eyeSight System Requirements

Before you begin installation, verify that the following requirements are met and that you have completed a Site Preparation Form, see Site Preparation Form.

Requirements may vary for virtual systems. See Virtual System Requirements for details.

eyeSight Licensing Mode

This version of eyeSight supports two different licensing modes. Each Forescout deployment operates in a single mode, however, you may have multiple deployments that use different licensing modes. License requirements differ according to licensing mode.

To identify your licensing mode:

From the Console, select Help > About Forescout CounterACT....

Supported Physical eyeSight Devices

For information about physical hardware models and their supported eyeSight versions (up to this version), refer to the Hardware and Software Interoperability Matrix Guide.

To determine the revision of a specific Enterprise Manager, do one of the following:

  • Run the fstool model command on the Enterprise Manager.
  • See the product label on the machine.

To determine the revision of a specific Appliance, do one of the following:

  • Run the fstool model command on the Appliance.
  • Run the fstool tech-support oneachmodel command on the Enterprise Manager.
  • See the product label on the machine.

Contact your Forescout sales representative for alternative solutions if any of your Appliances are on this list of revisions not supported.

eyeSight Hardware Requirements

You must supply a machine to host the application software. Minimum hardware requirements are:

  • Non-dedicated machine, running:
    • Windows 10 / 11
    • Windows Server 2008 / 2008 R2 / 2012 / 2012 R2 / 2016 / 2019
    • Linux RHEL/CentOS 7.9 / 8
    • macOS 13 / 14 /15
  • 2GB RAM
  • 1GB disk space

eyeSight Network Access Requirements

Deploying eyeSight requires TCP/IP communication. This section details eyeSight connectivity requirements. Check your security policy (Router ACLs, etc.), and modify it, if required, to allow for this communication.

Each Appliance requires a single management connection to the network. This connection requires an IP address on the local LAN and port 13000/TCP access from machines that run the Console. The connectivity listed in the following table is required.

Port

Service

To or From eyeSight

Function

22/TCP

SSH

From

Allows remote inspection of OS X and Linux endpoints.

Allows eyeSight to communicate with network switches and routers.

   

To

Allows access to the eyeSight command line interface.

2222/TCP

SSH

To

(High Availability) Allows access to the physical Appliances that are part of the High Availability pair.

Use 22/TCP to access the shared (virtual) IP address of the pair.

25/TCP

SMTP

From

Allows eyeSight access to the enterprise mail relay.

53/UDP

DNS

From

Allows eyeSight to resolve internal IP addresses.

80/TCP

HTTP

To

Allows HTTP redirection.

123/UDP

NTP

From

Allows eyeSight access to a local time server or ntp.forescout.net.

By default eyeSight accesses ntp.foreScout.net.

135/TCP

MS-WMI

From

Allows remote inspection of Windows endpoints.

139/TCP

SMB, MS-RPC

From

Allows remote inspection of Windows endpoints (For endpoints running Windows 7 and earlier).

445/TCP

   

Allows remote inspection of Windows endpoints.

161/UDP

SNMP

From

Allows eyeSight to communicate with network switches and routers.

For information about configuring SNMP, refer to the eyeSight Administration Guide.

162/UDP

SNMP

To

Allows eyeSight to receive SNMP traps from network switches and routers.

For information about configuring SNMP, refer to the eyeSight Administration Guide.

389/TCP

(636)

LDAP

From

Allows eyeSight to communicate with Active Directory.

Allows communication with Forescout web-based portals.

443/TCP

HTTPS

To

Allows HTTP redirection over TLS.

10006/TCP

SecureConnector for Linux

To

Allows SecureConnector to create a secure (encrypted TLS) connection to the Appliance from Linux machines. SecureConnector is a script-based agent that enables management of Linux endpoints while they are connected to the network.

10003/TCP

SecureConnector for Windows

To

Allows SecureConnector to create a secure (encrypted TLS) connection to the Appliance from Windows machines. SecureConnector is an agent that enables management of Windows endpoints while they are connected to the network. Refer to the eyeSight Administration Guide for more information about SecureConnector.

When SecureConnector connects to an Appliance or to the Enterprise Manager, it is redirected to the Appliance to which its host is assigned. Ensure this port is open to all Appliances and to the Enterprise Manager to allow transparent mobility within the organization.

10005/TCP

SecureConnector for OS X

To

Allows SecureConnector to create a secure (encrypted TLS) connection to the Appliance from OS X machines. SecureConnector is an agent that enables management of OS X endpoints while they are connected to the network. Refer to the eyeSight Administration Guide for more information about SecureConnector.

When SecureConnector connects to an Appliance or to the Enterprise Manager, it is redirected to the Appliance to which its host is assigned. Ensure this port is open to all Appliances and to the Enterprise Manager to allow transparent mobility within the organization.

13000/TCP

eyeSight

From/To

For deployments with only one Appliance – from the Console to the Appliance.

For deployments with more than one Appliance – from the Console to the Appliance and from one Appliance to another. Appliance communication includes communication with the Enterprise Manager and the Recovery Enterprise Manager, over TLS.

Network Deployment Requirements

Each Appliance must be set up at a location in which it sees vital network traffic and can protect devices connected to your switch.

The supports deployment options for:

  • Monitoring multiple VLANs (tagged traffic) – recommended, as it provides the best overall coverage while monitoring only a single port
  • Monitoring a tagged port (802.1Q tagged)
  • Monitoring a single VLAN (untagged)
  • Monitoring a single port (untagged)

Important notes:

  • Carefully consider the traffic to monitor.
  • It is recommended to monitor the authentication traffic between end users and authentication servers.
  • To notify end users via their web browsers, you must monitor HTTP traffic between end users and the Internet/Intranet.

Appliance Information Requirements

 

The following information regarding each Forescout Appliance is required:

  • Appliance cliadmin password
  • Appliance IP address
  • Appliance host name
  • DNS domain name
  • Management interface through which Appliance and Console communicate
  • Network mask
  • Default gateway IP address
  • List of the company’s DNS server addresses (to allow resolution of internal IP addresses to their DNS names)

Enterprise Manager Information Requirements

 

The following Enterprise Manager information is required:

  • Forescout Enterprise Manager IP address
  • Forescout Enterprise Manager host name
  • Enterprise Manager Administrator password
  • Management interface
  • Network mask
  • Default gateway
  • DNS domain name
  • DNS server addresses

Network Connection Requirements

 

Network connections must allow full visibility to all response and monitor traffic.

Virtual systems have additional requirements. See Network Connection Requirements for Forescout Virtual Devices for details.

Bandwidth Requirements

 

Refer to the

 

Sizing Guide for information on bandwidth requirements.