T Techclick ← All lessons
Forescout · eyeSight / eyeControl · Lesson 8 of 10

eyeExtend: share context, do not fight the port

Forescout sees a bad camera. ISE owns user ports. The firewall should quarantine the camera IP. eyeExtend is that bus. This lesson is how to share context without two products slamming the same switchport.

Updated 2026-08-18·16 min read·L2 primary·Quiz at end

After this page you can

The ticket

Forescout flagged malware-like traffic from 10.20.30.80. Virtual FW blocked her. ISE still showed Auth OK VLAN 30. SOC had two truths.

Quick interview answer

eyeExtend connects Forescout to the tools you already own. Typical: publish host properties to ISE (pxGrid / ANC / endpoint group) so ISE CoA re-authorizes, or add the IP to a Palo Alto / Check Point group. Forescout stays the sensor. ISE or the firewall stays the enforcer for that domain.

Hero · share, don’t wrestle
Forescout sharing context to ISE and firewall
One event, one enforcer. The other system only receives a tag.
Lab data · dummy only

Enterprise Manager fs-em 10.10.10.30 · Appliance fs-app1 10.10.10.31 · span/mirror on sw-access-01 · same LAN 10.20.30.0/24 · Priya 10.20.30.80 · printer 10.20.30.60 · OT PLC 10.50.1.10. Not a live customer.

The bus

Forescout marketplace: eyeExtend for Advanced Compliance and partner modules automate response using products you already have.

PatternSensorEnforcer
AForescoutISE ANC / CoA
BForescoutNGFW object / quarantine
CISE Live LogsForescout inspect only (rare)
https://fs-em.techclick-lab.in
Training mock · not live
Asset InventoryPolicyChannelsTools
Modules → eyeExtend Cisco ISE

Connection

ise-pan.techclick-lab.in
Assign ANC Quarantine
Forescout → ISE
Off for these hosts
eyeExtend Cisco ISE module. Training mock — exact menu names vary by module version.

Three patterns

User VLAN owned by ISE → pattern A. Camera subnet with no ISE → pattern B or Virtual FW (one only). Never A+B+plugin together.

How you wire ISE

  1. Side A — ISE

    pxGrid / ERS / ANC enabled on PAN (your train’s module README). Dedicated API user.

  2. Side B — Forescout module

    Connect, map “High risk laptop” → ANC Quarantine.

  3. Side C — prove

    Trigger on a lab PC. ISE Live Logs show CoA. Session dACL becomes quarantine. Forescout does not also Virtual-FW it.

Four extend failures

1 · Cert/trust for pxGrid

2 · Dual enforce

3 · API user = Super Admin

4 · Mapping every Forescout property into ISE Authz

How to prove it

Close the ticket only when

1) Module status Connected. 2) One lab trigger. 3) Exactly one enforcer log. 4) Rollback: clear ANC / remove FW object.

Traps

WrongRight
eyeExtend is a third NACIt is a bus
Silent mappingDocument the ANC name

Knowledge check

Judgment items. One best answer. Reasons send you back to the matching section.

Q1

eyeExtend is…

Correct: a. Concept.
Q2

User ports owned by ISE. Forescout should…

Correct: a. Pattern A.
Q3

Prove the handoff?

Correct: a. Runbook C.
Q4

API user should be…

Correct: a. Failure 3.
Q5

pxGrid cert broken. Symptom?

Correct: a. Failure 1.
Q6

Three enforce paths at once?

Correct: a. Choose.

Forescout class series: Three products · First day · Discovery · Classification · Policy · Enforcement · Switch plugin · eyeExtend · OT / IoT · vs ISE + interview

Sources

Related: Forescout evidence desk · session factory · Cisco ISE series.