Restricting endpoint inspection

Forescout products use both passive and active methods to inspect and manage endpoints:

  • Passive methods learn endpoint information from network devices, monitored traffic, or other data sources in your environment.
  • Active methods include probing the endpoint for open ports, running Nmap against the endpoint, or any other attempt to establish a network connection to the endpoint.

Some devices, such as critical OT/IoT devices, can be adversely affected if eyeSight repeatedly connects to resolve properties or run Nmap scans. This is referred to as active scanning. Assign these endpoints to the Properties - Passive Learning group to limit active scanning of specified endpoints or IP ranges. Forescout eyeSight never contacts endpoints in this group to resolve properties, even for policy evaluation. Properties that can be learned passively may be resolved for endpoints in this group, depending on available information.

Note: When you assign an endpoint to the Properties – Passive Learning group based on its MAC address, Forescout eyeSight may apply active scan processes when it first detects the endpoint's IP address on the network, until it discovers the endpoint's MAC address.
Note: From eyeSight v8.4, the Forescout Admin (REST) API provides you with automatic configuration capabilities for managing deployments on the eyeSight, where network entities, such as the segment tree and default groups ranges, can change on a daily basis. The Admin API allows you to integrate third-party network management IPAM (IP Address Management) tools, such as Infoblox and BlueCat, and ensures that segments defined on the eyeSight are synchronized with their latest IPAM database definitions. For more information, see Work with the Forescout Admin API in the Admin API Plugin Configuration Guide.
Note: When you assign an endpoint to the Properties – Passive Learning group based on its MAC address, Forescout eyeSight may apply active scan processes when it first detects the endpoint's IP address on the network, until it discovers the endpoint's MAC address.

The following options are available for restricting inspection of endpoints:

  • Add individual endpoints or import lists of endpoints using the Properties - Passive Learning group manager. See Import and Export Group Members.
  • Apply the Add to Group action to endpoints that match policy conditions. See Add to Group for details.

If you are not sure which devices may be adversely impacted by active scanning, you can use the Passive Learning Mode template to discover and handle them. See Passive Learning Mode Template for details.