Control Use of Root User Log-In to Devices
Enhance the security of your deployment by controlling the user's ability to perform a root user log-in, via SSH, to eyeSight devices (Enterprise Manager and Appliances), whether physical devices or virtual devices.
- A new installation of eyeSight (version 8.2.2 or above) has, by default, the root user log in capability prohibited (disabled).
- An upgrade of eyeSight (from version 8.2.1 or below to version 8.2.2 or above) keeps the existing control of the root user log in capability. In other words, if before the upgrade, this capability was allowed (enabled) in the
/etc/ssh/sshd_configfile of the SSH server, then after the upgrade this capability remains allowed (enabled). However, if before the upgrade, this capability was prohibited (disabled) in the/etc/ssh/sshd_configfile of the SSH server, then after the upgrade this capability remains prohibited (disabled).
Forescout recommends prohibiting (disabling) use of the root user log in capability on your Forescout devices.
To control the use of "root" user to log in, via SSH, to a Forescout device:
Note: Do this for each Forescout device:
- Log in to the CLI of the eyeSight device, using
cliadminuser credentials. - To prohibit the use of root log in, enter the following parameter setting:
ssh_root_password_login disable - To allow the use of root log in, enter the following parameter setting:
ssh_root_password_login enable - Provide two password authentication, as follows:
- When prompted, enter the
cliadminpassword. - When prompted, enter the shell password.
- When prompted, enter the
minute read