Naming Forescout Object Groups
Create network object group names for use by Forescout eyeSight based on the naming convention composed of the following, two string variables:
<Network_Group_Name><Netgroup_suffix>
| Variable | Description |
|---|---|
|
Network Group Name |
A value you specified when you configured the firewall in the module.
The default value for this string is |
|
Netgroup suffix |
A numerical value that is defined for the Cisco PIX/ASA Access-list action being used in a Forescout policy. See Cisco PIX/ASA Access-list Action. This means that each policy can use its own object group. At the firewall, you can apply different access list restrictions to each object group. |
Using this naming convention, you can create a series of object group names.
For example, combine the default Network Group Name
string FS_GROUP_ together with different
Netgroup suffix values to yield the following
series of object groups:
FS_GROUP_0 FS_GROUP_1 FS_GROUP_2 …
For example, you can configure the firewall to block internal network access
for all members of FS_GROUP_0, and to block access to the
finance server for all members of FS_GROUP_1. Different
policies add hosts to each group.
minute read