<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wrong HIP match in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrong-hip-match/m-p/460700#M2362</link>
    <description>&lt;P&gt;Hi team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope so you&amp;nbsp; all are doing great.&lt;/P&gt;&lt;P&gt;We are in the phase of implementing compliance checks based on HIP checks.&lt;/P&gt;&lt;P&gt;Before that we have created multiple HIP objects/profiles to observe our end users asset compliance and now we have asked our IT team to start installing compliance software in the end machine to avoid any issues when we fully provide access based on HIP checks.&lt;/P&gt;&lt;P&gt;We generate report of non-compliance machine (matching our non-compliance HIP profile) every week but I am observing something weird now, user who were matching non-compliance HIP checks earlier around 15days back&amp;nbsp; are not matching those HIP checks now. There is no config change or GP client change on the end machine. As the logs are purging in almost one week but for one user I saw in the HIP report every HIP check was there still it matched wrong HIP object and now it is matching everything perfectly.We can see similar issue for various other users also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My HIP checks are as follows-&lt;/P&gt;&lt;P&gt;Firstly the machine should be part of domain and secondly crowstrike should be installed.(Any version is fine).&lt;/P&gt;&lt;P&gt;Any machine not matching either of this criteria are posed as non-compliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are nearing the final stage of this project, it will be great if you guys have any inputs or faced such issue&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jan 2022 20:09:56 GMT</pubDate>
    <dc:creator>shubhamgupta</dc:creator>
    <dc:date>2022-01-24T20:09:56Z</dc:date>
    <item>
      <title>Wrong HIP match</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrong-hip-match/m-p/460700#M2362</link>
      <description>&lt;P&gt;Hi team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope so you&amp;nbsp; all are doing great.&lt;/P&gt;&lt;P&gt;We are in the phase of implementing compliance checks based on HIP checks.&lt;/P&gt;&lt;P&gt;Before that we have created multiple HIP objects/profiles to observe our end users asset compliance and now we have asked our IT team to start installing compliance software in the end machine to avoid any issues when we fully provide access based on HIP checks.&lt;/P&gt;&lt;P&gt;We generate report of non-compliance machine (matching our non-compliance HIP profile) every week but I am observing something weird now, user who were matching non-compliance HIP checks earlier around 15days back&amp;nbsp; are not matching those HIP checks now. There is no config change or GP client change on the end machine. As the logs are purging in almost one week but for one user I saw in the HIP report every HIP check was there still it matched wrong HIP object and now it is matching everything perfectly.We can see similar issue for various other users also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My HIP checks are as follows-&lt;/P&gt;&lt;P&gt;Firstly the machine should be part of domain and secondly crowstrike should be installed.(Any version is fine).&lt;/P&gt;&lt;P&gt;Any machine not matching either of this criteria are posed as non-compliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are nearing the final stage of this project, it will be great if you guys have any inputs or faced such issue&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 20:09:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrong-hip-match/m-p/460700#M2362</guid>
      <dc:creator>shubhamgupta</dc:creator>
      <dc:date>2022-01-24T20:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Wrong HIP match</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrong-hip-match/m-p/460705#M2363</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/193747"&gt;@shubhamgupta&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;There's not a whole lot of information included in your post to actually assist with troubleshooting to be honest. What sort of things are you actually checking with your HIP Objects, how is the HIP Profile actually structured, is non-compliance just checking updates that maybe got installed since the last time an endpoint was recorded as non-compliant?&lt;/P&gt;
&lt;P&gt;You don't really say what you're looking at outside of the fact that a few weeks ago an endpoint was matching the non-compliance profile and now it isn't. Depending on what what the non-compliance profile HIP Objects actually check that wouldn't necessarily be an unexpected thing to change. For example if I'm ensuring Windows updates are installed someone maybe just finally got around to installing the updates so they are in compliance again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 20:03:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrong-hip-match/m-p/460705#M2363</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-01-24T20:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Wrong HIP match</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrong-hip-match/m-p/460708#M2364</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firstly,thanks for your response and secondly my bad for posting it not informative.&lt;/P&gt;&lt;P&gt;Actually we have kept two checks- firstly the machine should be part of domain and secondly crowstrike should be installed.(Any version is fine).&lt;/P&gt;&lt;P&gt;Any machine not matching either of this criteria are posed as non-compliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 20:07:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrong-hip-match/m-p/460708#M2364</guid>
      <dc:creator>shubhamgupta</dc:creator>
      <dc:date>2022-01-24T20:07:43Z</dc:date>
    </item>
  </channel>
</rss>

