Restricting endpoint inspection
Forescout products use both passive and active methods to inspect and manage endpoints:
- Passive methods learn endpoint information from network devices, monitored traffic, or other data sources in your environment.
- Active methods include probing the endpoint for open ports, running Nmap against the endpoint, or any other attempt to establish a network connection to the endpoint.
Some devices, such as critical OT/IoT devices, can be adversely affected if eyeSight repeatedly connects to resolve properties or run Nmap scans. This is referred to as active scanning. Assign these endpoints to the Properties - Passive Learning group to limit active scanning of specified endpoints or IP ranges. Forescout eyeSight never contacts endpoints in this group to resolve properties, even for policy evaluation. Properties that can be learned passively may be resolved for endpoints in this group, depending on available information.
The following options are available for restricting inspection of endpoints:
- Add individual endpoints or import lists of endpoints using the Properties - Passive Learning group manager. See Import and Export Group Members.
- Apply the Add to Group action to endpoints that match policy conditions. See Add to Group for details.
If you are not sure which devices may be adversely impacted by active scanning, you can use the Passive Learning Mode template to discover and handle them. See Passive Learning Mode Template for details.
minute read