<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect quarantine in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-quarantine/m-p/506095#M2922</link>
    <description>&lt;P&gt;I am in the process of setting up HIP objects and profiles with the end result being a quarantine for devices that do not match for AV software and definitions along with Windows patch levels. I want to be able to automatically quarantine a device to allow it internet only so the user can fix the issue. I then want the device to be allowed back onto our network once the issue is fixed. I know I can automatically quarantine a device based on HIP objects and profiles but I can't figure out how to remove the device automatically from quarantine once it does match a HIP object and profile.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jun 2022 20:49:19 GMT</pubDate>
    <dc:creator>nikkikole</dc:creator>
    <dc:date>2022-06-24T20:49:19Z</dc:date>
    <item>
      <title>GlobalProtect quarantine</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-quarantine/m-p/506095#M2922</link>
      <description>&lt;P&gt;I am in the process of setting up HIP objects and profiles with the end result being a quarantine for devices that do not match for AV software and definitions along with Windows patch levels. I want to be able to automatically quarantine a device to allow it internet only so the user can fix the issue. I then want the device to be allowed back onto our network once the issue is fixed. I know I can automatically quarantine a device based on HIP objects and profiles but I can't figure out how to remove the device automatically from quarantine once it does match a HIP object and profile.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 20:49:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-quarantine/m-p/506095#M2922</guid>
      <dc:creator>nikkikole</dc:creator>
      <dc:date>2022-06-24T20:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect quarantine</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-quarantine/m-p/506161#M2924</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183664"&gt;@nikkikole&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Using the quarantine feature for this actually&amp;nbsp;&lt;EM&gt;isn't&amp;nbsp;&lt;/EM&gt;what I would personally recommend. Rather than quarantine the device, why not create security rulebase entries around a corresponding HIP-Profile? Use the HIP Notification to alert the end-user that they have been restricted from accessing internal resources and why, and then use the HIP-Profile in the security rulebase to restrict matching endpoints from accessing internal resources and only allow them access to the internet. That way, as soon as the issue is corrected they can just re-submit their HIP data and the firewall will automatically start allowing traffic again once they no longer match the HIP Profile.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you use the Device Quarantine feature, the firewall won't automatically remove these entries once the issue has been fixed. You'd have to build out a remediation detection method and script the automated removal yourself. Quarantine is really meant for a compromised endpoint, I'd use HIP Profiles for "minor" correctable infractions like failing an AV check.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2022 03:05:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-quarantine/m-p/506161#M2924</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-06-25T03:05:14Z</dc:date>
    </item>
  </channel>
</rss>

