<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows Update HIP Check in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows-update-hip-check/m-p/527449#M3596</link>
    <description>&lt;P&gt;i saw another user is having pretty much the same problem as me, but her post was over a year ago. was hoping some other users might have had the same problem as me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here's the original post:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/td-p/449066" target="_blank"&gt;https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/td-p/449066&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;essentially what we would like to do is....&lt;/P&gt;
&lt;P&gt;1, check our VPN users to make sure they have Windows Update enabled&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;OR&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;2, check our VPN users to make sure they don't have any severity 3 patches not installed. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for option 1 i tried to configure the HIP check like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wcoulson_1-1673983372475.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47142iD5E5E07BDDEEE7F7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="wcoulson_1-1673983372475.png" alt="wcoulson_1-1673983372475.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for option 2 i tried to configure the HIP check like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wcoulson_2-1673983424218.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47143i5C964F14C5DF7D9D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="wcoulson_2-1673983424218.png" alt="wcoulson_2-1673983424218.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it doesn't seem to matter what options i check under patch management, the PC always fails the check for windows update.&lt;/P&gt;
&lt;P&gt;what am i missing or what do i have configured wrong?&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jan 2023 19:24:24 GMT</pubDate>
    <dc:creator>wcoulson</dc:creator>
    <dc:date>2023-01-17T19:24:24Z</dc:date>
    <item>
      <title>Windows Update HIP Check</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows-update-hip-check/m-p/527449#M3596</link>
      <description>&lt;P&gt;i saw another user is having pretty much the same problem as me, but her post was over a year ago. was hoping some other users might have had the same problem as me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here's the original post:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/td-p/449066" target="_blank"&gt;https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/td-p/449066&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;essentially what we would like to do is....&lt;/P&gt;
&lt;P&gt;1, check our VPN users to make sure they have Windows Update enabled&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;OR&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;2, check our VPN users to make sure they don't have any severity 3 patches not installed. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for option 1 i tried to configure the HIP check like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wcoulson_1-1673983372475.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47142iD5E5E07BDDEEE7F7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="wcoulson_1-1673983372475.png" alt="wcoulson_1-1673983372475.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for option 2 i tried to configure the HIP check like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wcoulson_2-1673983424218.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47143i5C964F14C5DF7D9D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="wcoulson_2-1673983424218.png" alt="wcoulson_2-1673983424218.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it doesn't seem to matter what options i check under patch management, the PC always fails the check for windows update.&lt;/P&gt;
&lt;P&gt;what am i missing or what do i have configured wrong?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 19:24:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows-update-hip-check/m-p/527449#M3596</guid>
      <dc:creator>wcoulson</dc:creator>
      <dc:date>2023-01-17T19:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Update HIP Check</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows-update-hip-check/m-p/527551#M3599</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/267540"&gt;@wcoulson&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I would confess I don't have real experience with patch management HIP check, but I could suggest the following:&lt;/P&gt;
&lt;P&gt;- Can you confirm your GP portal agent config is configured to collect patch management information? Patch management is not excluded here&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1674050081793.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47158i38A3D2F80C3BB653/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1674050081793.png" alt="Astardzhiev_0-1674050081793.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;- From documentation is says "Check —Match on whether the endpoint &lt;U&gt;has missing&lt;/U&gt; patches." - &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/globalprotect/objects-globalprotect-hip-objects/hip-objects-patch-management-tab" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/globalprotect/objects-globalprotect-hip-objects/hip-objects-patch-management-tab&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So my understanding is that "has-any" means has any missing patch. And if I understand your first case you want this object to match a machine with all patches installed. Based on that I believe you need to use "has-none" - which should means "has none missing patches = has all patches"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Second screenshot seems OK - should match if not severity 3 patches are missing, but you haven't specify patch management vendor. I am not sure if this could be a problem but you can try to add it the same way as your first hip object.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you checked how the HIP report looks like (the same way from the screenshot from the other post)? You can either check from GP client (setting -&amp;gt; Host Profile) or from FW cli &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClshCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClshCAC&lt;/A&gt; but this will be raw XML and GUI should be easier to read.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 14:17:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows-update-hip-check/m-p/527551#M3599</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-01-18T14:17:11Z</dc:date>
    </item>
  </channel>
</rss>

