Naming Forescout Object Groups

Create network object group names for use by Forescout eyeSight based on the naming convention composed of the following, two string variables:

<Network_Group_Name><Netgroup_suffix>

Variable Description

Network Group Name

A value you specified when you configured the firewall in the module. The default value for this string is FS_GROUP_.

Netgroup suffix

A numerical value that is defined for the Cisco PIX/ASA Access-list action being used in a Forescout policy. See Cisco PIX/ASA Access-list Action. This means that each policy can use its own object group. At the firewall, you can apply different access list restrictions to each object group.

Using this naming convention, you can create a series of object group names. For example, combine the default Network Group Name string FS_GROUP_ together with different Netgroup suffix values to yield the following series of object groups:

FS_GROUP_0­   FS_GROUP_1   FS_GROUP_2   …

For example, you can configure the firewall to block internal network access for all members of FS_GROUP_0, and to block access to the finance server for all members of FS_GROUP_1. Different policies add hosts to each group.