Working with appliance folders

 

Use Appliance folders to simplify and unify eyeSight device management and configuration tasks. These folders are especially useful for medium- and large-scale deployments.

Use Appliance folders to group devices into a tree structure, and to correlate Appliances with geographical or functional segments of the Internal Network. The Appliances in a folder handle endpoints in the Internal Network segments you assigned to the folder.

Define Appliance folders to:

  • Efficiently support large or geographically disperse networks
  • Implement automatic IP allocation between Appliances
  • Create failover clusters (licensed feature. Refer to the Forescout eyeSight Resiliency and Recovery Solutions User Guide.

Use Forescout segments based on the Internal Network to assign IP addresses to folders or Appliances. Define these segments in the Segment Manager before you work with folder tools. For example, if your network expands, you typically:

  • Install new Appliances
  • Use the Segment Manager to define segments with your network's new IP addresses. See Working with Forescout Segments.
  • Add these segments to the Internal Network. See Working with the Internal Network.
  • Follow the procedures described in this section to define folders that contain the new Appliances, and to assign the new segments to Appliances.
Note: If you change the definition of Internal Network segments, this can change which IP addresses are assigned to folders or Appliances.

The following general permissions are required to work with Appliance folders:

  • CounterACT Configuration
  • CounterACT Policy Management

To work with folder tree actions, the following additional permissions are required:

  • Multiple CounterACT Appliance Management (update)
  • CounterACT Appliance Control

Write permission is required to save changes.

To work with Appliance folders select Options> CounterACT Devices > IP Assignment and Failover.

The IP Assignment and Failover pane opens.

images/image673.png

The tree of Appliance folders is shown in the left pane. If you have already defined Appliance folders, they appear in the tree. To modify the folder tree, select a node in the tree and perform one of the following actions:

images/image113.png
Add a folder. You are prompted to name the new folder. The new folder is created as a child of the selected node.
images/image674.png
Edit the name of the selected folder. This string appears in the Folder ID field.
images/image114.png
Delete the selected folder. Before you can delete a folder, you must remove all its segment assignments and child nodes.
images/image115.png
Move the selected folder and its child nodes to another location in the tree. The selected folder is moved under the new parent node that you specify.
images/image675.png
Assign segments to the folder. The network segments you specify here appear in the Assigned Segments field. To support these segments, endpoints are allocated to free Appliances (which do not have statically assigned segments).
images/image676.png
Reassign segments to this folder from Appliances in child folders. All segments statically assigned to Appliances in sub-folders of the selected folder are assigned to the selected folder.
Reassigned segments now participate in load sharing.
Segments assigned to sub-folders are not reassigned
This action skips sub-trees with a folder-level segment assignment.
images/image677.png
Configure the selected folder as a failover cluster. This folder should have only folder-level segment assignments. You cannot include an Appliance with static segments assignments in a failover cluster.
This is an optional, licensed feature. For details on licensing and failover cluster configuration, refer to the Forescout eyeSight Resiliency and Recovery Solutions User Guide.

The main pane lists the following information for each Appliance in the selected folder:

Status
An icon indicating the operating state of the Appliance, and its connection to Enterprise Manager.
Appliance
The name or other identifying label of the Appliance
Folder Location
The full path to the folder that includes this Appliance. This is the full path of the selected node in the Appliance Folders tree.
Assigned Segments
Segments defined in your internal network that are assigned to the Appliance. Segments listed in italic font are assigned to the parent folder; segments listed in plain font are statically assigned to the Appliance itself.
IP Addresses
IP address ranges associated with the segments assigned to the Appliance. If some segments are statically assigned to Appliances in the folder, this column indicates the remaining unassigned IP addresses.

The following tools are available in this pane:

Assigned Appliances
Use this search field to refine the table:
Enter an Appliance name to locate its folder.
Enter an IP address to locate the Appliance or folder that handles that network segment. Enter an Appliance folder to locate it in the tree.
Show child folder information
When this option is selected, the main table displays Appliances in sub-folders of the selected folder.
Assign
Assign segments to the Appliance you selected in the table.
Move
Move selected Appliances to another folder of the Appliance tree.

Static and automatic IP allocation

You can assign IP addresses to Appliances in two ways:

  • Automatic IP Allocation: Assign segments to a folder. If the folder contains several Appliances, IPs in these segments are automatically assigned to available Appliances in the folder. Endpoint sessions are distributed proportionally based on each Appliance's licensed capacity.
  • Static Allocation: Assign segments to a single Appliance. This Appliance handles endpoints in these segments. If this Appliance is part of a folder, it does not participate in automatic IP allocation.
    Note: IP addresses not assigned to a folder or Appliance are handled by the Enterprise Manager. The Enterprise Manager also handles IP addresses that are assigned to a folder that has no Appliances available.

Overlapping IP assignments

The Forescout eyeSight verifies that each network IP address is assigned to only one Appliance. This ensures, for example, accurate endpoint monitoring and policy execution.

If you mistakenly assign an IP address to more than one Appliance, the Console displays a table that lists the ranges and segments to which the overlapping IP address was defined, as well as the exact IP address ranges that overlap. Review this information and update IP assignments in the IP Assignment dialog box so that each IP address is only assigned to one Appliance. You can export the information in the table to a CSV file.

Networks can be intentionally configured with overlapping IP addresses, as in retail branches, Operational Technology environments, or merged corporate networks. You can enable support for these networks in the Internal Network. For more information refer to the Working with Overlapping IP Addresses How-to Guide.

images/image678.png

Note: Although there is no limit to the total number of entries displayed in the Overlapping IP Assignments dialog box, a maximum of 10 overlapping ranges are displayed at any one time. To see any additional overlapping ranges that might exist, first resolve the overlap conflicts displayed in the table. Once resolved, additional ranges are displayed.
Note: If you change the definition of Internal Network segments, this can change which IP addresses are assigned to folders or Appliances.

Conflicting configurations

When you configure Forescout modules and other components, you can define groups of Appliances that have the same configuration settings, as described in Configure Features for an Appliance or Group of Appliances.

In some cases, these configuration settings may conflict with the Appliance groupings you define in the Appliance Folders tree. For example, endpoint connection settings of the Endpoint Module may conflict with endpoint-handling settings of the Appliance Folders tree. A pop-up message notifies you of any conflicts when you save your Appliance Folders configuration. Review the two configurations applied to the Appliance to identify and resolve the conflict.