Cloud Data Exchange Plugin v1.1.1 Release Notes
These release notes offer details on updates and important information related to the Cloud Data Exchange plugin v1.1.1 release. This release works with eyeSight v8.4.x, v8.5.x, and v9.1.x.
New Feature and Enhancement
This release includes the following new feature and enhancements:
- You can now poll Forescout Cloud for asset information from all eyeSight devices by disabling the “Use Focal” setting under the Advanced General tab.
- You can now use the asset polling task running on two different intervals (regular and fast) to resolve the new Cloud Data Exchange Device Tunnel Status property on a faster interval for expedited resolve turnaround time for this property.
- You can now have the Cloud Data Exchange plugin admit MAC-only hosts to eyeSight that it has heard about through polling Forescout Cloud for asset information.
- You can now only use the Cloud Data Exchange plugin to interact with the Cloud if the eyeSight license is valid.
- The Cloud URL now defaults to the US Forescout Azure Cloud deployment: https://eaus.app.cloud.forescout.com/api/data-exchange/v3/. For more listings of the different regions, please see URL Endpoints.
Important Consideration - Netskope
Netskope will provide assets to the Forescout Cloud, using MAC addresses as identifier. eyeFocus will apply its identification logic in order to merge the right addresses to a host, and enrich it with additional information, including IP address, where applicable.
eyeFocuswill also sync these hosts to eyeSight; this is a bi-directional process.
After upgrading to v1.1.1, if eyeSight already knows a host for one of the MACs present in the list provided by eyeFocus (and indirectly by Netskope), CDE will resolve the Netskope properties against the host that contains that MAC address. CDE will prioritize hosts that it also has an IP address for, as this indicates the host has an IP address from another plugin in eyeSight, and that is the desired host to resolve properties against.
Due to synchronization intervals, it is possible that eyeSight learns about a host beforeeyeFocus does, in which case CDE will admit the MAC-only host, if configured to using the “Allow eyeFocus MAC Only Admissions” checkbox in the Advanced Assets configuration page.
Since eyeSight has the known limitation of keeping one MAC address per host, in case where a host has multiple MAC addresses, CDE has a caching logic to briefly keep multiple MAC addresses in an attempt to learn more about a host. In this scenario, eyeSight will still show one MAC address for that host, but all properties linked to the associated MAC addresses will have been resolved on that host.
In the event that CDE admits a MAC-only host, and later on eyeSight becomes aware of a host that has an IP and a different MAC address that appears in the MAC address list for the Netskope host in cloud, CDE will begin resolving against that host instead and the original MAC-only host that CDE admitted will be purged.
Supported Version
To view a complete list of compatible eyeSight versions, visit the Supported Versions section. It includes the minimum supported eyeSight versions that work with each plugin version covered by this guide.
minute read