The ticket
Security asked for NAC. Networking heard 802.1X. Biomed heard “scanner.” Forescout can do all three badly if you enable Virtual Firewall on day one.
eyeSight discovers and classifies IP-connected devices (docs: without agents; passive + careful active). eyeControl automates admission and post-admission actions. eyeExtend shares context and response with ISE, firewalls, ITSM. Enterprise Manager is the console brain; Appliances sit on spans and switch plugins — like PAN vs PSN, not identical.
Enterprise Manager fs-em 10.10.10.30 · Appliance fs-app1 10.10.10.31 · span/mirror on sw-access-01 · same LAN 10.20.30.0/24 · Priya 10.20.30.80 · printer 10.20.30.60 · OT PLC 10.50.1.10. Not a live customer.
Three products
| Product | Job | This lab |
|---|---|---|
| eyeSight | Discover, classify, posture | Always on |
| eyeControl | Virtual FW, 802.1X, switch CLI, HTTP notify | Off until lesson 6 |
| eyeExtend | ISE / Palo Alto / ServiceNow | Lesson 8 |
| eyeSegment | Matrix segmentation (optional) | Mention only |
Rebooting EM because a span is dark is the wrong box.
When to turn enforce on
Week 1–2: discover only. Week 3: notify. Week 4+: Virtual FW or ISE handoff on known groups. Never enforce Unknown.
Licensed modules
How you see it
Side A — console
Log into EM 10.10.10.30. Asset Inventory should start filling from the span on fs-app1.
Side B — appliance
Channel / interface: monitor (span) vs response (enforcement NIC). Do not put Virtual FW on the span NIC.
Side C — prove
Priya’s laptop and the printer appear with an IP and a first classification. No block actions yet.
Four mix-ups
1 · Calling Forescout “just 802.1X”
2 · Enforce on day one
3 · EM down = “NAC down” while appliances still see
4 · eyeExtend fighting ISE on the same port
How to prove it
1) You can say which product is on. 2) Inventory shows lab hosts. 3) No control action is hitting production VLANs. 4) You know EM ≠ appliance.
Traps
| Phrase | Translate |
|---|---|
| CounterACT | Older name for the platform / appliance |
| eyeControl policy | The enforcement tree — not ISE policy set |
| Virtual Firewall | Appliance inline/ACL-like control, not ASA |
Knowledge check
Judgment items. One best answer. Reasons send you back to the matching section.
Forescout class series: Three products · First day · Discovery · Classification · Policy · Enforcement · Switch plugin · eyeExtend · OT / IoT · vs ISE + interview
Sources
- Forescout eyeSight admin — discover/classify without agents.
- eyeSight, eyeControl / eyeExtend.
Related: Forescout evidence desk · session factory · Cisco ISE series.