Forescout NAC โ Agentless Visibility & Control
eyeSight + eyeControl + eyeSegment + eyeInspect. Visibility & control for IT, IoT and OT โ without agents.
Who Is This For
- NAC engineers running Forescout in production
- Engineers comparing Forescout vs Cisco ISE
- OT / IoT security architects
- L2 / L3 admins migrating from agent-based NAC
Prerequisites
- CCNA-level networking
- Some firewall / NAC exposure useful, not required
Full Syllabus โ 12 Modules
M 1Forescout Architecture
- CounterACT appliance lineup
- Enterprise Manager & Recovery Enterprise Manager
- Distributed deployment design
- Plugins / Modules ecosystem
M 2Initial Setup & CLI
- Bootstrap appliance
- Console / fstool CLI basics
- HA & failover
- Console access policies
M 3Discovery & Visibility (eyeSight)
- Network monitoring methods
- SPAN / RSPAN, mirror sessions
- SNMP, switch / router integrations
- Asset inventory dashboard
M 4Classification & Profiling
- Function / OS / vendor classification
- Custom property fields
- Cloud Profiling Service
- Anomaly detection
M 5Authentication & 802.1X
- RADIUS Plugin
- 802.1X integration
- MAC Authentication Bypass
- EAP types support
M 6Compliance & Posture Policies
- HPS Inspection Engine
- Compliance checks for Windows / macOS / Linux
- Custom policies, scripts
- Remediation actions
M 7Network Access Control (eyeControl)
- Restrict / VLAN change actions
- HTTP redirect to portal
- Switch ACL push
- Wireless & VPN restrictions
M 8Segmentation (eyeSegment)
- Traffic matrix & baseline
- Policy zones & suggested rules
- Integration with firewalls (Palo Alto, Cisco, etc.)
- Microsegmentation use cases
M 9IoT & OT Security (eyeInspect)
- OT protocols โ Modbus, DNP3, Profinet
- OT asset discovery
- Anomaly & threat detection
- Manufacturing / utility / healthcare use cases
M 10Third-Party Integrations
- Firewall integrations โ Palo Alto / FortiGate / Check Point
- SIEM forwarding (Splunk, QRadar, Sentinel)
- Vulnerability scanners (Tenable, Qualys)
- EDR integrations
M 11Operations & Troubleshooting
- Reports & dashboards
- Daily admin tasks
- Common issues โ discovery gaps, false positives
- fstool debug
M 12Cert Path & Interview Prep
- FSCA / FSCE blueprint
- Forescout vs Cisco ISE comparison
- L2 / L3 interview question bank
What You Get
40 Hours
Live + recorded sessions for the full Forescout suite.
Walkthroughs
Recorded admin demos โ vendor lab access is read-only.
Real Case Studies
OT discovery, segmentation rollout, compliance policy tuning, firewall integration.
Interview Q&A
L2 / L3 NAC + IoT/OT question bank.
Certificate
Techclick Infosec course completion certificate.
WhatsApp Group
Doubt-clearing batch group with the trainer.
Your Instructor
Trained by working senior cloud and network security engineers with 13+ years of hands-on enterprise experience across NAC, IoT/OT security, Forescout and Cisco ISE.
FAQ
Q 1Forescout vs Cisco ISE?
Both covered comparatively in Module 12. Forescout is agentless and stronger for IoT/OT.
Q 2Hands-on labs?
Vendor labs are read-only. We use recorded admin demos plus screenshot-based config exercises.
Q 3OT covered?
Yes โ Module 9 is dedicated to eyeInspect and OT protocols.
Q 4Duration?
About 40 hours over 5โ6 weeks.
Q 5Placement help?
CV review and interview prep.
Visibility without agents.
Talk to us about the next batch.