Set Up an appliance with the Forescout eyeSight Initial Setup Wizard

When you log in to the Forescout Console for the first time, the Initial Setup wizard appears.

Forescout eyeSight Initial Setup Wizard - Welcome

The Welcome pane is the first pane in the Initial Setup Wizard for an eyeSight component.

The Welcome pane displays the eyeSight component to which you logged in, as well as information you defined during the installation in the Data Center. More Appliance information can be viewed in the Forescout Options window.

Select Next to start the Initial Setup Wizard.

Initial Setup Wizard-Welcome Pane

Forescout eyeSight Initial Setup Wizard - License (Virtual Systems Only, Per-Appliance Licensing Mode)

The License pane of the Initial Setup Wizard appears only for a virtual system operating in Per-Appliance Licensing

The virtual license feature is designed to meet the needs of users working in Virtual IT environments, including environments that require a proxy server. These features ensure that such users are working with authorized, secure, and protected licenses.

Note: Refer to the Forescout eyeSight Installation Guide for information about installing Forescout virtual systems.

In the License pane, you can install the virtual demo license provided by your Forescout representative by email. This license is valid for 30 days from the time it was generated by the Forescout representative. When you install the license, the license expiration date is indicated. You must request and install a permanent license before this period expires. See Virtual Licenses for details.

You will be contacted via email regarding the license expiration date and any license violations. In addition, license alerts, violations, status and troubleshooting information can be accessed from the Appliance, Details pane. See View License Alerts for details.

Virtual licenses are authenticated daily by the Forescout License Server (at https://license2.forescout.com). Licenses that cannot be authenticated for a month are revoked and significant Forescout functionality stops. See Virtual Licenses for information about working with the License Server.

When working with the initial demo license, you can select any license file for any device, provided that a specific license file is installed on one device only. (If you use the same license file for more than one device, the license may be revoked. Moreover, you will be unable to add an Appliance to the Enterprise Manager if an Appliance with the same license is already connected.) You can rename the file if required. Extended demo licenses and permanent licenses are intended for a specific device.

Install License
Browse to and select the license file and then select OK. The Install License from File dialog box opens.
Select the device and then select Install.
A dialog box displays information about the start and end date for installing the license, as well as other license information.
If the End User License Agreement opens, accept it.

Forescout eyeSight Initial Setup Wizard - Time

Use the Time pane of the Initial Setup Wizard for time zone NTP time server synchronization settings.

Note: The NTP time server settings can be modified after the initial setup by selecting Tools > Options > General > Time in the Console. See Configure NTP Server Synchronization.

Initial Setup Wizard-Time Pane

Time Zone
Set the time zone according to your geographical location or by GMT offset. The default value is the time zone of the Appliance. This time zone is used when displaying and recording detection times in the Console.
Enable sync with NTP server
Enables synchronizing the system clock with an NTP time server. When enabled, lets you set NTP server addresses, and to enter their authentication key strings (SHA-1). Enabled by default.
NTP Server
devices require NTP connectivity (port 123 UDP) to an NTP server. Enter an NTP server that your organization connects to or use the default server (ntp.forescout.net).
In the Key field, enter the SHA1 key string used for authentication of the NTP server connection. (Optional but recommended).
Select Test to test the availability of the NTP server.
If the test fails, contact your IT professional.
You can add additional NTP servers after installation is complete. See Configure NTP Server Synchronization.
You can define NTP servers for individual Appliances, see Configure Additional NTP Servers

Forescout eyeSight Initial Setup Wizard - Mail

In the Mail pane, you can define the Mail relay and the Admin email addresses.

eyeSight generates email messages for:

  • Policy and Threat Protection alerts
  • Scheduled reports
  • Critical system operation alerts
  • Licensing alerts

    Initial Setup Wizard-Mail Pane

     

    Admin Email (Required)
    Forescout Administrator email address(es) or another address that should receive the email alerts / notifications, which are generated by eyeSight alerts. Separate multiple addresses by commas, spaces or semicolons.
    You can sign these emails using a digital certificate, as specified by the Secure / Multipurpose Internet Mail Extensions (S / MIME) standard. See Signing Emails with an S/MIME Certificate for details.
    Mail Relay
    The internal mail relay IP address to allow delivery of email alerts if SMTP traffic (port 25) is not allowed from the Forescout platform to the Internet.
    This must be the fully qualified host name. For example, mail-relay.example.com.
    If you enter an incorrect address you will not receive alerts.

    You can update all the options that the eyeSight SMTP mail server uses to send its email alerts/notifications, including using SMTP user name / password authentication with TLS (secure communication). See Managing Email Notifications.

Forescout eyeSight Initial Setup Wizard - User Directory

Use the User Directory pane of the Initial Setup Wizard to define the credentials for a User Directory server.

You can define User Directory credentials to validate network authentication and resolve user details. For example, endpoint User Directory display name, department name, or email address.

You can define various types of User Directory servers. The following user directory and authentication servers are supported:

  • Microsoft Active Directory
  • Novell eDirectory
  • Oracle Directory
  • IBM Lotus Notes
  • OpenLDAP Server
  • RADIUS
  • TACACS

You can work with more than one server type simultaneously. For example, if your organization uses Microsoft Active Directory for retrieving user details and a RADIUS server for verifying authentication, you can configure the plugin to work with both these server types.

Note: You cannot configure RADIUS or TACACS authentication servers in the Initial Setup Wizard.

You can define additional User Directory servers from the Forescout Console Options window by selecting User Directory, and then selecting Add.

Initial Setup Wizard-User Directory Pane

Setup requires a User Directory server that can be queried to validate authentication and obtain details regarding users at detected endpoints. Configure the following settings in the User Directory pane:

Name
Enter the hostname of the server.
Note: This value cannot be edited later.
Type
Select a server type:
Microsoft Active Directory
Novell eDirectory
Oracle Directory
IBM Lotus Notes
OpenLDAP Server
Note: This value cannot be edited later.
Address/DNS Detection
Do one of the following:
Enter the remote address of the server, such as an IP address, an FQDN address string, or an IPv6 address string. For server types other than Microsoft Active Directory, this is the only option.
Select DNS Detection to instruct the eyeSight to learn directory servers based on the domain name configured in the Directory section, Domain field. This option applies to Microsoft Active Directory servers only. For more information, refer to the User Directory Plugin Configuration Guide.
Port
Enter the server port in the Port field. The default port for servers used as directories to retrieve user information is 636.
Use TLS
For some server types, you can instruct the eyeSight to use TLS to encrypt communication with the User Directory server. By default, Use TLS is enabled.
Ensure that TLS communication is supported and enabled on servers used as directories to retrieve user information. The User Directory Plugin can communicate with servers that support TLS 1.1 or TLS 1.2. It cannot communicate with servers that support TLS 1.0 only.

After User Directory server setup, you can view and edit the existing User Directory server configuration by selecting Tools > Options > User Directory in the Console. User details and authentication status are displayed in the Detections pane. For more information about User Directory server setup, refer to the User Directory Plugin Configuration Guide.

Forescout eyeSight Initial Setup Wizard - Domains

Use the Domain Credentials pane of the Initial Setup Wizard to set up network domain credentials that the Appliance uses to perform deep inspection on endpoints.

In the Domains pane, enter the domain information necessary for the Appliance to authenticate with the Domain Controller. Domains should include endpoints that are handled by your policies. You may include several domain entries.

In the Domains pane, select Add, and define the following:

Domain Controller
The Domain Controller IP address. This information is used to test password validity and provide defaults for the authentication servers defined later.
Domain Name
The domain name. The domain should include all endpoints that you want to inspect via the policy. Endpoints in this domain must also be in the Internal Network.
User
The domain administrator name for this domain.
Password
The domain administrator password for this domain.
Note: Refer to the Forescout eyeSight Installation Guide for information about installing Forescout virtual systems.

If the verification test fails, you may need to perform troubleshooting tasks. See Remote Access to Endpoints for details.

Note: Refer to the Forescout eyeSight Installation Guide for information about installing Forescout virtual systems.

Forescout eyeSight Initial Setup Wizard - Internal Network

Use the Internal Network pane in the Initial Setup Wizard to define your network segments or IP ranges.

The Internal Network is a set of network segments or IP ranges that defines your network in the eyeSight. When eyeSight detects endpoints with IP addresses within the Internal Network, they are assumed to be in your network.

The Internal Network defines the extent of eyeSight management activity. For example, when a Forescout policy scope is defined as "All IPs," the policy is applied to all IP addresses in the Internal Network. Network segments that are part of your physical network, but are not included in the Internal Network definition, are not managed by Forescout products. In addition, endpoints in the Internal Network must be visible to Forescout Appliances.

The Internal Network is defined in the Console as a set of named IP ranges. Typically, these ranges correspond to logical segments of your network.

Several Forescout tools use these Internal Network segments. For example, you use these segments to assign sectors of your network to Appliances, to define the scope of a policy, and to define the active response range for Threat Protection features.

Segments you define during setup can be fine-tuned to more closely represent the structure of your corporate network, and you can add additional segments later. See Working with Forescout Segments for details.

Initial Setup Wizard-Internal Network Pane

In the Internal Network pane, select Add to define IP ranges or subnets. The Segment name field is mandatory.

Note: Refer to the Forescout eyeSight Installation Guide for information about installing Forescout virtual systems.
Note: Refer to the Forescout eyeSight Installation Guide for information about installing Forescout virtual systems.

Completing interface assignments made in the Data Center

If you change the monitoring interface assignment in the Channels pane, you must go back to the Data Center and readjust the physical interface connections so that they match.

Initial Setup Wizard-Channels pane

Initial Setup Wizard-Channels Pane

If your network architecture is set up to work with VLANs, the Appliance automatically detects them. These VLANs are listed in the Channels pane.

Status Indicators

An indicator is displayed on the Console status bar if:

  • There is a connectivity problem on an enabled VLAN or interface.
  • No channels are enabled.
  • A new VLAN is discovered by the Appliance.
Note: A tooltip provides details about the event.

The Channels pane contains the following options:

Enabled
Activates the channel configuration. Select this option for each VLAN that you want to activate.
Monitoring and response activity do not take place until you select Apply from the Channels pane.

Monitor Interface Information

Monitor VLAN
Displays all VLAN IDs discovered for the selected monitor interface.
If you defined a channel that works with an IP layer, that VLAN is displayed as IP LAYER.
Traffic
Displays total VLAN traffic detected on the monitor interface.
Mirrored Traffic
Displays the percentage of mirrored traffic from the total VLAN traffic.
Symmetric
Indicates whether the interfaces passed the Symmetric Traffic test. The test verifies that the Appliance can see symmetric traffic on the monitoring interfaces. That is, for every TCP conversation, both incoming and outgoing traffic is visible. If this condition is detected, traffic received on the channel is ignored until the condition has cleared.
The test runs continually.
If the test fails, you can review related troubleshooting information at the bottom of the Channels pane.
# Hosts
Displays the total number of endpoints monitored on the VLAN.

Response Interface Information

Response VLAN
Displays all VLAN IDs discovered for the selected response interface.
Traffic
Displays total VLAN traffic detected on the response interface.
Response
Indicates whether the Response Traffic test succeeded on the VLAN. The test verifies that the Appliance successfully sends response traffic to the network.
The test runs continually.
If the test fails, you can review related troubleshooting information at the bottom of the Channels pane.
IP Address
Displays the DHCP address used by the Appliance for response traffic. By default, the IP address is acquired through DHCP.
If the DHCP is not successful, the cannot respond to ARP requests. In this case, manually define the address.
Addresses are defined per VLAN, if required. See Manually Add a VLAN for details.
Use DHCP by Default
Select this option if a DHCP address is used by the for monitored traffic. Clear this option to manually configure the IP address.

Initial Setup Wizard - Switch

Use the Switch pane in the Initial Setup Wizard to configure the switches that the Switch Plugin manages.

For switches managed by the Switch Plugin, use eyeSight switch tools to:

  • Track the location of endpoints connected to network switches and retrieve relevant switch information. For example, users can view the switch IP address and switch port to which endpoints are connected.
  • Detect new endpoints on the network, by alerting the Forescout eyeSight about port status changes via SNMP traps.
  • Assign switch ports to VLANs, allowing you to set up dynamic, role-based VLAN assignment policies or quarantined VLANs.
  • Use ACLs to open or close network zones, services, or protocols on specific endpoints at the switch.
  • Block endpoints based on IP addresses or MAC addresses.
  • Shut down switch ports completely.

    Initial Setup Wizard-Switch Pane

    In the Switch pane, you can configure a switch that exists in your network by selecting Add, and completing the Add Switch wizard.

You can configure the switch to add other switches in your network in two ways:

  • Auto-discover additional switches: Switches of certain vendors (Cisco, HP, Brocade/Foundry, Enterasys and Nortel) can auto-discover neighboring switches of any of these vendors. Discovered switches inherit basic attributes of the switch that detected them. All permissions and ACL configurations in discovered switches are disabled
  • Use the switch configuration as a template for other switches: When an unmanaged switch (that is, a switch that is not managed by the Switch Plugin) sends an SNMP trap and the community string of the unmanaged switch matches the community string of this switch, then all the settings of this switch (except its IP address) are applied to the unmanaged switch. Switches detected in this manner are automatically added in the Console.

    You can also add additional switches here, and then select Switch in the Console Options window to edit switch configurations and use additional Switch Plugin features.

Note: You will need to complete the configuration of auto-discovered switches including (recommended) enabling auto-discovery (so that their neighbors can also be auto-discovered) and then enabling these switches.
Note: Refer to the Switch Plugin Configuration Guide for information about additional switch configuration features.

Initial Setup Wizard - Policies

Use the Policies pane of the Initial Setup Wizard to classify endpoints into easily manageable groups of network assets and corporate/guest users.

Network asset classification is carried out by a eyeSight Primary Classification policy. Corporate/guest user classification is carried out by a Corporate/Guest Control policy. These policies are created using core policy templates.

Note: After registering with an Enterprise Manager, many Appliance policy settings are automatically replaced with the Enterprise Manager settings. See CounterACT Device Management Overview for details.
Initial Setup Wizard-Policies Pane

Initial Setup Wizard-Policies

How classification works

A proprietary algorithm is used to compare the properties of endpoints with the properties of pre-defined device classification profiles, each composed of properties and corresponding values. When the classification algorithm detects that certain endpoint properties match a given profile, the endpoint is classified appropriately. For example, the profile defined for Apple iPad considers a set of properties that includes the HTTP banner, the NIC vendor, and Nmap scan results.

Classify Devices
Select this option to enable Primary Classification, which resolves function, operating system, vendor, and model classification properties on connected devices, and groups the devices into the following easily manageable groups.
Detect Guests
Select this option to enable Corporate/Guest control policies and related groups.

Initial Setup Wizard - Inventory

Use the Inventory pane in the Initial Setup Wizard to select the network activities to include in the Asset Inventory. The Asset Inventory presents a live display of network activity in the Console, for example, running processes and services, detected vulnerabilities, open ports, and logged in users.

See also Working with Asset Inventory Detections for details about the inventory, or select Help in this pane.

Use the Asset Inventory to:

  • Broaden your view of the network from endpoint-specific to activity-specific.
  • View endpoints that have been detected with specific attributes whether or not they are policy-compliant.
  • Easily track network activity.
  • Incorporate inventory detections into policies. For example, if you discover that network guests are running unauthorized processes on your network, create a policy that detects and stops these processes on guest machines.
     

    Initial Setup Wizard-Inventory Pane

    Note: External Devices Connected and Microsoft Vulnerabilities are excluded from the default Inventory rules. Discovery of these properties may generate extensive network traffic. You can include them by updating the Inventory rules. See How the Asset Inventory Is Learned for details.
    Note: Open ports can also be displayed in the Asset Inventory. This information can be displayed by creating a policy that includes the Open Ports property.
Note: Refer to the Forescout eyeSight Installation Guide for information about installing Forescout virtual systems.