Cloud Data Exchange settings
Configure the connection between the eyeSight and the Forescout Cloudinstance with the following settings.
Cloud Settings
| Address | Cloud Uniform Resource Locator (URL) where the data will be uploaded. Tip: The URLs will generate and
display on the configuration screen when generating an API
key. |
|
| Authorization Token | Enter the API key obtained from the Forescout Cloud instance. To obtain an API key, see Generate API Key (Forescout Cloud Administration Guide). |
In the API Key Type, select Risk Sharing API. |
Proxy Settings
If your Forescout device does not have a direct connection to the Internet, configure the Proxy Settings accordingly.
| Use Proxy | Use Proxy |
|
| Proxy Server IP/Name | Proxy Server IP/Name | |
| Proxy Server Port | Proxy Server Port |
|
| Use Proxy Credentials | Use Proxy Credentials |
|
| Proxy Username | Proxy Username | |
| Proxy Password | Proxy Password |
Advanced General Settings
| Focal Device | Manages the communication between Forescout eyeSightand Forescout Cloud. It collects the data from all eyeSight devices and sends the data to Forescout Cloud from a central (focal) point. |
|
| Health Monitoring Upload Max Size (KB) | Set the max size of the Health Monitoring upload (KB). Maximum size of upload for health monitoring data. If amount of data is larger than the max size set, the upload will be split into multiple smaller uploads. Max size set by cloud is 5 mb. |
|
| Health Monitoring Upload Interval (minutes) | Set the time interval (in minutes) in which health monitoring
data is uploaded to cloud. How often CDE uploads health monitoring data to cloud. |
|
| Use Throttling Cache for Property Updates | Enable throttling cache for property updates. Enable caching of property updates to prevent too many host property resolve messages. |
|
| Throttling Cache for Property Updates Timeout (seconds) | Time interval (in seconds) to expire properties from throttling
cache. How long property updates are kept in cache. |
|
| Plugin Configurations Upload Interval (minutes) | Interval for uploading plugin configurations to the Cloud (in
minutes). How often to upload plugin configurations to cloud. |
|
| Plugin Configurations Max Message Size (bytes) | Max number of bytes that a non-focal device can send to the focal
device in a single message during the plugin configuration
upload. This value is both the max message size between non-focal devices and the focal device, as well as the max upload size for plugin configurations. |
|
| Max Size for Message from Non-focal Device to Focal Device (bytes) | Max number of bytes that a non-focal device can send to the focal device in a single message during the run of SyncHostnamesTask. |
|
| Max Size for Message from Focal device to Non-focal Device (bytes) | Max number of bytes that a focal device can send to the non-focal device in single message about IRD assets that is has polled from Cloud. |
|
| Maximum Payload Size for DICOM Events (KB) | Specify the maximum payload size for DICOM events upload (in
KB). The maximum payload size for DICOM events upload (in kilobytes). The max set by cloud is 2 mb. |
|
| DICOM Events Upload Interval (minutes) | DICOM events upload interval (in minutes). How often to upload DICOM events to cloud. |
|
| Advanced Compliance Uploads Enabled | Enables the Advanced Compliance plugin to upload SCAP reports. If enabled, the CDE plugin will provide the Advanced Compliance plugin with the necessary information to communicate with Forescout Cloud. |
|
| Advanced Compliance Upload Interval (mintues) | If Advanced Compliance Uploads are enabled, this is the interval at which the Advanced Compliance plugin will attempt to upload reports to Forescout Cloud. |
|
| Advanced Compliance Upload Maximum Reports | If Advanced Compliance Uploads are enabled, this is maximum number of reports the Advanced Compliance plugin will attempt to upload at once to Forescout Cloud. |
|
| Advanced Compliance Upload Max Size (MB) | If Advanced Compliance Uploads are enabled, this is maximum upload size Advanced Compliance plugin will attempt to upload at once to Forescout Cloud. |
|
| Unmonitored IPs Upload Interval (minutes) | Unmonitored IPs upload interval (in minutes). How often to upload unmonitored IPs to cloud. |
|
| Sync Hostname Interval (minutes) | Set how often (in minutes) to sync hostnames and IP maps. How often to sync known host name cache. |
|
| Cloud Connectivity Interval (minutes) | Set how often (in minutes) to check cloud connectivity. How often to check if CDE is connected to cloud tenant. |
|
| HTTP Request Timeout (seconds) | HTTP request timeout (in seconds). Default connection timeout for cloud connection. |
|
Advanced Polling Settings
| Requests Polling Interval (minutes) |
Specify the time interval (in minutes) for polling the cloud instance for requests. The time interval (in minutes) for polling the cloud instance for requests for uploads. |
|
| Enable Detection Polling | Enable polling the cloud instance for
detections. Previously detection polling was disabled by setting detection polling interval to 0. This property replaces the enable/disable functionality of that property. |
|
| Detection Polling Interval (minutes) | Specify the time interval (in minutes) for polling the cloud instance for detections. |
|
| Enable Assets Polling |
Enable polling the cloud instance for asset properties. Previously asset polling was disabled by setting asset polling interval to 0. This property replaces the enable/disable functionality of that property. |
|
| Assets Polling Interval (minutes) |
Specify the time interval (in minutes) for polling the cloud instance for asset properties. |
|
| Enable Fast Asset Polling |
Enable fast polling the cloud instance for asset properties.
This only applies for |
|
| Fast Asset Polling Interval (minutes) |
Specify the time interval (in minutes) for fast polling the cloud instance for asset properties. |
|
Advanced Assets Settings
| Asset Data Upload Interval (minutes) | Specify the time interval (in minutes) to upload updated
asset data. The time interval (in minutes) to upload updated asset data. |
|
| Allow eyeFocus Admissions | Used to determine whether CDE should try and admit assets it
has polled from Cloud that do not already exist in eyeSight. Please see Important Consideration for further
details. |
|
|
Allow eyeFocus MAC Only Admissions |
Used to determine whether CDE should try and admit MAC-only assets it has polled from Cloud that do not already exist in eyeSight. |
|
| Upload New Asset Data | Enable uploading asset data that has been updated. |
|
| New Asset Upload Interval (minutes) | Specify the time interval (in minutes) for uploading new
assets to the cloud instance. The time interval (in minutes) for uploading new assets to the cloud instance. |
|
| Initial assets' properties last updated time (days) | Enter the initial value (in days) for the last time asset
properties were updated. Initialize value for assets' properties last updated time. Value will be overwritten when assets' properties are updated. |
|
| Ignore Send2Cysiv Policy Action | Ignore Send2Cysiv Policy Action. |
|
Advanced Flow Settings
| Enable Flow Uploads | Specify whether flows should be uploaded or not. Whether flows should be uploaded or not. |
|
| Maximum Payload Chunk Size for Flows Upload (KB) | Specify the maximum payload chunk size for flows upload (in
kB). The maximum payload chunk size for flows upload (in kilobytes). The max set by cloud is 2 mb. |
|
| Enable Packet Engine Flow Heuristics | Enable Packet Engine flow heuristics. |
|
| Aggregate Inbound Flows | Allow aggregating inbound flow sessions to be included in flows upload. |
|
| Aggregate Outbound Flows | Allow aggregating outbound flow sessions to be included in flows upload. |
|
| Aggregate Internal Flows | Allow aggregating internal flow sessions to be included in flows upload. |
|
| Aggregate External Flows | Allow aggregating external flow sessions to be included in flow upload. |
|
| Ignore Inbound Flows | Ignore inbound flows. |
|
| Ignore Outbound Flows | Ignore outbound flows. |
|
| Ignore TCP Non-bidirectional Flows | Ignore TCP non-bidirectional flows. |
|
| Ignore UDP Flows With High Ports from eyeSight | Ignore UDP flows with high ports from eyeSight. |
|
| Ignore UDP Flows from eyeSight Above Port | Specify the lowest port from eyeSight to be considered a high
UDP port. All flows above this port will be ignored. All UDP flows that have a source port above this value will be ignored. |
|
| Max Flows to Flush from Flow Connections Table (thousands) | Set the max amount of flows (in thousands of flows) to flush
from flow connections table. If Dynamic RAM Allocation is
enabled, this value is ignored. The max amount of flows (in thousands of flows) to flush from flow connections table. If Dynamic RAM Allocation is enabled, this value is ignored. |
|
| Flow Connections Table Flush Interval (minutes) | Specify the time interval (in minutes) to flush the flow
connections table. How often to flush the flow connections table. |
|
| Flow Upload Interval (seconds) | Specify the time interval (in seconds) to send the flow
connections table to uploader. How often to send the flow connections table to uploader. |
|
| Flow Upload Retries | Set the maximum number of times to retry uploading
flows. The maximum number of times to retry uploading flows to cloud. |
|
| Flow Upload Time Between Retries (minutes) | Specify the time (in minutes) before retrying to upload
flows. How long to wait before retrying to upload flows. |
|
| Allow Dynamic RAM Allocation for Flows | Enable Dynamic RAM allocation for flow connections table in memory. |
|
| Flow Size (bytes) | Set the size of a single flow (in bytes) in flow connections
table. The size of a single flow (in bytes) in flow connections table. When dynamic RAM allocation is enabled, this value is used, along with how many flows to upload and size of safety buffer, to calculate how much memory to allocate. |
|
| Number of Flows (MB) | Set the size of safety buffer for flow connections table (in
mB). Set the size of safety buffer for flow connections table (in kb). When dynamic RAM allocation is enabled, this value is used, along with how many flows to upload and size of safety buffer, to calculate how much memory to allocate. |
|
minute read