Control Use of Root User Log-In to Devices

Enhance the security of your deployment by controlling the user's ability to perform a root user log-in, via SSH, to eyeSight devices (Enterprise Manager and Appliances), whether physical devices or virtual devices.

  • A new installation of eyeSight (version 8.2.2 or above) has, by default, the root user log in capability prohibited (disabled).
  • An upgrade of eyeSight (from version 8.2.1 or below to version 8.2.2 or above) keeps the existing control of the root user log in capability. In other words, if before the upgrade, this capability was allowed (enabled) in the /etc/ssh/sshd_config file of the SSH server, then after the upgrade this capability remains allowed (enabled). However, if before the upgrade, this capability was prohibited (disabled) in the /etc/ssh/sshd_config file of the SSH server, then after the upgrade this capability remains prohibited (disabled).

Forescout recommends prohibiting (disabling) use of the root user log in capability on your Forescout devices.

To control the use of "root" user to log in, via SSH, to a Forescout device:

Note: Do this for each Forescout device:
  1. Log in to the CLI of the eyeSight device, using cliadmin user credentials.
  2. To prohibit the use of root log in, enter the following parameter setting: ssh_root_password_login disable
  3. To allow the use of root log in, enter the following parameter setting: ssh_root_password_login enable
  4. Provide two password authentication, as follows:
    1. When prompted, enter the cliadmin password.
    2. When prompted, enter the shell password.