# Policy: inspect first, control later, first match still wins

Source: https://ai.techclick.in/blog_forescout_policy_first_match
Markdown: https://ai.techclick.in/blog_forescout_policy_first_match.md
Publisher: Techclick Infosec Pvt Ltd

Policy tree: inspect vs control. First matching sub-rule. Dummy HR_Laptop policy.

## The ticket

 Printer classified correctly, still blocked. Host log shows it matched “Windows corporate — allow” never the printer rule. Order was wrong.

  Quick interview answer

 Policies evaluate top-down. Start with  inspect-only  (classify, notify). Add  control  (Virtual FW, switch VLAN, HTTP) only on high-confidence groups. Official how-to videos: policy in the console can enforce an eyeSegment / NAC action — treat that as a change window, not a default.

  Hero · tree

 Pause control = still see. Delete policy = go blind.
  Lab data · dummy only
 Enterprise Manager  fs-em   10.10.10.30  · Appliance  fs-app1   10.10.10.31  · span/mirror on  sw-access-01  · same LAN  10.20.30.0/24  · Priya  10.20.30.80  · printer  10.20.30.60  · OT PLC  10.50.1.10 . Not a live customer.

## Inspect vs control

   Mode  Does  When

  Inspect  Match, log, email  Always first
  Control  Virtual FW / VLAN / 802.1X / script  After two weeks of clean inspect hits

     https://fs-em.techclick-lab.in

     Training mock · not live

       Forescout Console

       Asset Inventory  Policy  Channels  Tools

       Policy Manager

### HR_Laptop

        Main rule  Function = Laptop AND OS contains Windows

  Sub-rule 1  Domain joined → Inspect (later: allow)

  Sub-rule 2  Not joined → Notify IT

  Control  Paused

        Cancel  Save

   Policy Manager. Training mock.

## Tree design

 OT_Inspect (no control) at top. Printers. Phones. Windows. Unknown_Notify. Default_Inspect. Control copies live in a separate folder you enable per group.

## How you write one

- #### Side A — name the group Reuse classification from lesson 4.

- #### Side B — inspect policy Match + log + optional email. No Virtual FW checkbox.

- #### Side C — prove hit Host → Policies tab: HR_Laptop / sub-rule 1. Then — later — clone to control.

## Four policy failures

### 1 · Wide rule above specific

### 2 · Control enabled on Unknown

### 3 · Deleted inspect policy to “clean up”

### 4 · Two control policies fighting (Forescout + ISE)

## How to prove it

  Close the ticket only when

 1) Host shows the intended policy/sub-rule. 2) Control is paused unless that was the change. 3) Printers do not match Windows. 4) Unknown only notifies.

## Traps

   Symptom  Look at

  Wrong action  Rule order
  No hosts  Classification empty, not the ACE

## Knowledge check

   Judgment items. One best answer. Reasons send you back to the matching section.

       Q1
       Inspect vs control?

           Inspect sees/logs; control changes access
           They are the same
           Inspect blocks
           Control is EM only

       Correct:  a . Concept.

       Q2
       Unknown hosts should…

           Notify, not Virtual FW
           Get HR access
           Get default permit any
           Disable SPAN

       Correct:  a . Design.

       Q3
       Printer matches Windows policy. Cause?

           Wide rule above / weak condition
           NTP
           MnT
           pxGrid

       Correct:  a . Ticket.

       Q4
       To stop enforcement but keep seeing…

           Pause control / inspect-only
           Unplug SPAN
           Delete EM
           Disable DNS

       Correct:  a . Caption.

       Q5
       Two NACs controlling one port?

           Pick one owner
           Enable both Virtual FW and ISE dACL randomly
           That is required
           Use more NMAP

       Correct:  a . Failure 4.

       Q6
       Where do you see which rule hit?

           Host → Policies
           Show ip bgp
           ISE PAN only
           Gaia

       Correct:  a . Runbook C.

       Check answers
       Reset

  Forescout class series:   Three products  ·  First day  ·  Discovery  ·  Classification  ·  Policy  ·  Enforcement  ·  Switch plugin  ·  eyeExtend  ·  OT / IoT  ·  vs ISE + interview

## Sources

- Forescout console Policy Manager / How-to create an eyeControl policy.
- This series lessons 1 and 4.

 Related:  Forescout evidence desk  ·  session factory  ·  Cisco ISE series .

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
