ForeScout CounterACT Review

Make sure to plan for all endpoints. If you want full coverage of your networks, account for anything that has an IP

Valuable Features

Endpoint visibility, policy flexibility, compatibility and integration with other products.

Improvements to My Organization

Automation! One broad example is that we can now stop network threats right away and without intervention.

Room for Improvement

Forescout is constantly adding new features, so this may change as of this writing, but sometimes the switch management interface doesn't display accurate information which relates to false positives on individual switch access errors.

Use of Solution

1 year

Deployment Issues

None that were Forescout related. CounterACT always opens a bunch of little IP sessions with endpoints, ake sure you have a large enough connection table on your firewall if you plan to put it behind one.

Stability Issues

Minor. Had to reinstall one virtual appliance, which is painless when you have an Enterprise Manager.

Scalability Issues

No, this is one of the products strengths.

Customer Service and Technical Support

Customer Service:

10 out of 10. Very responsive and address concerns quickly.

Technical Support:

9 out of 10. Really fast response, high level of competency.

Previous Solutions

I switched from Cisco NAC because it is reliant on 802.1X, and has no other function than to ensure endpoints have authenticated via your method of choice.

Initial Setup

Straightforward. Setup is simple with a solid, pre-defined set of policies that you build on and customize as you learn.

Implementation Team

In house.


Without access specific numbers, we now have the ability to instantly shut down internal malicious hosts or traffic, refuse or restrict access to non-compliant hosts, discover risks on the network we didn't know were there, and automate the remediation of a multitude of security risks. As I work for an organization that spends a lot on security administration, at a minimum, the cost savings must have already paid for the product.

Other Solutions Considered

Palo Alto

Other Advice

Make sure to plan for all endpoints. If you want full coverage of your networks, account for anything that has an IP address. For example, a busy core switch can have 20+ IP addresses, and each one goes against your license count. Also, if you plan to have it behind a firewall, take into consideration your firewall's connection limitations. Although CounterACT isn't really a heavy bandwidth user, it does open a ton of short connections on a constant basis. The more you tune these down, the less accurate your real time host information becomes.

Disclosure: My company has a business relationship with this vendor other than being a customer: I currently work as a Solution Architect for ForeScout, but I wrote this review when I was a customer.
2 visitors found this review helpful
1 Comment
Vandy VaReal UserTOP 20

Technology improved network security via access layer L2.

18 June 15
Sign Up with Email