Before You Upgrade Forescout eyeSight
This topic contains important information and recommendations to consider before upgrading eyeSight.
Upgrade Verifier Guidance
For the most up-to-date upgrade guidance and validation steps, refer to the Upgrade Verifier Plugin and Pre-Upgrade Verifier sections below to assess your system readiness before upgrading.
Upgrade Paths to the Latest eyeSight Version
The Upgrade Matrix below shows the possible upgrade paths from a given Initial eyeSight version to a given Destination eyeSight version.
- If a direct upgrade path exists, the matrix displays a
tick mark in the intersecting cell. - If no direct upgrade exists, the matrix displays an
in the intersecting cell. - If a single-step upgrade is not supported between two points, it is necessary to upgrade in more than one step.
| 8.4 | 8.4.1 | 8.4.2 | 8.4.3 | 8.4.4 | 8.5.1 | 8.5.2 | 8.5.3 | 8.5.4 | 8.5.5 | 9.1.2 | 9.1.3 | 9.1.4 | 9.1.5 | 9.1.6 | 9.1.7 | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 8.4 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 8.4.1 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 8.4.2 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 8.4.3 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 8.4.4 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 8.5.1 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 8.5.2 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 8.5.3 |
|
|
|
|
|
|
|
|
|
|
|
* |
|
|
|
|
| 8.5.4 |
|
|
|
|
|
|
|
|
|
|
|
* |
|
|
|
|
| 8.5.5 |
|
|
|
|
|
|
|
|
|
|
|
* |
|
|
|
|
| 9.1.2 |
|
|
|
|
|
|
|
|
|
|
|
|
|
- |
|
|
| 9.1.3 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 9.1.4 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 9.1.5 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 9.1.6 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
*It is advised to upgrade to eyeSight v9.1.4 (or higher) instead of eyeSight v9.1.3. Please review the eyeSight v9.1.4 Release Notes for more information about resolved issues.
- OS Upgrade File: Upgrade from v8.x to v9.1.6+ with OS and full bundled module/plugin updates.
- Core OS Upgrade File: Upgrade from v8.x to v9.1.6+ with OS updates and core plugins only (Packet Engine and DPI).
- Upgrade File: Upgrade from v9.x to a later v9.x release with full bundled module/plugin updates.
- Core Upgrade File: Upgrade from v9.x to a later v9.x release with core plugins only (Packet Engine and DPI).
Upgrade Path Examples
- Upgrade directly from 8.3 to 8.5.1
- Upgrade directly from 8.4.3 to 8.5.1
- Upgrade directly from 8.5.2 to 9.1.2
- Upgrade directly from 9.1.2 to 9.1.x
Downgrades are only supported via re-imaging the Appliance. You can also upgrade an Appliance by re-imaging it.
Refer to the eyeSight Installation Guide for a description of the re-imaging process.
Upgrade Verifier Plugin
In addition to the inline Pre-Upgrade Verifier, Forescout also offers a separate Upgrade Verifier Plugin. You can use the plugin to determine upgrade readiness before you begin your upgrade.
The Upgrade Verifier plugin offers the same verification checks as the Pre-Upgrade Verifier, plus additional checks to provide a more comprehensive verification of upgrade readiness. However, unlike the inline Pre-Upgrade Verifier process, the Upgrade Verifier plugin offers on-demand readiness verification. Refer to the Upgrade Verifier Plugin guide for more information.
Pre-Upgrade Verifier
When you attempt to perform an upgrade on the Enterprise Manager, the Pre-Upgrade Verifier runs and performs the following functions to verify the readiness of your Enterprise Manager and all its attached Appliances for upgrade:
- Checks total and free memory
- Checks a full set of Appliance characteristics, per Appliance in the system, and displays the results
- Checks database status and size
- Checks High Availability status
- Displays detailed verification results in the Console window
- Provides a link to download the verification results
While running, the Pre-Upgrade Verifier displays progress, success, and failure screens in the window. When the pre-upgrade verification process completes, a pre-upgrade verification report is generated.
The ForescoutConsole8.x.x\GuiManager\current\upgradeverifier folder contains the following pre-upgrade verification files:
- upgrade_verifier_report.txt - pre-upgrade verification report
- upgrade_verifier_version.properties - pre-upgrade verification properties
If you attempt to install a second time from the same upgrade version package (with the same software version), the pre-upgrade verification report in the upgradeverifier folder appears as PreUpgradeVerifierLastReport.txt. You can download this file before clicking the Verify button in the Console window.
Once you click the Verify button, the pre-upgrade verification report is deleted from the upgradeverifier folder, and a new report is generated. The report appears as PreUpgradeVerifierCurrentReport.txt. You can download this file from the Console window when the current pre-upgrade verification process is completed.
See the section on Upgrade the Enterprise Manager for full details about the upgrade process.
The following table shows several pre-upgrade verification results' use-cases, and what to do in each case:
| Pre-Upgrade Verification Notifications and Warnings | Consequence | What to do |
|---|---|---|
| Successfully completed with errors only | Upgrade is blocked | Review the report, and fix the issue(s) before upgrading. |
| Unsuccessful due to internal error from one or more Appliances or Enterprise Manager | Upgrade is blocked | Review the report, and fix the issue(s) before upgrading. |
| Unsuccessful due to internal error from one or more Appliances or Enterprise Manager | Upgrade is blocked | Review the results / logs, and contact Customer Support. |
| Timeout from one or more Appliances or Enterprise Manager | Upgrade can proceed only with user confirmation | Review the results / logs and contact Customer Support, or skip pre-upgrade verification by adding Console or Appliance properties. |
Important Considerations before Upgrade
You should check hardware and software compatibility before upgrading:
- Validate that your current physical hardware or virtual appliance supports upgrade to the latest version. Refer to the matrix in the Hardware and Software Interoperability Matrix.
Limited Appliance mode has been discontinued and is not part of version 9.1.2 and higher.
- For Virtual system requirements, refer to the Forescout Sizing Guide.
- eyeSight v9.1.2 and higher do not support CT appliances. Both the Upgrade Verifier v1.0.4 and the Pre-Upgrade Verifier have checks included for CT appliances.
- An unsupported plugin version should be upgraded to a supported version (if available) or uninstalled before upgrading to the latest version.
- Known / Fixed Upgrade Issues: Review the eyeSight Release Notes for this version.
- Identify and uninstall modules that are not supported in the latest version.
- If you are considering using the CLI upgrade method, Forescout recommends running the Upgrade Verifier plugin first as the CLI method does not automatically run the Pre-Upgrade Verifier.
- The Installer program automatically identifies an earlier version on your system. Upgrade options allow you to either maintain the configuration parameters from the previous version or define new parameters.
- If your current deployment is operating in PAL Mode, and you need to simultaneously upgrade and switch to Flexx Licensing Mode, obtain licenses to convert to Flexx. The administrative process for issuing the licenses that enable Conversion to Flexx licensing mode can take 2-3 weeks. During this period, you can continue to use PAL Mode.
- If you performed a rollback prior to the upgrade, wait for a minimum of 30 minutes after High Availability Appliances have synchronized before starting the upgrade.
- For High Availability devices, back up the pair before you upgrade. The pair must be functioning when you upgrade.
- If only empty segments are assigned to a fail over cluster, you must remove them from all fail over cluster folder assignments before you remove any of the segments. Refer to Working with Appliance Folders in the eyeSight Administration Guide for more information.
- Upgraded versions of might include legacy Asset Classification policies that provide limited information about endpoints. To take advantage of more precise classification profiles, it is recommended to create and run Primary Classification policies.
To use the Primary Classification policy, you must import the Discovery policy and disable the actions on the legacy Asset Classification policy.
Ensure that the Add to Group actions are enabled in the Primary Classification policy and use the Policy Manager to stop your Asset Classification policies. - The Netflow Plugin is no longer available. Forescout recommends using the Flow Collector Plugin. The Flow Collector provides accurate and stable traffic flow detection and scalable bandwidth capabilities.
If you previously used the NetfFlow plugin:
- First, configure and enable the Flow Collector Plugin.
- Next, stop and uninstall the Netflow Plugin.
- Control Actions: disable any enabled control actions prior to upgrade. This is to ensure no actions are applied after the upgrade.
Certificate and TLS validation
eyeSight 9.1.x uses OpenSSL 3 and applies stricter TLS and certificate validation requirements than earlier releases.
As a result, devices that authenticated or communicated successfully in previous releases might experience authentication or connectivity issues after upgrading if they use TLS versions or certificates that do not meet current security requirements.
Environments more likely to be affected
Review your environment carefully if it includes:
- Certificate-based authentication deployments, such as EAP-TLS
- Legacy IoT or OT devices
- Medical devices
- Phones, printers, badge readers, or other embedded devices
- Older infrastructure or long-lived certificates
Potential upgrade impact
After upgrading, devices might fail authentication or communication because eyeSight 9.1.x applies additional TLS and certificate validation checks.
Additional validation associated with OpenSSL 3
- SHA-1 and other weak or deprecated signature algorithms
- RSA keys smaller than 2048 bits
- TLS versions earlier than 1.2
- Stricter validation of certificate purposes and Extended Key Usage (EKU)
- Stricter certificate chain and trust validation
Certificate requirements that continue to apply
The following requirements are not new but remain necessary for successful authentication and communication:
- Valid (non-expired) certificates
- A complete, trusted certificate chain
Before you upgrade
Forescout recommends that you:
- Inventory endpoints that use certificate-based authentication.
- Validate certificate health and certificate chains.
- Verify certificate usage settings.
- Confirm that endpoints support TLS 1.2 or TLS 1.3.
- Test representative devices before upgrading production systems.
Authentication or connectivity issues identified after upgrading might indicate existing certificate or TLS configuration issues that were previously accepted, rather than issues introduced by eyeSight.
Upgrade preparation
Run the Upgrade Verifier plugin: Before upgrading your appliance, assess your readiness using the Upgrade Verifier plugin.
- You can find it in the Customer Portal's Downloads section.
- It's separate from the upgrade process, so you don't need to distribute upgrade files.
- You can run it multiple times before the upgrade window.
Pre-Upgrade verification
- Verification process: The Pre-Upgrade Verifier checks your environment and software requirements when you start an upgrade using the console.
- After the check, a summary screen will display key information.
Summary screen information
- Dependencies:
- Lists compatible versions of plugins and eyeExtend products.
- May prompt you to upgrade or uninstall incompatible items.
- Forescout Version Notification:
- Alerts you if the target version does not include the currently installed plugin and hotfix versions.
- Provides an itemized list of potentially impacted versions.
- End-of-Life and Unsupported Modules/Plugins: Uninstall these items before continuing with the Upgrade.
- System Information:
- Shows total memory and appliance model.
- Refer to the Forescout Sizing Guide for complete specifications.
End-of-Life Products
Products that have reached End-of-Life (EOL) must be uninstalled from before upgrading the software.
For complete End-of-Life information, refer to the Forescout End-of-Life document.
Perform a Complete Backup of your System
Perform a complete backup of your Enterprise Manager and /or Appliances before starting an upgrade.
If there is a problem after the upgrade, you can restore your devices to the previous version from the backup. For virtual machines, snapshots can be created.
See the Back Up your Enterprise Manager and / or Appliances section.
To Back up your configuration and Policy Set:
- Verify that iDRACs are set up and are available for hardware Appliances with no physical access (physical Appliances only). Refer to Remote System Management Integration in the Installation Guide.
- Save Virtual Machine snapshots, if applicable (Virtual Appliances only).
- Perform a complete backup of the Enterprise Manager and / or Appliances.
- Export your Segments, Ignored IP Lists, switches, wireless, Threat Protection Legitimate Scanners, policies, groups, and all the configurations needed in case of a recovery. Refer to the relevant topics on exporting in the eyeSight Administration Guide.
- Save all the usernames and passwords for all the available accounts. The HPS Inspection Engine plugin and the User Directory plugin must be manually copied.
minute read