About Forescout eyeSight Resiliency and Recovery Solutions

Forescout resiliency and recovery solutions provide support for availability of eyeSight services to minimize down-time in cases of system failure.

Resiliency solutions for Forescout eyeSight appliances

The following resiliency solutions are available for eyeSight Appliances:

  • Failover Clustering
    • Implemented with clusters of Appliances.
    • Redundancy is achieved by defining clusters of Appliances that can automatically take over discovery, assessment, and control in case of single or multiple Appliance failure within the cluster(s).
    • Workload is balanced among the Appliances in the cluster/s after failover.
  • High Availability Pairing
    • Implemented in pairs of two Appliances.
    • Redundancy is achieved by assigning an Active node and a Standby node. The Standby node automatically takes over discovery, assessment, and control in case the Active node fails.
    • The two nodes are synchronized by a redundant pair of directly interconnecting cables.

      For a comparison of the above solutions, and to learn more about which solution is appropriate for your deployment, see Comparison of Resiliency Solutions for Appliances.

Solutions for the Forescout eyeSight Enterprise Manager

The following resiliency and recovery solutions are available for the Forescout eyeSight Enterprise Manager:

  • High Availability Pairing
    • Implemented in pairs of two Enterprise Managers.
    • Redundancy is achieved by assigning an Active node and a Standby node. The Standby node automatically takes over discovery, assessment, and control in case the Active node fails.
    • The two nodes are synchronized by a redundant pair of directly interconnecting cables.
  • Disaster Recovery for Enterprise Manager
    • Implemented in pairs of two Enterprise Managers.
    • Redundancy is achieved by defining a Recovery Enterprise Manager that is manually triggered to take over from an Enterprise Manager that is no longer functioning as a result of, for example, a disaster.
    • The Enterprise Manager and the Recovery Enterprise Manager are synchronized by communication performed on port 13000/TCP.
      Note: The Failover Clustering solution does not support Enterprise Manager failure scenarios.

      See the Glossary for descriptions of terms related to Forescout resiliency and recovery solutions.

Forescout eyeSight Requirements

Verify that the following licensing, software and network requirements are met and that Forescout Console users have the necessary permissions:

Supported eyeSight and Base Module Versions

The following table lists the eyeSight version and the Base Module versions that Failover Clustering operation requires:

Version Network Discovery Module Version Endpoint Module Version
9.1.5 1.4.12 1.4.14
9.1.4 1.4.10 1.4.13
9.1.3 1.4.10 1.4.13
9.1.2 1.4.9 1.4.12
8.5.4 1.4.12 1.4.15
8.5.3 1.4.11 1.4.14
8.5.2 1.4.8 1.4.11
8.5.1 1.4.7 1.4.10
8.4.4 1.4.6 1.4.9
8.4.3 1.4.3 1.4.7
8.4.2 1.4.2 1.4.3

8.4.1

1.4.1

1.4.1

The following Network Discovery Module components must be running:

  • Switch Plugin
  • Wireless Plugin

If you are working with Windows, Linux, or macOS/OS X endpoints, the following Endpoint Module components must be running:

  • HPS Inspection Engine
  • Linux Plugin
  • OS X Plugin

All Appliances participating in failover must have uniform configuration settings applied. Plugins or features cannot be configured individually per Appliance. See Choosing the Right Solution for Your Deployment for more information.

Forescout eyeSight Network Deployment Requirements

  • A network infrastructure that enables rerouting or load balancing traffic (e.g. SPAN, SNMP traps from network devices) so that potential recipient Appliances can see and handle endpoints and network devices, in case of an Appliance or site failure.
  • This feature can be enabled on Appliances that are connected to the same Enterprise Manager, but not on the following Forescout devices:
    • A single, standalone Appliance that is not connected to an Enterprise Manager
    • An Enterprise Manager
  • Appliances that can potentially manage network devices as a result of a failover must have network access to those switches.
  • Make sure that all Active Directory services can be accessed by all Appliances in the failover cluster:
    • If the DNS Detection checkbox is selected for Appliances in the failover cluster, this happens automatically.

      This checkbox is configured when defining User Directory servers in the User Directory Plugin.

    • Otherwise, make sure that this is configured manually by adding the relevant server IP addresses in the User Directory Plugin.

      Refer to Configure Server Settings in the User Directory Plugin Configuration Guide for more information.