T Techclick ← All lessons
Forescout · eyeSight / eyeControl · Lesson 1 of 10

Forescout: see first, then enforce, then orchestrate

A PLC appeared on VLAN 30. Someone wants 802.1X tomorrow. Forescout’s first job is not RADIUS. It is eyeSight — discover and classify without an agent. eyeControl enforces. eyeExtend talks to ISE and firewalls. Mixing those three words is how OT outages start.

Updated 2026-08-18·16 min read·L2 primary·Quiz at end

After this page you can

The ticket

Security asked for NAC. Networking heard 802.1X. Biomed heard “scanner.” Forescout can do all three badly if you enable Virtual Firewall on day one.

Quick interview answer

eyeSight discovers and classifies IP-connected devices (docs: without agents; passive + careful active). eyeControl automates admission and post-admission actions. eyeExtend shares context and response with ISE, firewalls, ITSM. Enterprise Manager is the console brain; Appliances sit on spans and switch plugins — like PAN vs PSN, not identical.

Hero · see / enforce / share
eyeSight see, eyeControl enforce, eyeExtend share
If you cannot classify it, do not Virtual-Firewall it.
Lab data · dummy only

Enterprise Manager fs-em 10.10.10.30 · Appliance fs-app1 10.10.10.31 · span/mirror on sw-access-01 · same LAN 10.20.30.0/24 · Priya 10.20.30.80 · printer 10.20.30.60 · OT PLC 10.50.1.10. Not a live customer.

Three products

ProductJobThis lab
eyeSightDiscover, classify, postureAlways on
eyeControlVirtual FW, 802.1X, switch CLI, HTTP notifyOff until lesson 6
eyeExtendISE / Palo Alto / ServiceNowLesson 8
eyeSegmentMatrix segmentation (optional)Mention only
Like ISE personas — not the same
Enterprise Managerconsole / policies Appliance fs-app1span + plugin Switch / ISEenforce / RADIUS

Rebooting EM because a span is dark is the wrong box.

When to turn enforce on

Week 1–2: discover only. Week 3: notify. Week 4+: Virtual FW or ISE handoff on known groups. Never enforce Unknown.

https://fs-em.techclick-lab.in
Training mock · not live
Asset InventoryPolicyChannelsTools
Tools → Options → Modules

Licensed modules

On
Installed, policies paused
Off until lesson 8
Forescout docs: eyeSight admin — discover/classify. Training mock.

How you see it

  1. Side A — console

    Log into EM 10.10.10.30. Asset Inventory should start filling from the span on fs-app1.

  2. Side B — appliance

    Channel / interface: monitor (span) vs response (enforcement NIC). Do not put Virtual FW on the span NIC.

  3. Side C — prove

    Priya’s laptop and the printer appear with an IP and a first classification. No block actions yet.

Four mix-ups

1 · Calling Forescout “just 802.1X”

2 · Enforce on day one

3 · EM down = “NAC down” while appliances still see

4 · eyeExtend fighting ISE on the same port

How to prove it

Close the intro only when

1) You can say which product is on. 2) Inventory shows lab hosts. 3) No control action is hitting production VLANs. 4) You know EM ≠ appliance.

Traps

PhraseTranslate
CounterACTOlder name for the platform / appliance
eyeControl policyThe enforcement tree — not ISE policy set
Virtual FirewallAppliance inline/ACL-like control, not ASA

Knowledge check

Judgment items. One best answer. Reasons send you back to the matching section.

Q1

eyeSight’s job?

Correct: a. Docs.
Q2

eyeControl’s job?

Correct: a. Concept.
Q3

eyeExtend’s job?

Correct: a. Concept.
Q4

Enterprise Manager is closest to…

Correct: a. SVG.
Q5

When do you enable enforcement?

Correct: a. Choose.
Q6

Virtual Firewall on the span NIC is wrong because…

Correct: a. Runbook Side B.

Forescout class series: Three products · First day · Discovery · Classification · Policy · Enforcement · Switch plugin · eyeExtend · OT / IoT · vs ISE + interview

Sources

Related: Forescout evidence desk · session factory · Cisco ISE series.