Configure the Cisco PIX/ASA Firewall Integration Module

To configure:

  1. Select Cisco PIX/ASA Firewall Integration and then select Configure. The Select Appliances dialog box opens.
  2. Select the required Forescout devices and then select OK.

    The Cisco PIX/ASA Firewall Integration Module Configuration window opens.

    Define the following Cisco PIX/ASA Firewall Integration fields:

    Firewall name
    The name of the PIX or ASA firewall
    Firewall Address
    The IP address of the PIX or ASA firewall
    User
    The Forescout device SSH user name
    User Password
    The Forescout device SSH user password
    Privilege Level
    The Forescout device user privilege level
    Privilege Level Password
    The password to obtain the privilege level
    Network Group Name Prefix
    A label that identifies network object groups used by Forescout eyeSight. This prefix is combined with a numerical value to specify an object group. Together, the prefix and suffix define a set of object groups. See Apply Firewall Access Lists to a Host for more information.
    SSH Port
    The port number for secure shell communication.
    SSH version
    The version of SSH used to access the PIX or ASA firewall
    Maximum group size
    The maximum size of a network object group
    Show net group members on test
    Specifies whether to list the members of the network object group when you test the module.
    Using clear local-host command
    Specifies whether to run the clear local-host command at the firewall after a host is added to or removed from a network group. This command clears all existing connections and NAT sessions associated with the endpoint on its local network segment.
  3. (Optional) Repeat the steps above to configure communication between remaining Forescout devices and additional PIX/ASA firewalls.