Policy safety features

Several safety features are available to help ensure that your policies efficiently handle endpoints.

Working with action thresholds

An action threshold is the maximum percentage of endpoints that can be controlled by a specific action type defined at a single device. By working with thresholds, you gain more control over how many endpoints are simultaneously restricted in one way or another..

In some scenarios, policy enforcement requires blocking or restricting network devices and users. Action thresholds are designed to automatically implement safeguards when rolling out such sanctions across your network. Consider a situation in which you defined multiple policies that utilize a blocking action, for example, the Virtual Firewall or Switch Block action. In a situation where an extensive number of endpoints match these policies, you may block more endpoints than you anticipate.

How Action thresholds work

  1. Forescout products set default thresholds for an action type.
  2. Forescout products put actions on-hold for endpoints that are detected after the threshold is passed.
  3. An On-hold indicator blinks on the Console status bar. Manual approval is required to cancel the on-hold status and carry out the actions.
  4. Select the indicator to access the Action Threshold dialog box, where you can, for example, change the threshold or stop the device. Additional options are also available.
  5. When the situation is remediated and the blocking limit falls below the threshold, you can cancel the on-hold status and continue to block or remediate.
  6. You can also manually select endpoints and cancel on-hold status.

You can also create threshold policy exceptions, i.e., policies that you want to exclude from action threshold calculations. For example, you can exclude all thresholds when working with policies that handle outside contractors.

How On-hold thresholds are calculated

Thresholds for each action type are calculated per device, based on the number of endpoints assigned to the device.

To enforce on-hold status, the following must occur:

  • A threshold percentage must be exceeded. See Actions Covered and Threshold Percentages for details.
  • The number of endpoints with an action assigned to them must be equal to or more than the minimal number of endpoints Forescout eyeSight is instructed to detect before calculating the threshold. By default, this number is ten.

Using the default, if the total number of endpoints assigned to a device is 500, and the default threshold for the Switch Block action is 2%, then the threshold limit is passed after 2% of the endpoints on the device (or 10 endpoints in this example) are blocked via the switch. At this point, the action is put on-hold for new endpoints detected.

Actions covered and threshold percentages

The following table lists actions covered by thresholds and the default threshold values.

Action Default Threshold

Switch Block

2%

Assign to VLAN

2%

Virtual Firewall

2%

HTTP Notification

20%

HTTP Redirection to URL

20%

Send Email

2% during one minute

VPN Block

1%

WLAN Block

1%

Kill Process on Windows

2%

Add to Blocking Exceptions list

2%

ACL

2%

Disable External Device

2%

How do I know when a threshold violation occurred?

The action threshold indicator flashes if a threshold violation occurred.

You can select the icon to open the Action Threshold dialog box for details. At that point the indicator will remain on the status bar, but will not flash.

A tooltip gives you information about the on-hold status.

Configure action thresholds

 

Select Tools > Options > NAC > Action Thresholds.

images/image197.png

The Actions area lists all the actions defined in your enterprise and provides related information.

Statusimages/image198.pngimages/image199.png
The on-hold status of the action. If the action is put on hold at one device, the overall status is considered On-hold.
A green check-mark means that the action is not on-hold at any device. A blue icon indicates that it is On-hold.
Action
The action being handled.
# On-hold Devices
The number of devices that are working with an on-hold action.
Max % Hosts With Action
The highest percentage of endpoints covered by an action at a specific device, in relation to all enterprise devices. For example, 20% of all endpoints at a specific device have been assigned this action, and this is the highest percentage at all devices.
Use the value to get a better understating of how to configure your threshold for a particular action. Using this example, if 20% is the maximum value but the default threshold is at 2%, you may want to adjust the threshold.
Threshold
The current on-hold threshold for the action.
Policies
Policies that include this action.

Select an action from this section and review detailed threshold information in the Threshold Details area. This section displays threshold information for the action you select in the Actions area, for example, the current number of endpoints On-hold at a specific device for the Virtual Firewall action. You can also use the tools in this section to:

  • Change the default threshold.
  • Create threshold policy exceptions; policies to exclude from action threshold calculations. For example, exclude all policies that handle organizational visitors.
  • Configure thresholds if you are working in small environments.
  • Start or stop a device.
  • Cancel the On-Hold mechanism.
  • Include or exclude endpoints that were manually assigned an action.

The Devices tab describes threshold information for an action you select in the Actions area, for example, the current number of endpoints on hold at a specific device for the Send Email action.

Status
The On-hold status for the action on the selected device. A green check-mark means that the action is not On-hold at this device. A blue icon indicates that it is.
Device
The device IP address.
Threshold
The current threshold for this action. The threshold is identical on all devices and varies by default per action.
% Hosts With Action
The percentage of endpoints on the device that are targeted for the action selected in the Actions section. Some actions may be carried out, while others may be on-hold because of a threshold violation.
# Hosts With Action
The total number of endpoints on the device to which the action applies. Endpoints detected by policies that are configured as threshold exceptions are not counted.
# On-hold Hosts
The number of endpoints on the device that are not being controlled by the action because of a threshold violation - On-hold.
Stop Device
 
When you stop a device, all activity on endpoints is halted. You may decide to do this if the action is causing unexpected results.
Manage Held Action
Define how to handle a held action on previously detected endpoints. Options:
  • Perform the action.
  • Cancel the action. The action remains canceled until it is either deleted or unmatched to a policy and then matched.
  • Leave the action on-hold.
After releasing the on-hold mechanism, you can continue blocking or restricting newly detected endpoints.

Use the Configuration tab of the Thresholds pane to change the default configuration for the threshold and to create threshold policy exceptions - policies that you want to exclude from action threshold calculations. For example, exclude all policies that handle organizational visitors. You can exclude an entire policy or a specific rule. Threshold values that contain fractions are rounded to the nearest whole number.

images/image201.png

Minimal number of hosts
The minimum number of endpoints that are counted for an action before enforcing a threshold. For example, wait until 20 endpoints are detected with a certain action before calculating the threshold. This setting applies to all devices. The calculation is done by each device separately. The default setting is 10 endpoints.
In small enterprises with fewer endpoints, the default threshold may be initiated too soon. For example, if the threshold is 1% and less than 100 endpoints are assigned to the device, then the first action will bypass the threshold. Conversely, in large organizations, the threshold may need to be lowered.
Count Manual Actions
By default, endpoints that were manually assigned actions are included in the endpoint count. To exclude these endpoints, clear this option.

Managing actions on-hold on a specific device

If too many actions are not being carried out, you can take the following actions to release the On-hold mechanism on previously detected endpoints.

  • Increase the action threshold in the Configuration tab from the Options > NAC > Actions Thresholds pane.
  • Stop the relevant policies.
  • Increase the minimum number of endpoints to detect.
  • Add the relevant policies to the Policy Threshold Exceptions list in the Configuration tab from Tools > Options > NAC > Actions Thresholds.
  • Apply the Manage Held Action option to selected devices.

Approve actions on a specific endpoints

You can release the On-hold status for specific endpoints and approve the action.

  1. In the Detections pane, click the Actions column header, and look for the hourglass icon. This icon indicates endpoints that are On-hold or Pending. The first set of endpoints is On-hold.
  2. Right-click the endpoint, and then select Approve Actions. Select the action that you want to release from On-hold.

Handling irresolvable criteria

In some situations, eyeSight cannot properly resolve endpoint property criteria. Such criteria are considered irresolvable criteria.

Property criteria can have a status of Irresolvable for one of two reasons:

  • eyeSight failed to resolve the criteria.
  • A system error caused eyeSight not to respond to the resolve request (for example, a plugin is not running or experienced a timeout).

Many properties provide an option for handling irresolvable criteria. If eyeSight cannot verify a property, you can choose how to resolve that endpoint.

images/image202.png

You can instruct eyeSight to handle irresolvable criteria as follows:

True
Treat the endpoint as if it matches the criteria defined for the property.
False
Treat the endpoint as if it does not match the criteria defined for the property.

If you do not select the Evaluate irresolvable criteria as option, the criteria is handled as irresolvable and the endpoint does not undergo further analysis. The endpoint is not checked to see if it matches additional condition criteria

By default, all irresolvable criteria are evaluated according to the user-defined settings configured in the property (Evaluate irresolvable criteria as True/False).

However, when criteria are irresolvable due to a system error, you can change this default setting. Because this status did not stem from an actual failure to resolve, but rather from of an error, this resolution can be considered imprecise. As a result, you can override any user-defined settings and continue to evaluate such criteria as irresolvable. The endpoint does not undergo further analysis and is not checked against additional condition criteria.

To access this setting, select Tools > Options > Advanced Policy.

Evaluate criteria that is irresolvable due to a system error
Determines how to handle irresolvable criteria that are not caused by a failure to resolve the property.
  • Always as Irresolvable - continue to evaluate Irresolvable criteria as such when the evaluation was caused by a system error.
  • According to user-defined settings per property -irresolvable criteria are evaluated according to the user-defined settings configured in the property.

Handling criteria defined as empty lists

Properties supply information learned on an endpoint to evaluation criteria. If a property is normally populated with information that is not present on an endpoint, eyeSight evaluates the property as an empty list for that endpoint. You can choose to evaluate the properties as True or False in this case.

For example, the Microsoft Vulnerabilities Fine-tuned property is used to report and evaluate the Microsoft vulnerabilities on an endpoint. If the endpoint has no Microsoft vulnerabilities, no content is returned for the property, and a criteria based on this property cannot be evaluated.

Evaluate empty list value as
Determines how to resolve criteria when an endpoint does not contain information reported by a property.

images/image203.png