ForeScout Technologies CounterACT 6.3.4

Network access control (NAC) products are often seen as expensive and difficult to deploy. ForeScout's CounterACT claims to be anything but and in this review Dave Mitchell tests this latest virtual appliance.


Compliancy policies check systems to ensure they have required components such as specific anti-virus software products. These can also check for apps such as IM and P2P and the policy can be set to terminate the program if the user tries loading them.

Mobile devices are on CounterACT's radar as it can manage products such as iPhones and iPads as well as Blackberry, Android and Windows Mobile smartphones. It can query the device and use policies to manage usage. For greater control ForeScout is now developing agents for them with an Android agent already available.

Policy creation is wizard driven and these can be used to check on required software products and apply a range of actions to

Although Windows clients that are part of an AD domain can have network access controlled without an agent, there are a number of circumstances where it is required. CounterACT can restrict access to external devices such as USB storage but needs the SecureConnector agent loaded which can be easily downloaded from a self-service portal or pushed out via a policy.

With this agent installed on a Windows 7 test client we created a policy to block all access to USB storage devices. When we inserted a flash drive the agent promptly blocked access. We also created policies that terminated IM and P2P apps - when we loaded Windows Live Messenger and a BitTorrent client, the SecureConnector agent closed them both down immediately.

Advertisement - Article continues below
Advertisement - Article continues below

ForeScout's CounterACT is a good choice for businesses that don't want to make any major changes to their networks to accommodate a NAC solution. CounterACT is comparatively good value and we found the new virtual appliance version easy to deploy and capable of providing strong policy-based network security and access controls.

So what's our verdict?


Compared with many NAC products, we found CounterACT easy to deploy and, apart from setting up switch span ports, requires no major changes to the existing network infrastructure. Its policy-based security makes it very versatile allowing administrators to provide controlled, secure network access to managed, unmanaged and guest systems as they attempt to join the network.

Operating System: VMware ESX/ESXi 3.5 and above

Memory: 1.5GB

Hard disk: 80GB free space

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now

Most Popular

identity and access management (IAM)

44 million Microsoft customers found using compromised passwords

6 Dec 2019
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019

Five signs that it’s time to retire IT kit

29 Nov 2019

Where modernisation and sustainability meet: A tale of two benefits

25 Nov 2019