T Techclick ← All lessons
Forescout · eyeSight / eyeControl · Lesson 12 of 13

eyeSegment: see the matrix, simulate the deny, then hand off

Security wants “segment OT.” Networking hears Virtual Firewall. eyeSegment is a traffic matrix of Source and Destination zones — policy groups and eyeSight segments — plus a simulate-deny. It is not a second enforcement owner on the access port.

Updated 2026-08-18·18 min read·L2 primary·Quiz at end

After this page you can

The ticket

OT asked for a block from user VLAN 30 to PLC 10.50.1.10. Someone enabled Virtual Firewall on fs-app1 the same night. The filler line stopped. Nobody had looked at the matrix cell. eyeSegment exists so you see the flow before you own the drop.

Quick interview answer

eyeSegment builds a matrix of Source and Destination zones — selected from Forescout policy groups and eyeSight segments. The module also creates virtual default zones: Internal Network, Private Network, Multicast/Broadcast, Internet. You can focus a row/column/cell into sub-zones. You can simulate denying a segment and notify on a simulated violation. Enforcement is a later handoff (eyeExtend / NGFW / ISE), not “draw a VLAN and hope.” Docs: About the Forescout eyeSegment Module. Menu names vary 8.x/9.x — confirm on your train.

Hero · matrix before drop
eyeSegment source-destination traffic matrix before any deny
A blue cell is a flow. A drop without a simulation is an incident.
Lab data · dummy only

Enterprise Manager fs-em 10.10.10.30 · Appliance fs-app1 10.10.10.31 · span/mirror on sw-access-01 · same LAN 10.20.30.0/24 · Priya 10.20.30.80 · printer 10.20.30.60 · OT PLC 10.50.1.10. Not a live customer.

Zones and the matrix

Zone kindWhat it is
Policy group / eyeSight segmentYou pick these as Source, Destination, or both
Internal NetworkIPs in eyeSight internal network not already in a user zone
Private NetworkPrivate IPs outside that internal network
Multicast/BroadcastThose ranges
InternetEverything else
One cell — users to PLC
Source zoneUsers 10.20.30.0/24policy group Matrix cellflow present · simulate denynotify OT — do not Virtual-FW Dest zoneOT PLC 10.50.1.10eyeSight segment

Focus the cell for sub-zones and ports. Then simulate. Then pick one enforcer (lesson 8 eyeExtend).

https://fs-em.techclick-lab.in
Training mock · not live
Asset InventoryPolicyChannelsTools
eyeSegment → Matrix

Shared matrix

Users (policy group), Internal Network
OT-PLC (eyeSight segment), Internet
Users → OT-PLC · traffic present
Simulate deny + notify OT DL — not enabled
About eyeSegment: one shared matrix; each user can keep Advanced Filter criteria. Training mock — confirm Open the eyeSegment Application on your version.

Simulate vs enforce

Week 1: matrix + filters only. Week 2: simulate deny on one unexpected cell, notify. Week 3+: push the committed rule to the owner you already named — NGFW object or ISE ANC — not Virtual FW on the same ports ISE owns. OT cells stay simulate/notify unless OT signed the change.

How you use one cell

  1. Side A — zones

    Create/select Users (10.20.30.0/24 policy group) and OT-PLC (10.50.1.0/24 segment). Know Internal Network vs Internet so leftover traffic is not “invisible.”

  2. Side B — matrix

    Open eyeSegment. Confirm the Users → OT-PLC cell. Focus/drill if the product shows sub-zones. Note service/port if shown.

  3. Side C — simulate then hand off

    Simulate deny + notify. If the flow is unexpected, ticket OT. If it is expected (historian, engineering workstation), do not drop it. Enforcement owner is written: Forescout inspect only, or eyeExtend → firewall. One owner.

Four matrix failures

1 · Virtual FW instead of a matrix look

2 · Treating Internet default zone as “we have no OT traffic”

Unzoned IPs land in virtual defaults. Empty user zones ≠ empty plant.

3 · Dual enforce (matrix policy + plugin VLAN + ISE CoA)

4 · Simulating nothing, enforcing everything on Friday

How to prove it

Close the ticket only when

1) Named Source and Destination zones. 2) Screenshot or export of the Users → OT-PLC cell. 3) Simulate-deny result attached. 4) Written enforcer (none / NGFW / ISE) — not “both plus Virtual FW.” 5) OT named if the cell touches 10.50.1.0/24.

Traps

WrongRight
eyeSegment is a third NACIt is a matrix + simulate layer on eyeSight data
Zone = VLAN IDZone = policy group / segment / virtual default
No cell = no riskWrong SPAN (lesson 2) hides the cell

Knowledge check

Judgment items. One best answer. Reasons send you back to the matching section.

Q1

eyeSegment’s primary picture is…

Correct: c. About the eyeSegment Module — matrix of selected zones.
Q2

Virtual default zones include…

Correct: b. Official default zone list.
Q3

Users → PLC cell shows traffic. First control?

Correct: a. Ticket + Choose.
Q4

Who should enforce a committed OT deny in this design?

Correct: d. Lesson 6/8 one owner; lesson 9 OT change ticket.
Q5

A zone can be designated…

Correct: c. Docs: each zone Source, Destination, or both.
Q6

No matrix cell but OT insists users hit the PLC. Suspect?

Correct: b. Traps + lesson 2.

Forescout class series: Three products · First day · Discovery · Classification · Policy · Enforcement · Switch plugin · eyeExtend · OT / IoT · vs ISE + interview · HPS posture · eyeSegment matrix · RADIUS 802.1X MAB

Sources

Related: Forescout evidence desk · session factory · Cisco ISE series.