ForeScout CounterACT
- 02 Mar 2023
- 2 Minutes to read
- Print
- DarkLight
- PDF
ForeScout CounterACT
- Updated on 02 Mar 2023
- 2 Minutes to read
- Print
- DarkLight
- PDF
Article Summary
ForeScout CounterACT platform provides insight into network-connected devices.
Types of Assets Fetched
This adapter fetches the following types of assets:
- Devices
Parameters
NOTE
To allow Axonius use the ForeScout eyeExtend Connect Module for Web API, you need to install and configure that module, especially user credentials and valid IP addresses. For details, see 'How to Install' and 'Configure the Module' sections in the ForeScout eyeExtend Connect Module for Web API Plugin Configuration Guide.
- ForeScout CounterACT Domain (required) – The URL for the ForeScout CounterAct domain.
- User Name and Password (required) - The credentials for a user account that has the Required Permissions to fetch assets.
- Verify SSL (required, default: False) - Verify the SSL certificate offered by the value supplied in ForeScout CounterACT Domain. For more details, see SSL Trust & CA Settings.
- If enabled, the SSL certificate offered by the value supplied in ForeScout CounterACT Domain will be verified against the CA database inside of Axonius. If the SSL certificate can not be validated against the CA database inside of Axonius, the connection will fail with an error.
- If disabled, the SSL certificate offered by the value supplied in ForeScout CounterACT Domain will not be verified against the CA database inside of Axonius.
- HTTPS Proxy (optional, default: empty) - A proxy to use when connecting to the value supplied in ForeScout CounterACT Domain.
- If supplied, Axonius will utilize the proxy when connecting to the value supplied in ForeScout CounterACT Domain.
- If not supplied, Axonius will connect directly to the value supplied in ForeScout CounterACT Domain.
- To learn more about common adapter connection parameters and buttons, see Adding a New Adapter Connection.
Advanced Settings
Note:
Advanced settings can either apply for all connections for this adapter, or you can set different advanced settings and/or different scheduling for a specific connection, refer to Advanced Configuration for Adapters
- Do not fetch devices with no MAC address and no hostname (required, default: False) - Select whether to exclude fetching devices without MAC address and without hostname.
- If enabled, all connections for this adapter will only fetch devices having MAC address or hostname.
- If disabled, all connections for this adapter will fetch devices even if those do not have MAC address and no hostname.
- Do not fetch devices with no IP (required, default: False) - Select whether to exclude fetching devices without an IP address.
- If enabled, all connections for this adapter will only fetch devices with an IP address.
- If disabled, all connections for this adapter will fetch devices even if those do not have an IP address.
- Ignore irrelevant device manufacturers - Select this option to ignore the device manufacturer field.
- Number of parallel requests (required, default: 10) - Set the number of parallel requests that the ForeScout CounterAct server will get data from devices.
- Re-authenticate every X requests (required, default 100) - Set the number of requests to allow before attempting to re-authenticate to get a new session token.
- Do not fetch rule information for devices (fast mode) - Select this option to not fetch each device's Forescout policies and rules.
NOTE
For details on general advanced settings under the Adapter Configuration tab, see Adapter Advanced Settings.
APIs
Axonius uses the Forescout eyeExtend Connect Module: Web API.
Required Permissions
The value supplied in User Name must have permissions to use the API, see Configure the Web API section in the ForeScout eyeExtend Connect Module for Web API Plugin Configuration Guide.