ForeScout CounterACT backs up other tools
When Chad Clement joined worldwide office furniture maker Haworth 18 months ago, he discovered the company needed to get a handle on network security.
Part of the problem was that Haworth didn’t have an accurate inventory of the 12,000 devices on the network, which spans 80 sites worldwide, and that even with configuration management tools in place, some devices didn’t meet corporate configuration standards.
As the company’s new information security manager, Clement also wanted to deploy an intrusion detection system (IDS) so he would know when the company’s valuable data-center assets were being compromised.
A data-security assessment commissioned before he got there found cracks in the company’s defenses, including endpoint integrity. “We wanted to make sure that all the hosts in our environment belonged in our environment, as well as had a standardized configuration on them – that the antivirus was our standard antivirus and that it was up to date,” Clement says.
The company already had Shavlik NetChk management and configuration software for servers and Symantec’s Altiris client management for desktops, but they didn’t catch everything. “Machines got missed,” he says. “A lot of times it was that the agent wasn’t running on them to inform users that they needed to get their updates.”
Also in use on the network were Qualys vulnerability management and BMC Remedy service management software, and he thought he could make better use of them as well.
The security-assessment consultant had used ForeScout’s CounterACT NAC gear to help discover devices on the Haworth network for its report. Clement says that capability plus its IDS features and the ability to assess compliance with corporate endpoint configuration standards interested him in the ForeScout appliance.
He also considered StillSecure, but after trying out a simulation of it online he decided he liked the ForeScout interface better and the visibility that it gave him.
The fact that the CounterACT platform integrates with the BMC Remedy service-management software influenced him, too. The firm uses BMC Remedy as a way to track trouble tickets, and CounterACT can work with it to automatically open tickets when endpoints are found out of compliance with corporate configuration standards.
“But the goal with the Remedy plug-in is, when they’re out of compliance, automatically create a Remedy ticket to have the issue resolved,” he says. That integration is on hold at the moment, though, because the company is upgrading its Remedy deployment.
CounterACT also integrates with the Qualys vulnerability management software to share what it discovers about endpoint configurations.
One factor that strongly influenced his choice was that CounterACT requires no permanent software on endpoints. “That was one of my key criteria. I didn’t what to throw another agent on all of our machines because we already had the antivirus agent running on them and the patch-management agent running on them,” he says.
The company deployed one CounterACT box in its Holland, Mich., data center where it checked that devices attempting to gain access behaved properly by using the device’s IDS capabilities. Since then it has deployed seven more.
So far the company does not use them to ensure that endpoints comply with configuration policies. Rather it monitors and notifies, because he doesn’t want the enforcement to get in the way of people doing work. “I want it to have as minimal an impact on our users as possible, so we put it in discovery mode,” he says.
Clement is just now considering turning on enforcement mode. “We’re taking our time with it making sure our asset classification policies are working accurately so I can minimize the amount of false positives,” he says.
He wants to be sure appropriate policies are being applied. For instance, manufacturing controllers on the network have no antivirus software, so he didn’t want to risk blocking one from the network for failure to comply with the antivirus policy. “I wouldn’t want to take a controller down and stop production,” he says.
Clement hasn’t yet discussed with the IT team whether to turn on self-remediation where noncompliant endpoints would be forced to a portal where users would be instructed how to bring their machines into compliance.
Ultimately, he wants to check all endpoints on the LAN and all devices connecting via VPN as well as the corporate or guest wireless networks.
Guests are allowed on to Cisco wireless access points that broadcast separate SSIDs. Guests are allowed access to one of those SSIDs that tunnels all the traffic to the corporate DMZ, and they can access only the Internet.
Traffic through the Cisco VPN concentrators on the network is being monitored via a CounterACT VPN plug-in that allows authentication to be proxied to the NAC device, which then interrogates the endpoint.
Despite being a Cisco shop, Haworth decided against Cisco NAC. “I am the security team here, so I was looking for something that was easy to manage, and ForeScout gave me that,” Clement says. “My personal preference is to go with vendors that are security-centric because I feel I can give a lot more input and see results.”
The company is also a Microsoft shop, but he has not looked at network access protection (NAP), Microsoft’s flavor of NAC.
The device has afforded unexpected utility. In an attempt to locate a missing laptop, he created a rule that anytime its computer name or MAC address was found by the NAC device, it would notify Clement. The lost computer never showed up, but he would have been told if it had.
In another case, to facilitate an investigation, he needed to know when a particular device connected to the network so forensic data could be downloaded from it. He used the CounterACT to notify him so he could have a forensics engineer collect evidence he needed.
The device can also tell what switch and port a device is plugged into, and he’s going to let the help desk have access to that data via the ForeScout asset portal in order to help troubleshoot and resolve endpoint problems. “It’s another tool to give visibility to what’s going on,” he says.




