T Techclick ← All lessons
Forescout · eyeSight / eyeControl · Lesson 6 of 10

Enforcement: Virtual Firewall or 802.1X — not both wild

You can block a camera with the appliance (Virtual Firewall / ACL-like) or with ISE 802.1X/MAB. Doing both without a design is a flap. This lesson is how to choose.

Updated 2026-08-18·16 min read·L2 primary·Quiz at end

After this page you can

The ticket

Port flaps: ISE assigns VLAN 30, Forescout Virtual FW remaps, ISE CoA, repeat. Two owners.

Quick interview answer

Virtual Firewall: the appliance applies allow/deny (or similar control) using its response path — good for devices that will never do 802.1X. 802.1X/MAB via ISE: the switch is the enforcer; Forescout should only see or trigger ISE via eyeExtend. One port, one enforcement owner.

Hero · two hammers
Virtual firewall versus 802.1X enforcement
Laptops → ISE. Cameras/PLC → Forescout visibility, then one control path.
Lab data · dummy only

Enterprise Manager fs-em 10.10.10.30 · Appliance fs-app1 10.10.10.31 · span/mirror on sw-access-01 · same LAN 10.20.30.0/24 · Priya 10.20.30.80 · printer 10.20.30.60 · OT PLC 10.50.1.10. Not a live customer.

Two hammers

Virtual FW / pluginISE 802.1X
EnforcerAppliance / switch CLISwitch RADIUS
IdentityClassificationUser/cert/MAC
BestAgentless OT/IoTManaged users

Decision table

Windows domain laptop → ISE only (Forescout inspect). Camera → Forescout classify, optional Virtual FW or MAB in ISE — pick one. PLC → inspect only unless OT signed a control window.

https://fs-em.techclick-lab.in
Training mock · not live
Asset InventoryPolicyChannelsTools
Policy → Camera_Lab → Control

Actions

Allow 10.20.30.5 (NVR) only — paused
Not applied
Not applied
Forescout (cameras)
eyeControl actions. Training mock.

How you enable one

  1. Side A — write the owner

    Spreadsheet: VLAN/port range → ISE or Forescout.

  2. Side B — enable one action

    Notify week, then one control on one camera.

  3. Side C — prove

    Host log shows one action. Switch session does not also show a conflicting ISE VLAN change.

Four enforce failures

1 · Dual owners

2 · Virtual FW without response NIC

3 · 802.1X on PLC

4 · Control before classify

How to prove it

Close the ticket only when

1) Written owner. 2) One action in the log. 3) Camera still reaches NVR. 4) Priya still does ISE 802.1X, not Virtual FW.

Traps

WrongRight
Both products “just in case”One owner
Virtual FW = stealth ASAIt is NAC control, not a perimeter FW

Knowledge check

Judgment items. One best answer. Reasons send you back to the matching section.

Q1

User laptops should be enforced by…

Correct: a. Choose.
Q2

Agentless camera. Reasonable owner?

Correct: a. Quick answer.
Q3

Port flapping VLAN 30/40. Suspect?

Correct: a. Ticket.
Q4

Virtual FW without response NIC?

Correct: a. Failure 2.
Q5

PLC 802.1X PEAP?

Correct: a. Failure 3.
Q6

Prove ownership?

Correct: a. Runbook C.

Forescout class series: Three products · First day · Discovery · Classification · Policy · Enforcement · Switch plugin · eyeExtend · OT / IoT · vs ISE + interview

Sources

Related: Forescout evidence desk · session factory · Cisco ISE series.