About the Cisco PIX/ASA Firewall Integration Module

This topic describes the Cisco PIX/ASA Firewall Integration Module.

The Forescout Cisco PIX/ASA Firewall Integration Module forwards host blocking requests to an external Cisco PIX or ASA firewall.

Blocking is implemented using access lists that reference a set of object groups. Forescout eyeSight maintains the object groups, adding and removing hosts from the group as needed.

Supported eyeSight Version

This table lists the eyeSight version that works with each plugin version covered by this guide.

Plugin Version eyeSight Version

2.2 and 2.2.1

8.1.x, 8.2, 8.2.1, 8.2.2, 8.3, 8.4, and 8.4.1

Requirements

The module requires the following:

  • A firewall user account unique to Forescout. See Configure the Cisco PIX or ASA Firewall for privileges and access requirements for this user.
  • If you are using Flexx licensing, ensure that you have a valid Forescout eyeControl (ForeScout CounterACT Control) license, to use enforcement actions provided by the component.