About the Forescout eyeSight Forescout eyeSight v8.5.5 Release
These release notes offer brief, high-level descriptions of enhancements, new features, and fixed and known issues for the Forescout eyeSight Forescout eyeSight version 8.5.5 and its base module components. This document also includes links to important information to assist you with your upgrade planning and deployment.
What's New
- Google deployment guidance updated to reflect transition from Google Deployment Manager to alternatives.
- Maintenance rollup with additional fixed and known issues updates in the 8.5.x line.
Enhancement
This release includes the following enhancement:
- Google is phasing out Deployment Manager on March 31, 2026. If you're currently using Google Deployment Manager, you'll need to move to Google Infrastructure Manager (or another alternative) to ensure your services stay online. To help make the switch easy, you can find the new instructions for deploying the Forescout appliance here.
Fixed Issues
This release includes the following fixed issues.
| Issue # | Description |
|---|---|
| EYST-34570, EYST-35817, EYST-35834 | When an endpoint-managing appliance and the appliance issuing a control action were different appliances, the actions triggered in policy may have been cancelled, even though the eyeSight console showed the action as Successful. This has been fixed in build 8.5.4-47. Important: Forescout recommends that all customers running eyeSight eyeSight v8.5.3 upgrade to v8.5.4 or later. Before you upgrade from v8.5.3, you should stop actions at all policy levels. Once the upgrade is complete, restart the actions. |
| SST-1493, SST-1494 | Lack of Transfer Layer Security (TLS) hostname verification in the SocketAppender component creates a security vulnerability to improper validation of certificate with host mismatch in org.apache.logging.log4j:log4j-core. This has been fixed. |
Known Issues
This release includes the following known issues.
| Issue # | Description |
|---|---|
| DOT-5819 | For endpoints not managed by the authenticating appliance, a Change of Authorization (CoA) request sends a disconnect notice to the authenticating appliance. As a result, the CoA action fails. Workaround: To prevent failed CoA requests, we recommend rolling back to RADIUS plugin v4.8.3 or upgrading to v4.8.5. |
Solution Bundle Orders
Forescout Solution Bundles are composed of a packaged combination of entitlements for Forescout Software, Cloud Services, Integrations, and Premium Support Services designed to deliver comprehensive capabilities for defined use cases.
In the event that a customer has placed an order that includes an Entitlement Credit applied towards a Replacement Entitlement, the customer will continue to have access to their Current Entitlement for thirty (30) days from the date Forescout accepts the applicable order to facilitate the customer’s transition from the Current Entitlement to the Replacement Entitlement.
Module and Plugin Updates
Details for base and content modules included in v8.5.5.
| Module Name | Version |
|---|---|
| Authentication | 1.4.12 |
| Cloud Data | 1.0.9 |
| Core Extensions | 2.0.5 |
| Device Profile Library | 25.7.1 |
| DPI | 1.0.8 |
| Endpoint | 1.4.15 |
| Hybrid Cloud | 2.3.8 |
| IoT Posture Assessment Library | 19.0.12 |
| Network | 1.4.12 |
| NIC Vendor DB | 25.9.4 |
| Packet Engine | 8.4.4 |
| Visibility Content Plugin | 25.9.4 |
| Windows Applications | 24.0.10 |
| Windows Vulnerability DB | 25.9.4 |
Module Details
Authentication (Base) Module v1.4.12
| Plugin Name | Version |
|---|---|
| RADIUS | 4.8.4 |
| User Directory | 6.7.9 |
Core Extensions (Base) Module v2.0.5
| Plugin Name | Version |
|---|---|
| Active Probing Plugin | 2.0.5 |
| Admin API | 1.0.3 |
| Advanced Tools | 2.6.5 |
| CEF | 3.0.3 |
| Cloud Classification Gateway | 1.0.3 |
| Dashboards | 1.4.7 |
| Data Publisher | 1.2.4 |
| Data Receiver | 1.2.4 |
| Device Classification Engine | 1.6.6 |
| DHCP Classifier | 2.4.6 |
| DNS Client | 3.3.4 |
| DNS Enforce | 1.5.3 |
| DNS Query Extension | 1.5.2 |
| External Classifier | 2.4.0 |
| Flow Analyzer | 1.5.0 |
| Flow Collector | 1.3.2 |
| IOC Scanner | 2.5.1 |
| IoT Posture Assessment Engine | 1.2.0 |
| Reports | 5.4.8 |
| Syslog | 3.8.4 |
| Technical Support | 1.5.8 |
| Web Client | 1.4.2 |
Endpoint (Base) Module v1.4.15
| Plugin Name | Version |
|---|---|
| Hardware Inventory | 1.3.2 |
| HPS Agent Manager | 1.4.8 |
| HPS Inspection Engine | 11.3.17 |
| Linux | 1.7.12 |
| Microsoft SCCM/ECM | 2.6.8 |
| NBT Scanner | 3.3.1 |
| OS X | 2.5.11 |
Extended Modules & Hybrid Cloud
| Plugin Name | Version |
|---|---|
| Connect | 2.1.5 |
| Connect Add-On | 1.0.0 |
| AWS | 2.3.7 |
| Azure | 1.2.6 |
| VMware NSX | 1.4.1 |
| VMware vSphere | 2.7.5 |
Frequently Asked Questions
Common questions about the v8.5.5 release.
Why Move to RHEL?
CentOS v7 reached End of Life on June 30, 2024. Forescout participates in Red Hat's Extended Life-cycle Support for RHEL v7.9, which extends support through 2028.
Is this upgrade more extensive than usual?
No. Since CentOS v7.9 and RHEL v7.9 share the same codebase, the upgrade follows the standard FSP file process and is straightforward.
When should I upgrade?
Upgrade timing depends on your hardware and policy needs; plan for v8.5.x or v9.1.x depending on appliance compatibility and IPv6/feature requirements.
minute read