the endpoint (after all services have loaded).
You can also set this value per policy. See Update the Network Admission Resolve Delay in Main Rule Advanced Options for details.
Policy Ignores Information Older Than
A time period that Forescout eyeSight does not see traffic at previously detected endpoints. Endpoints listed in a policy that are inactive beyond the time set here are no longer rechecked. Inspection begins again only when the endpoint in rediscovered as a result of the activation settings defined. The default Inactivity Timeout is defined in the Policy Preferences dialog box. The value there is applied to all Appliances until changed specifically, per policy, here.
Inactivity Timeout
After initial detection, endpoints in your network may disconnect from the network, that is, go offline.
For endpoints that are not connected to a switch managed by the Switch Plugin, the Inactivity Timeout option is used to resolve offline status. This is the time period that endpoints should be disconnected from the network in order for Forescout eyeSight to resolve them as offline. The minimal (and default) offline setting is one hour.
This parameter applies to policy endpoints as well as other endpoint detections. Endpoints that are offline beyond the time set here can be hidden from the Home view, Detections pane. This lets you view and work exclusively with online endpoints.
If endpoints are connected to a switch that is managed by the Switch Plugin, by default Forescout eyeSight detects offline status within one minute. Refer to the Switch Plugin Configuration Guide for information about changing this one-minute default setting.
Purge Inactivity Timeout
After initial detection, endpoints in your network may disconnect from the network - become inactive for a lengthy period. The Purge Inactivity Timeout refers to a specific time period that Forescout eyeSight does not see traffic at endpoints that it previously discovered. This includes policy endpoints as well as other endpoint detections. Endpoints that are inactive beyond the time set here are cleared from the database. For example, those endpoints no longer appear in the Detections pane, Host Details dialog box, Policy Log, in reports, or in the History view.
Purge IPv6 Timeout
This setting determines how long Forescout eyeSight associates an IPv6 address with an endpoint. This timeout is measured from the time eyeSight learns the IPv6 address. If eyeSight does not detect this address or its related MAC address in the network during the time period specified:
It no longer associates the address with the endpoint. This address no longer appears in the IPv6 Address host property for the endpoint.
If the endpoint has no other IP or MAC address, it is purged completely.
Display Action Icon after Action Is Complete
 
The time period that the Console displays an Action icon after a one-time action is complete.