Professional Documents
Culture Documents
5100 Series Physical Appliance This guide will help you scope your requirements for deploying the Forescout platform on:
Specifications (Flexx).......................................................11
• Physical appliances: the 5100 Series, 4100 Series and CT Series appliances
4100 Series Physical Appliance • Virtual appliances: supported on VMware ESXi, Microsoft Hyper-V and Linux KVM. Note that virtual appliances
Specifications (Flexx).......................................................14 can be deployed on-premises as well as in AWS or Azure public clouds.
Sizing CT & CEM Series Appliances The Forescout platform currently offers two licensing paths.
(Per-Appliance).................................................................15
• Flexx Licensing: Licenses are independent of hardware appliances, providing an intuitive and flexible way to
license, deploy and manage Forescout products across your extended enterprise – campus, data center, IoT,
Virtual Appliance Specifications
(Per-Appliance).................................................................15 cloud and OT. Existing CT appliance customers can upgrade to Flexx, supported from Forescout software
version 8.0.
CT & CEM Series Physical Appliance Specifications • Per-Appliance Licensing: Licenses have a fixed device count per appliance. License counts cannot be
(Per-Appliance).................................................................18 reallocated or shared across appliances. Per-appliance licensing is only available on CT appliances.
Appendix A
Test Environment..............................................................24
Appendix B
Bandwidth Considerations...............................................25
Forescout Licensing and Sizing Guide 2
eyeManage eyeRecover
Scalable Enterprise Management | included in eyesight license Failover and Resiliency
Deployment
Products
Physical Appliances Virtual Appliances Vitual Appliances
5100 Series (on-premises) (public cloud)
CT Series KVM, VMware, Hyper-V AWS, Azure
Step 2: Determine which use cases you want to solve Forescout 4100/5100 Series Appliance Deployments (Flexx Licensing Only)
The Forescout platform provides visibility and control for your devices from campus to • Forescout 5120
• Forescout 5160
data center to cloud and to IoT and OT devices. In addition to the visibility capabilities
of eyeSight, you may be considering network segmentation and want • Forescout 5140 • Forescout 5110
to evaluate eyeSegment. As you start rolling out enforcement of policy-based • Forescout 4130
actions, you’ll need to add licenses for eyeControl. To help you get more from your
investments in other security and IT management tools, eyeExtend products can The Forescout 5160/5140/5120 appliances are 1U appliances. Although size is not
provide bi-directional data sharing and workflows across 25 technologies. the only consideration, in general, Forescout 5160 appliances are better suited to
large deployments, Forescout 5140 to medium-size deployments and Forescout 5120
eyeExtend Connect enables integration with even more IT and security tools. An to small deployments. For centralized management and single-pane manageability
eyeExtend Connect license is required to run eyeExtend apps. If you want to run more across all Forescout appliances, you simply dedicate one of the rack-mounted
than two eyeExtend apps, you can purchase eyeExtend app licenses in bundles of Forescout appliances to be your Forescout eyeManage appliance. The Forescout
five apps. You may also have resiliency requirements for high availability or failover 5110 is a small form-factor desktop version for extra-small deployments and is not
scenarios. Forescout eyeRecover enables failover or disaster recovery. All of these recommended for the integrated OT sensor. Forescout version 8.2.0 and higher are
products are licensed per device. not supported on the 5110 appliances, but a Limited Appliance option is available
starting from the 8.2.1 release.
License Sub-Scoping
Available on Forescout version 8.1 or higher, sub-scoping enables you to purchase CT Series Deployments (Per-Appliance Licensing)
licenses to cover a portion rather than all of their connected devices. Forescout offers
• Forescout CT-10000 • Forescout CT-1000
sub-scoping for eyeControl and eyeRecover as well as for eyeExtend products for
Advanced Compliance, EMM, EPP, EDR, PAM and CTM categories. • Forescout CT-4000 • Forescout CT-100
• Forescout CT-2000 • Forescout CT-R
Examples include:
• If you are deploying in both campus and OT networks, you may choose to deploy Upgrades from per-appliance licensing to Flexx are available for existing CT Series
eyeControl only in your campus environment. customers. The Forescout CT appliances are 1U appliances with the exception of
the CT-R, which is a small form-factor, desktop version for extra-small deployments.
• If you have an EMM solution, you may choose to purchase eyeExtend product
Forescout version 8.2.0 and higher are not supported on the CT-R appliances but a
licenses just for your mobile devices.
Limited Appliance option is available starting from the 8.2.1 release.
costs are to keep appliances near the assets (devices and switches) with which they What if licenses have been exceeded?
interact. Deploy as follows: If you have exceeded the license count purchased for your devices, you will need
• Use cloud-based appliances to manage cloud-based assets to do an “Endpoint Count True-Up,” where you pay prorated fees for the additional
licensing units required as well as the prorated fees for the associated Forescout
• Use on-premises appliances to manage on-premises assets ActiveCare. Fees for both true-up licenses and ActiveCare are based on your most
• Mix cloud-based and on-premises appliances to manage hybrid assets recent and applicable order(s). Please refer to the End User License Agreement
• Use focal and dedicated appliances close to the third-party applications with (EULA) for full details: https://www.Forescout.com/company/legal/eula.
which they interact
For detailed deployment guidance, see the “Forescout Platform Implementation in the Licensing Examples
AWS or Microsoft Azure Cloud How-to Guide,” available on the Forescout Customer
Portal. Example A:
You have 18,000 devices across three locations. Location A has a physical Forescout
5160 appliance that manages 6,000 devices. Location B also has a physical
Step 4: Determine how you would like to license
Forescout 5160 appliance that manages 7,000 devices. Location C is managing 5,000
Many products in the Forescout platform are offered in perpetual and term-based
devices with a virtual appliance. They have dedicated a physical Forescout 5140
licensing modes. Forescout eyeSight, eyeControl, eyeRecover and eyeExtend products
appliance for Forescout eyeManage (EM below).
are all available through term-based and perpetual licenses. Forescout eyeSegment
is available through subscription licenses of one or three years. For term-based
or subscription licensing, you must be running Forescout 8.1 or later. Forescout
Customer – Worldwide License for 18,000 Devices (installed at EM)
eyeManage functionality is included with the eyeSight license. Shipping Company
• The device count is the maximum number of devices known to eyeSight by either Location B - 7,000 devices
(Physical Appliance)
their MAC addresses and/or their IP addresses FS-HW-5160 FS-HW-5160 Spin-Up Virtual Appliance
Location C - 5,000 devices
• Devices may be detected by eyeSight when on site or off site, or they may be (Virtual Appliance) Using 18,000 Licenses Across 3 Locations
To ensure that Forescout can provide the best experience, four ActiveCare Basic Sizing Forescout 5100 Series
or Advanced licenses for maintenance and support of the hardware and software
Forescout appliances are needed: two ActiveCare licenses for the two 5160 Appliances (Forescout Flexx Licensing)
appliances, one ActiveCare license for the 5140 appliance used for eyeManage and
18,000 ActiveCare licenses for the 18,000 devices. Forescout 5100 Series appliances only support Flexx, not per-appliance licensing.
In addition to the licenses in Example A, you would purchase 18,000 licenses for Appliance specifications
eyeRecover, eyeExtend for ServiceNow and eyeExtend for Splunk. You would also Large networks that require multiple appliances can be centrally managed by
need the accompanying ActiveCare maintenance and support for each license. Note Forescout eyeManage. Up to a maximum of 200 Forescout appliances can be
that vulnerability assessment (VA), security information and event management managed in a single eyeManage deployment.
(SIEM), IT service management (ITSM), next-generation firewall (NGFW), advanced
threat detection (ATD) and the Forescout Open Integration Module (OIM) eyeExtend Appliance sizing recommendations are based on the following performance
licenses are not available for sub-scoping. requirements:
• Managed endpoints/devices
Example C:
• Managed switch/wireless LAN devices
Let’s take an example where you already have a deployment with 100,000 devices,
8,000 of which are mobile devices. Also, you have just purchased MobileIron®. You • Traffic monitoring (Gb/s) + captive portal (HTTP logins/minute)
also have CrowdStrike® deployed to protect 60,000 of your devices and would like to • 802.1X (authentications/second)
take advantage of our orchestration solutions with both CrowdStrike and MobileIron.
Note: The hardware and virtual appliance specifications were tested using the test
As sub-scoping is supported for both of these eyeExtend products, only 60,000 environment described in Appendix A of this document. This test environment
orchestration licenses are needed for eyeExtend for CrowdStrike and 8,000 simulates a common customer environment and includes typically used modules.
orchestration licenses for eyeExtend for MobileIron. You will also need 60,000 and Your environment may differ from our test environment due to different configuration
8,000 of the associated ActiveCare Basic or Advanced licenses. settings, amounts of network traffic, installed modules or other factors. Your observed
performance will vary accordingly.
Forescout Licensing and Sizing Guide 6
802.1x Authentications per Up to 5 Up to 10 Up to 42 (+2 vCPUs & Up to 86 (+4 vCPUs & Up to 166
second4 4GB memory)4 4GB memory)4
Traffic Monitoring5 Up to 100 [Mb/s] 25 Up to 1 [Gb/s] 250 Up to 3 [Gb/s] 750 Up to 3 [Gb/s] 750 Not supported
[KPPS] [KPPS] (requires an [KPPS] (requires an [KPPS] (requires an
additional 2 vCPUs & 4 additional 8 vCPUs & 12 additional 8 vCPUs & 12
GB Memory)4 GB Memory)4 GB Memory)4
Traffic Monitoring specs 5 HTTP logins/minute 10 HTTP logins/minute 88 HTTP logins/minute 88 HTTP logins/minute Not supported
above deliver captive portal
capacity for:
NetFlow 0 0 50,000 flows per 50,000 flows per 50,000 flows per
second second second
Forescout Licensing and Sizing Guide 7
Virtual Machine (VM) Specifications1 Extra-Small Small Medium Large Extra Large
Memory 12 GB (*) 14 GB 24 GB 32 GB 80 GB
* For Extra Small appliance, a minimum of 8 GB is needed if using version prior to 8.2.2.
* Extra-Large appliance is available starting from version 8.2.2.
Switch dedicated appliance Up to 120 managed Up to 280 managed Up to 400 managed Up to 1,900 managed
switches3,6 switches3,6 switches3,6 switches
Wireless dedicated appliance Up to 140 WLAN devices3 Up to 250 WLAN devices3 Up to 360 WLAN devices3 Up to 1,500 WLAN devices
NetFlow dedicated appliance 0 Up to 300,000 flows per Up to 300,000 flows per Up to 300,000 flows per
second second second
Memory 14 GB 24 GB 32 GB 80 GBs
To achieve: Up to 3 [Gb/s] 750 [KPPS] Up to 4 [Gb/s] 1000 [KPPS] Up to 9 [Gb/s] 2250 [KPPS]
Tested NIC VMware E1000/Hyper-V Network Adapter VMware VMXNET3 VMware PCI Passthrough
Maximum Traffic Monitoring per vNIC 750 [MB/s] 1 [Gb/s] 4.5 [Gb/s]
Memory 12 GB 12 GB 24 GB
Memory 12 GB 16 GB 24 GB
The maximum number of Forescout appliances that can be managed will vary based on factors including but not limited to network environment, product configuration and use cases.
Forescout Licensing and Sizing Guide 9
Performance Specifications
Small Medium Large
(Microsoft Azure)
Requirements: Requirements:
• Traffic monitoring performance: 2 [Gb/s] • Support 10 802.1X EAP-TLS authentication events per second
• 802.1X is not required • Traffic monitoring is not required
Therefore, the total virtual appliance size would be: Therefore, the total virtual appliance size would be:
Traffic Monitoring Up to 100 [Mb/s] 25 [KPPS] Up to 1 [Gb/s] 250 [KPPS] Up to 5 [Gb/s] 1250 [KPPS] Up to 10 [Gb/s] 2500 [KPPS]
Captive Portal (capacity) Up to 5 HTTP logins/minute Up to 10 HTTP logins/minute Up to 50 HTTP logins/minute Up to 200 HTTP logins/minute
OT Sensor Traffic Monitoring7 N/A Up to 500 [Mb/s] Up to 500 [Mb/s] Up to 500 [Mb/s]
NetFlow 0 50,000 flows per second 50,000 flows per second 50,000 flows per second
Form Factor Shelf/Desktop 1RU 19” Rack Mount 1RU 19” Rack Mount 1RU 19” Rack Mount
Fixed Network Interfaces 4x10/100/1000 Mbps Copper 4x10/100/1000 Mbps Copper 4x10/100/1000 Mbps Copper 4x10/100/1000 Mbps Copper
SFP Network Interfaces N/A 4 (2x1G/10G dual rate SR 4 (2x1G/10G dual rate SR 4 (2x1G/10G dual rate SR
Fiber SFPs included in base Fiber SFPs included in base Fiber SFPs included in base
configuration) configuration) configuration)
I/O Support 1 serial port (RJ45) 1 serial port (DB9) 1 serial port (DB9) 1 serial port (DB9)
USB Ports 2, USB 2.0-compliant 1 4-pin, USB 2.0-compliant 1 4-pin, USB 2.0-compliant 1 4-pin, USB 2.0-compliant
and 1 5-pin micro-USB 2.0 and 1 5-pin micro-USB 2.0 and 1 5-pin micro-USB 2.0
management port (front), 2 management port (front), 2 management port (front), 2
9-pin USB 3.0-compliant (rear) 9-pin USB 3.0-compliant (rear) 9-pin USB 3.0-compliant (rear)
DVD-ROM N/A 1 1 1
Hard Drives 1 HDD 3 HDD (RAID-1+HS) 600 GB 3 HDD (RAID-1+HS) 600 GB 3 HDD (RAID-1+HS) 1.2 TB
Power Supply 1 @ up to 60W 2 750W AC redundant power 2 750W AC redundant power 2 750W AC redundant power
100-240 VAC, 50~60Hz supply units, 100-240 VAC, supply units, 100-240 VAC, supply units, 100-240 VAC,
(external) 50~60Hz, auto-ranging 50~60Hz, auto-ranging 50~60Hz, auto-ranging
Operating Temperature 5°C to 40°C (41°F to 104°F) 10°C to 35°C (50°F to 95°F) 10°C to 35°C (50°F to 95°F) 10°C to 35°C (50°F to 95°F)
Storage Temperature 0°C to 70°C (32°F to 158°F) -40°C to 65°C (-40°F to 149°F) -40°C to 65°C (-40°F to 149°F) -40°C to 65°C (-40°F to 149°F)
Heat Dissipation (max.) N/A 2891 BTU/hr 2891 BTU/hr 2891 BTU/hr
Humidity 20% to 90% Operating (10% to 80%) Operating (10% to 80%) Operating (10% to 80%)
Appliance Dimensions 11cm x 21.06cm x 4.45cm 70.51cm x 48.18cm x 4.26cm 70.51cm x 48.18cm x 4.26cm 70.51cm x 48.18cm x 4.26cm
(length, width, height) (7.13” x 8.29” x 1.75”) (27.76” x 18.97” x 1.68”) (27.76” x 18.97” x 1.68”) (27.76” x 18.97” x 1.68”)
Shipment Package 38.1cm x 30.48cm x 16.51cm 84.18cm x 62.87cm x 84.18cm x 62.87cm x 84.18cm x 62.87cm x
(length, width, height, weight) (15” x 12” x 6.5”) 5.9 lbs 27.94cm (33.14” X 24.75” X 27.94cm (33.14” X 24.75” X 27.94cm (33.14” X 24.75” X
11.0”) 61 lbs 11.0”) 61 lbs 11.0”) 61 lbs
Switch dedicated appliance Up to 700 managed switches3,6 Up to 1,900 managed switches3,6 Up to 1,900 managed switches3,6
Wireless dedicated appliance Up to 500 WLAN devices3 Up to 1,000 WLAN devices3 Up to 1,500 WLAN devices3
NetFlow dedicated appliance Up to 300,000 flows per second Up to 300,000 flows per second Up to 300,000 flows per second
Forescout Licensing and Sizing Guide 13
Traffic Monitoring Up to 5 [Gb/s] 1250 [KPPS] Up to 10 [Gb/s] 2500 [KPPS] Up to 17 [Gb/s] 4250 [KPPS]
The maximum number of Forescout appliances that can be managed will vary based on factors including but not limited to network environment, product configuration and use cases.
Finisar FTLF1318P3BTL
1000BASE-LX 10km Industrial Temperature Gen 3 SFP Optical Transceiver
Finisar FTRJ1319P1BTL
Finisar FTLF8519P3BNL
1000BASE-SX 500m Extended Temperature SFP Optical Transceiver
Finisar FTLF8519P2BCL
Finisar FTLX1471D3BCV 10G/1G Dual Rate (10GBASE-LR and 1000BASE-LX) 10km SFP+ Optical Transceiver
Finisar FTLX8574D3BCV 10G/1G Dual Rate (10GBASE-SR and 1000BASE-SX) 400m Multimode Datacom SFP+ Optical Transceiver
DVD-ROM N/A
• Managed endpoints
• Managed switch/wireless LAN devices
• Traffic monitoring (Gb/s) + captive portal (HTTP logins/minute)
• 802.1X (authentications/second)
Note: The hardware and virtual appliance specifications were tested using the test environment described in Appendix A. This test environment simulates a common customer
environment and includes typically used modules. Your environment may differ from our test environment due to different configuration settings, amounts of network traffic,
installed modules or other factors. Your observed performance will vary accordingly.
Note: In virtual environments, factors such as CPU type, hypervisor version, memory and network I/O options may impact virtual appliance performance1.
Hardware Requirements:
• Maximum disk latency of 5ms
• Recommended I/O Read 200 MB/s or higher, I/O Write 200 MB/s or higher
• Minimum 2.0 Ghz CPU
• No CPU over commitment on virtual hosts
• CPUs and memory must be dedicated/reserved to the virtual appliance
• Additional disk space may be required to store local debug logs; virtual drives up to 2 TB are supported
Forescout Licensing and Sizing Guide 16
Traffic Monitoring5 Up to 100 [Mb/s] Up to 1 [Gb/s] 250 Up to 1 [Gb/s] 250 Up to 3 [Gb/s] 750 Up to 3 [Gb/s] 750 Up to 3 [Gb/s] 750
25 [KPPS] [KPPS] (requires [KPPS] (requires [KPPS] (requires [KPPS] (requires [KPPS] (requires
an additional 2 an additional 2 an additional 8 an additional 8 an additional 8
vCPUs and 4 GB vCPUs and 4 GB vCPUs and 12 GB vCPUs and 12 GB vCPUs and 12 GB
Memory)4 Memory)4 Memory)4 Memory)4 Memory)4
Traffic Monitoring specifications 5 HTTP logins/ 10 HTTP logins/ 10 HTTP logins/ 88 HTTP logins/ 88 HTTP logins/ 88 HTTP logins/
above deliver Captive portal minute minute minute minute minute minute
capacity for:
NetFlow 0 50,000 flows per 50,000 flows per 50,000 flows per 50,000 flows per 50,000 flows per
second second second second second
Memory 12 GB (*) 14 GB 14 GB 24 GB 24 GB 32 GB
Minimum Hard Drive Storage 200 GB 200 GB 200 GB 200 GB 200 GB 200 GB
eyeManage Performance
VCEM-05 VCEM-10 VCEM-25 VCEM-50 VCEM-100 VCEM-150 VCEM-200
Specifications
Memory 12 GB 24 GB 16 GB 16 GB 16 GB 24 GB 24 GB
Minimum Hard Drive Storage 200 GB 200 GB 200 GB 200 GB 200 GB 200 GB 200 GB
Up to 120 managed Up to 120 managed Up to 280 managed Up to 280 managed Up to 400 managed
Switch dedicated appliance
switches3.6 switches3.6 switches3.6 switches3.6 switches3.6
Up to 140 WLAN Up to 140 WLAN Up to 250 WLAN Up to 250 WLAN Up to 360 WLAN
Wireless dedicated appliance
devices3 devices3 devices3 devices3 devices3
Memory 14 GB 14 GB 24 GB 24 GB 32 GB
Note: Appliance capacity to manage switch/WLAN devices can vary depending on multiple factors, such as the actual number of endpoints connected to a device, the complexity of the policies
being run or the rates used by the plugin to poll devices.
Forescout Licensing and Sizing Guide 18
OT Sensor Traffic Monitoring N/A Up to 500 [Mb/s] Up to 500 [Mb/s] Up to 500 [Mb/s] Up to 500 [Mb/s] Up to 500 [Mb/s]
(only supported on Rev-50)7
1U desktop (steel
Chassis 1U 19” rack mount 1U 19” rack mount 1U 19” rack mount 1U 19” rack mount 1U 19” rack mount
slim line case)
I/O Support 1 serial port (RJ45) 1 serial port (DB9) 1 serial port (DB9) 1 serial port (DB9) 1 serial port (DB9) 1 serial port (DB9)
Forescout Licensing and Sizing Guide 19
2 back-panel USB 2 back-panel USB 2 back-panel USB 2 back-panel USB 2 back-panel USB
2 USB
USB Ports 2.0 + 1 front-panel 2.0 + 1 front panel 2.0 + 1 front panel 2.0 + 1 front panel 2.0 + 1 front panel
2.0-compliant
USB 2.0 USB 2.0 USB 2.0 USB 2.0 USB 2.0
DVD-ROM N/A 1 1 1 1 1
Hard Drives 1 HDD 3 HDD (RAID1+HS) 3 HDD (RAID1+HS) 3 HDD (RAID1+HS) 3 HDD (RAID1+HS) 3 HDD (RAID1+HS)
Environmental
CT-R CT-100 CT-1000 CT-2000 CT-4000 CT-10000
Specifications
Operating Temperature 5°C to 40°C (41°F 10°C to 35°C (50°F 10°C to 35°C (50°F 10°C to 35°C (50°F 10°C to 35°C (50°F 10°C to 35°C (50°F
to 104°F) to 95°F) at 10% to 95°F) at 10% to 95°F) at 10% to 95°F) at 10% to 95°F) at 10%
to 80% relative to 80% relative to 80% relative to 80% relative to 80% relative
humidity, 26°C humidity, 26°C humidity humidity humidity
max. dew point. max. dew point.
Storage Temperature 0°C to 70 °C (32°F –40°C to 65°C –40°C to 65°C –40°C to 65°C –40°C to 65°C –40°C to 65°C
to 158°F) (-40°F to 149°F) (-40°F to 149°F) (-40°F to 149°F) (-40°F to 149°F) (-40°F to 149°F)
with a max. temp. with a max. temp. with a max. temp. with a max. temp. with a max. temp.
gradation of 20°C gradation of 20°C gradation of 20°C gradation of 20°C gradation of 20°C
(68°F) per hour (68°F) per hour (68°F) per hour (68°F) per hour (68°F) per hour
Heat Dissipation (max) N/A 2891 BTU/Hr 2891 BTU/Hr 2891 BTU/Hr 2891 BTU/Hr 2891 BTU/Hr
Forescout Licensing and Sizing Guide 20
Humidity 20%-90% 20% to 80% (non- 20% to 80% (non- 10°C to 35°C (50°F 10°C to 35°C (50°F 10°C to 35°C (50°F
condensing) at condensing) at to 95°F) at 10% to 95°F) at 10% to 95°F) at 10%
a max. wet bulb a max. wet bulb to 80% relative to 80% relative to 80% relative
temp. of 29°C temp. of 29°C humidity (RH), humidity (RH), humidity (RH),
(84.2°F) (84.2°F) 26°C (78.8°F) 26°C (78.8°F) 26°C (78.8°F)
max. dew point max. dew point max. dew point
38.1cm x 30.48cm 84.18cm x 62.87cm 84.18cm x 62.87cm 84.18cm x 62.87cm 84.18cm x 62.87cm 84.18cm x 62.87cm
Shipment Package
x 16.51cm x 27.94cm (33.14” x x 27.94cm (33.14” x x 27.94cm (33.14” x x 27.94cm (33.14” x x 27.94cm (33.14” x
(length, width, height,
(15” x 12” x 6.5”) 24.75” x 11.0”) 24.75” x 11.0”) 24.75” x 11.0”) 24.75” x 11.0”) 24.75” x 11.0”)
weight)
5.9 lbs 61 lbs 61 lbs 61 lbs 61 lbs 61 lbs
*For CT-100 (rev-40 and below), specification updates for NetFlow and traffic monitoring are relevant starting with version 8.2.2.
In addition, starting with the 8.2.2 version, it is not recommended to run the eyeSegment module on these revisions. Also, exercise caution when deciding to run any eyeExtend modules or third-party
integrations that were not previously running. Appliance performance should be monitored via Appliance Resource Utilization Policy (part of health monitoring policies) to verify that the CT-100 or
CT-1000 appliance has not reached high resource utilization.
For details about Forescout health monitoring policies, refer to the Forescout Administration Guide.
Verify an appliance’s model and revision by running the Forescout CLI command fstool model. For details, refer to the Forescout CLI Commands Reference Guide.
Switch dedicated appliance max. managed switches3,6 5 25 300 500 1,000 1,500
Wireless dedicated appliance max. WLAN devices3 4 20 100 150 200 1,000
NetFlow max. flows per second 0 Up to 50,000 Up to 50,000 Up to 50,000 Up to 50,000 Up to 50,000
Forescout Licensing and Sizing Guide 21
eyeManage Performance
CEM-05 CEM-10 CEM-25 CEM-50
Specifications
Forescout Appliances 5 10 25 50
Network Ports–Copper (RJ-45) 10/100/1000 Mbps 10/100/1000 Mbps 10/100/1000 Mbps 10/100/1000 Mbps
I/O Support 1 serial port (DB9) 1 serial port (DB9) 1 serial port (DB9) 1 serial port (DB9)
2 back-panel, USB 2.0+ 1 2 back-panel USB 2.0 + 1 2 back-panel USB 2.0 + 1 2 back-panel USB 2.0 + 1
USB Ports
front-panel USB 2.0 front-panel USB 2.0 front-panel USB 2.0 front-panel USB 2.0
CD-ROM 1 1 1 1
Hard Drives 3 HDD (RAID-1+HS) 3 HDD (RAID-1+HS) 3 HDD (RAID-1+HS) 3 HDD (RAID-1+HS)
Power Supply 2 750W 100-240 VAC, 2 750W 100-240 VAC, 2 750W 100-240 VAC, 2 750W 100-240 VAC,
50~60Hz 50~60Hz 50~60Hz 50~60Hz
Operating Temperature 10°C to 35°C (50°F to 10°C to 35°C (50°F to 10°C to 35°C (50°F to 10°C to 35°C (50°F to
95°F) at 10% to 80% 95°F) at 10% to 80% 95°F) at 10% to 80% 95°F) at 10% to 80%
relative humidity, 26°C max. relative humidity, 26°C max. relative humidity relative humidity
dew point. dew point.
Storage Temperature –40°C to 65°C (-40°F to –40°C to 65°C (-40°F to –40°C to 65°C (-40°F to –40°C to 65°C (-40°F to
149°F) max. temp. gradation 149°F) max. temp. gradation 149°F) max. temp. gradation 149°F) max. temp. gradation
of 20°C per hour of 20°C per hour of 20°C per hour of 20°C per hour
Cooling Requirement 2891 BTU/Hr 2891 BTU/Hr 2891 BTU/Hr 2891 BTU/Hr
Forescout Licensing and Sizing Guide 22
Humidity 20% to 80% (non-condensing) 20% to 80% (non-condensing) 10°C to 35°C (50°F to 10°C to 35°C (50°F to
at a max. wet bulb temp. of at a max. wet bulb temp. of 95°F) at 10% to 80% relative 95°F) at 10% to 80% relative
29°C (84.2°F) 29°C (84.2°F) humidity humidity
Chassis 1U 19” rack mount 1U 19” rack mount 1U 19” rack mount 1U 19” rack mount
Appliance Dimensions (length, 70.05cm x 48.23cm x 4.28cm 70.05cm x 48.23cm x 4.28cm 70.05cm x 48.23cm x 4.28cm 70.05cm x 48.23cm x 4.28cm
width, height) (27.57” x 18.98” x 1.68”) (27.57” x 18.98” x 1.68”) (27.57” x 18.98” x 1.68”) (27.57” x 18.98” x 1.68”)
Shipment Package (length, width, 84.18cm x 62.87cm x 27.94cm 84.18cm x 62.87cm x 27.94cm 84.18cm x 62.87cm x 27.94cm 84.18cm x 62.87cm x 27.94cm
height, weight) (33.14” x 24.75” x 11.0”) (33.14” x 24.75” x 11.0”) (33.14” x 24.75” x 11.0”) (33.14” x 24.75” x 11.0”)
61 lbs 61 lbs 61 lbs 61 lbs
I/O Support 1 serial port (DB9) 1 serial port (DB9) 1 serial port (DB9)
2 back-panel, USB 2.0 + 1 front-panel 2 back-panel USB 2.0 + 1 front-panel 2 back-panel USB 2.0 + 1 front-panel
USB Ports
USB 2.0 USB 2.0 USB 2.0
CD-ROM 1 1 1
Power Supply 2 750W 100-240 VAC, 50~60Hz 2 750W 100-240 VAC, 50~60Hz 2 750W 100-240 VAC, 50~60Hz
Forescout Licensing and Sizing Guide 23
Operating Temperature 10°C to 35°C (50°F to 95°F) at 10°C to 35°C (50°F to 95°F) at 10°C to 35°C (50°F to 95°F) at
10% to 80% relative humidity 10% to 80% relative humidity 10% to 80% relative humidity
Storage Temperature –40°C to 65°C (-40°F to 149°F) with a –40°C to 65°C (-40°F to 149°F) with a –40°C to 65°C (-40°F to 149°F) with a
max. temp. gradation of 20°C per hour max. temp. gradation of 20°C per hour max. temp. gradation of 20°C per hour
10°C to 35°C at 10% to 80% relative 10°C to 35°C at 10% to 80% relative 10°C to 35°C at 10% to 80% relative
Humidity
humidity, 26°C (78.8°F) max. dew point humidity, 26°C (78.8°F) max. dew point humidity, 26°C (78.8°F) max. dew point
Chassis 1U 19” rack mount 1U 19” rack mount 1U 19” rack mount
Appliance Dimensions (length, width, 70.05cm x 48.23cm x 4.28cm 70.05cm x 48.23cm x 4.28cm 70.05cm x 48.23cm x 4.28cm
height) (27.57” x 18.98” 1.68”) (27.57” x 18.98” 1.68”) (27.57” x 18.98” 1.68”)
Shipment Package 96.52cm x 60.96cm x 28.58cm 96.52cm x 60.96cm x 28.58cm 96.52cm x 60.96cm x 28.58cm
(length, width, height, weight) (38.0” x 24.0” x 11.25”) (38.0” x 24.0” x 11.25”) (38.0” x 24.0” x 11.25”)
66 lbs 66 lbs 66 lbs
The maximum number of Forescout appliances that can be managed will vary based on several factors, including but not limited to network environment, product configuration and use cases.
Forescout Licensing and Sizing Guide 24
High Availability Throughput: Direct (cabled) connection 7 Mbps on TX (Transmit) 27.5 Mbps on TX 75 Mbps on TX
between appliance and HA appliance 1 Mbps on RX (Receive) 1.2 Mbps on RX 1 Mbps on RX
Network Throughput to eyeManage: Communication 82.7 Kbps on write (to EM) 122 Kbps on write (to EM) 206 Kbps on write (to EM)
between Forescout appliance and eyeManage (EM) appliance 1.8 Kbps on read (from EM) 2.88 Kbps on read (from EM) 1.5 Kbps on read (from EM)
Inter-Appliance Throughput (IAC): Communication between 4bps on average: numbers may differ on configuration change events
multiple Forescout appliances
MAC modulation
Total Bandwidth [in Bp/s] 388.7203 1135.404 2674.648 5004.851 7387.724 19078.59
• Latency: Even with very high MAC and ARP count the switch responded in the order of tens of milliseconds, on average 41ms.
• Test cycle: Up to 40 seconds with 10,000 MACs and 10,000 ARPs. Support for a 60-second polling rate is not recommended with additional entries or larger switches and
routers.
• Note on scale: A larger MAC or ARP table will consume more bandwidth but does not scale linearly with the number of entries.
[1] Forescout eyeExtend products are not included as part of the VM specification. In order to run eyeExtend products on virtual appliances, it is required to allocate more hardware resources to the VM depending on the product required and usage.
[2] Device count, as determined by Forescout appliance, is the number of devices known to the appliance by either their MAC address and/or their IP address. Devices may be detected by the appliance when on site or off site, or they may be made known to the
appliance via third-party integrations. A device may be counted more than once if it uses multiple IP addresses and/or multiple MAC addresses. Devices include user endpoints, network infrastructure devices, non-user devices and virtual machines.
Device information is retained in the appliance from initial discovery until such time the information is purged, based on aging preferences set in the product.
[3] Each Forescout appliance, physical or virtual, is licensed for a specified device count. However, the maximum number of devices manageable will vary based on several factors, including but not limited to network environment, product configuration and use
cases. It is recommended to manage the switch devices and the connected endpoints with the same appliance to achieve optimal performance. The recommended maximum number of switches that an appliance can manage assumes that 50 endpoints connect
to a switch on average. In cases where the average switch device has more endpoints connected to it, such as stacked switch devices, the overall number of managed switch devices will be lower (example: if the average switch device has 100 endpoints connected
to it, each switch device will be accounted as two switches).
[4] Performance shown in the table is for 802.1X EAP-TLS authentications without Fast Reconnect.
[5] The maximum bandwidth per E1000/ Hyper-V Network Adapter vNIC is 750Mb/s using 1G interface, and up to four (4) E1000/ Hyper-V Network Adapter vNICs are supported on a single virtual appliance to obtain 3Gb/s aggregate monitoring bandwidth. Support
for VMXNET3 interfaces is available for the VCT-2000/4000/10000: The maximum bandwidth per VMXNET3 vNIC is 1Gb/s using 10G interface, and up to two (2) VMXNET3 vNICs are supported on a single virtual appliance to obtain 2Gb/s aggregate monitoring
bandwidth. Support for Hyper-V Network Adapter is available for the VCT-2000/4000/10000: The maximum bandwidth per interface is 1.2Gb/s using a 10G interface, and up to three (3) Hyper-V Network Adapters are supported on a single virtual appliance to obtain
3.6Gb/s aggregate monitoring bandwidth. HTTP login is done by injecting HTTP redirect into an endpoint’s browser session and authenticating it using Active Directory.
[6] The appliance should be manually configured to a fixed number of subprocesses to work as a dedicated switch appliance. The number of subprocesses should be set to 10 for a small virtual appliance, to 15 for medium virtual appliance, to 20 for the large virtual
appliance and for the 5120 physical appliance and to 50 for the 5140/5160. The number of subprocesses should be set to 10 for VCT-100/VCT-1000, to 15 for VCT-2000/VCT-4000 to 20 for VCT- 10000. Instructions for configuring the number of subprocesses can
be found in the Switch Plugin manual, under section “Determining the Number of Sub-Processes to Run.”
[7] To avoid monitoring issues when using the Forescout appliance as both an OT Sensor and for traffic monitoring, do not configure the same port to perform both functions.
[8] This SFP option is not available for purchase through Forescout
[9] Forescout 8.2 is supported on the VCT-R.
[10] Copper ports are 10/100/1000 RJ-45. Fiber ports are 1Gb/s, 1000Base-SX SFP; Fiber 10G ports are 10Gb/s, 10Gbase-SR SFP+.
Forescout Technologies, Inc. Toll-Free (US) 1-866-377-8771 © 2021 Forescout Technologies, Inc. All rights reserved. Forescout Technologies, Inc. is a Delaware corporation. A list of our trademarks and patents is available at
190 West Tasman Drive Tel (Intl) +1-408-213-3191 https://www.Forescout.com/company/legal/intellectual-property-patents-trademarks. Other brands, products, or service names may be trademarks or service marks of their
San Jose, CA 95134 USA Support 1-708-237-6591 respective owners. Version 03_21