<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trouble with HIP checks for Anti-Malware in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/trouble-with-hip-checks-for-anti-malware/m-p/410747#M1387</link>
    <description>&lt;P&gt;Thanks for your reply!&lt;BR /&gt;Indeed - the PA220 is running 10.0.3, and the PA820 is running 10.0.4 (I know, the PA220 should be the one "on the bleeding edge-SW", rather than the PA820, but haven't found a fitting moment for it yet.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Jun 2021 07:58:26 GMT</pubDate>
    <dc:creator>pasmartin</dc:creator>
    <dc:date>2021-06-03T07:58:26Z</dc:date>
    <item>
      <title>Trouble with HIP checks for Anti-Malware</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/trouble-with-hip-checks-for-anti-malware/m-p/409550#M1331</link>
      <description>&lt;P&gt;Hi Community!&lt;BR /&gt;&lt;BR /&gt;I have some issues getting HIP checks to work on a PA820.&lt;BR /&gt;Have configured a couple Objects that checks whether the Cortex XDR agent or Windows Defender is installed/enabled&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pasmartin_0-1622111654042.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34107i850E21A80855C448/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="pasmartin_0-1622111654042.png" alt="pasmartin_0-1622111654042.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pasmartin_1-1622111671636.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34108i2F606A2569D5CDFA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="pasmartin_1-1622111671636.png" alt="pasmartin_1-1622111671636.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And have them added to a profile that I have added to the GlobalProtect Gateway.&lt;/P&gt;&lt;P&gt;This seems to be working fine on a LAB-PA220 - triggers whenever Cortex XDR is not found, or if Defender is turned off. Verified on three separate devices (VM running Windows 10, Laptop running Windows 10, VM running server 2016).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;On the PA820 however, users get the "Not Match Message" regardless of Cortex XDR / Defender status.&lt;/P&gt;&lt;P&gt;The funny part is that on the test machines mentioned above, I'm unable to reproduce the issues my coworkers are seeing. HIP works as intended.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Anyone know what could cause this behavior? My guess is that this is due to some local issues on Windows - but could there also be some issues where the firewalls (in general, or PA820 specifically?) are unable to get the the Host Information for some reason?&lt;BR /&gt;&lt;BR /&gt;Appreciate any help!&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 10:50:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/trouble-with-hip-checks-for-anti-malware/m-p/409550#M1331</guid>
      <dc:creator>pasmartin</dc:creator>
      <dc:date>2021-05-27T10:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble with HIP checks for Anti-Malware</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/trouble-with-hip-checks-for-anti-malware/m-p/410684#M1386</link>
      <description>&lt;P&gt;It is strange that it acts differently on the 2 different devices, as it should act the same on both.&lt;/P&gt;
&lt;P&gt;Do you mind letting us know what PAN-OS version is running on those 2 devices?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 20:02:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/trouble-with-hip-checks-for-anti-malware/m-p/410684#M1386</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-06-02T20:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble with HIP checks for Anti-Malware</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/trouble-with-hip-checks-for-anti-malware/m-p/410747#M1387</link>
      <description>&lt;P&gt;Thanks for your reply!&lt;BR /&gt;Indeed - the PA220 is running 10.0.3, and the PA820 is running 10.0.4 (I know, the PA220 should be the one "on the bleeding edge-SW", rather than the PA820, but haven't found a fitting moment for it yet.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 07:58:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/trouble-with-hip-checks-for-anti-malware/m-p/410747#M1387</guid>
      <dc:creator>pasmartin</dc:creator>
      <dc:date>2021-06-03T07:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble with HIP checks for Anti-Malware</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/trouble-with-hip-checks-for-anti-malware/m-p/411001#M1391</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34042"&gt;@pasmartin&lt;/a&gt;&amp;nbsp;Thanks for the PAN-OS versions..&amp;nbsp; I was thinking it would be drastically different..&amp;nbsp; So that isn't it, or don't think so.. other than ensuring the versions match..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What about dynamic updates versions? between the 2 devices?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 19:58:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/trouble-with-hip-checks-for-anti-malware/m-p/411001#M1391</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-06-03T19:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble with HIP checks for Anti-Malware</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/trouble-with-hip-checks-for-anti-malware/m-p/411094#M1394</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp;Oh snap - the PA220 had no check or action for antivirus - but other than that, they are configured the same for app&amp;amp;threat, wildfire are on the same versions.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 06:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/trouble-with-hip-checks-for-anti-malware/m-p/411094#M1394</guid>
      <dc:creator>pasmartin</dc:creator>
      <dc:date>2021-06-04T06:25:56Z</dc:date>
    </item>
  </channel>
</rss>

