T Techclick ← All lessons
Forescout · eyeSight / eyeControl · Lesson 2 of 10

First day: span up, enforce off

The appliance has power. Until a clean monitor interface sees the lab VLAN, inventory is empty and everyone will say “Forescout is broken.” This lesson is cabling and first login — not policies.

Updated 2026-08-18·16 min read·L2 primary·Quiz at end

After this page you can

The ticket

Inventory is empty. The span is on VLAN 1. Users live on VLAN 30. Forescout is fine. The mirror is wrong.

Quick interview answer

Appliance needs a management address (10.10.10.31), connectivity to EM (10.10.10.30), NTP, and a monitor interface on a SPAN/TAP that actually sees the user/OT VLANs. Response/enforcement is a different interface used later. Do not mix them.

Hero · first span
Appliance monitor NIC on a switch SPAN
If the SPAN source VLAN is wrong, classification will look “broken” forever.
Lab data · dummy only

Enterprise Manager fs-em 10.10.10.30 · Appliance fs-app1 10.10.10.31 · span/mirror on sw-access-01 · same LAN 10.20.30.0/24 · Priya 10.20.30.80 · printer 10.20.30.60 · OT PLC 10.50.1.10. Not a live customer.

Two NICs

NICJob
ManagementEM, DNS, NTP, eyeExtend
MonitorReceive SPAN/TAP copies
Response (later)Virtual FW / HTTP / ARP actions
https://fs-em.techclick-lab.in
Training mock · not live
Asset InventoryPolicyChannelsTools
Tools → Options → Channels

Channel VLAN30

fs-app1
eth1 — SPAN from sw-access-01 Gi1/0/24
Off
12 in last hour
Channels / interface assignment. Training mock.

SPAN vs TAP vs plugin

SPAN is fine for class. TAP is cleaner in production. Switch plugin (lesson 7) is for CLI VLAN/ACL, not a substitute for a visibility span if you want DHCP/HTTP banners.

First-day runbook

  1. Side A — switch

    Monitor session source VLAN 30 + printer VLAN, dest Gi1/0/24 toward fs-app1.

  2. Side B — appliance

    Set 10.10.10.31, default route, NTP, join EM.

  3. Side C — prove

    Asset Inventory: Priya and printer appear within minutes. Packet counters increment on eth1.

IOS SPAN · dummy
monitor session 1 source vlan 30 , 40
monitor session 1 destination interface Gi1/0/24
show monitor session 1
# Destination Port: Gi1/0/24
# Ingress: Disabled

Four first-day failures

1 · Wrong VLAN in SPAN

2 · Both NICs in one broadcast domain, looping

3 · No NTP — later 802.1X/ISE join looks flaky

4 · Appliance not approved on EM

How to prove it

Close first day only when

1) EM shows appliance Connected. 2) SPAN session is up. 3) Lab hosts visible. 4) Virtual FW off.

Traps

Empty inventoryCheck SPAN source, not the policy tree

Knowledge check

Judgment items. One best answer. Reasons send you back to the matching section.

Q1

Monitor NIC should see…

Correct: a. Concept.
Q2

Virtual FW on day one?

Correct: a. Proof.
Q3

Empty inventory, appliance green. First?

Correct: a. Ticket.
Q4

Management IP in this lab?

Correct: a. Lab.
Q5

Why NTP on first day?

Correct: a. Failure 3.
Q6

Response NIC vs monitor NIC?

Correct: a. Two NICs.

Forescout class series: Three products · First day · Discovery · Classification · Policy · Enforcement · Switch plugin · eyeExtend · OT / IoT · vs ISE + interview

Sources

Related: Forescout evidence desk · session factory · Cisco ISE series.