<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HIPS to prevent windows 7 clients in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533714#M3763</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/213555"&gt;@Stevenjw0728&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you apply a HIP Profile to a security policy rule, then the clients must match the HIP Profile to match the rule.&amp;nbsp; You can create the profiles 1st and check matches under Monitor &amp;gt; HIP Match before applying them to a policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think Windows 7 will match all Windows 7 flavors.&amp;nbsp; The best way to find out is create it and see who matches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Thu, 09 Mar 2023 01:41:45 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-03-09T01:41:45Z</dc:date>
    <item>
      <title>HIPS to prevent windows 7 clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533199#M3752</link>
      <description>&lt;P&gt;How would I go about creating a HIPS profile that would deny access to machines running windows 7 that need to connect to global protect?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 20:29:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533199#M3752</guid>
      <dc:creator>Stevenjw0728</dc:creator>
      <dc:date>2023-03-03T20:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS to prevent windows 7 clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533349#M3755</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/213555"&gt;@Stevenjw0728&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are the steps to use HIP in the security policy -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/host-information/configure-hip-based-policy-enforcement" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/host-information/configure-hip-based-policy-enforcement&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You would create a separate HIP Object like the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1678118606686.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48481i9861CB1CD8D9DDA9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1678118606686.png" alt="TomYoung_0-1678118606686.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Put it in a HIP Profile named Windows 7.&amp;nbsp; Add the Windows 7 HIP Profile as a source to a security policy rule and deny traffic except optionally to a remediation server.&amp;nbsp; GlobalProtect will not disconnect, but you can configure a GlobalProtect message under Gateway &amp;gt; Agent &amp;gt; HIP Notification.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 16:35:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533349#M3755</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-03-06T16:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS to prevent windows 7 clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533696#M3761</link>
      <description>&lt;P&gt;I created an object for all versions of windows, attached it to a profile, then assigned that profile to a rule that was VPN clients to Trust networks and it took everyone down.....why? Shouldn't it just be collecting data?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 22:59:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533696#M3761</guid>
      <dc:creator>Stevenjw0728</dc:creator>
      <dc:date>2023-03-08T22:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS to prevent windows 7 clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533706#M3762</link>
      <description>&lt;P&gt;When you select OS contains Windows 7, does that cover all the editions of Windows 7?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 00:07:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533706#M3762</guid>
      <dc:creator>Stevenjw0728</dc:creator>
      <dc:date>2023-03-09T00:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS to prevent windows 7 clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533714#M3763</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/213555"&gt;@Stevenjw0728&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you apply a HIP Profile to a security policy rule, then the clients must match the HIP Profile to match the rule.&amp;nbsp; You can create the profiles 1st and check matches under Monitor &amp;gt; HIP Match before applying them to a policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think Windows 7 will match all Windows 7 flavors.&amp;nbsp; The best way to find out is create it and see who matches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 01:41:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533714#M3763</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-03-09T01:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS to prevent windows 7 clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533784#M3769</link>
      <description>&lt;P&gt;if my profile was to include all windows 7, windows 10, and windows 11, why did all my traffic stop?!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 15:32:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533784#M3769</guid>
      <dc:creator>Stevenjw0728</dc:creator>
      <dc:date>2023-03-09T15:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS to prevent windows 7 clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533791#M3770</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/213555"&gt;@Stevenjw0728&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You would need to check the logic in the profile.&amp;nbsp; Maybe it was a logical AND and devices can't be all 3 at the same time?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 15:46:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533791#M3770</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-03-09T15:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS to prevent windows 7 clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533793#M3771</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/213555"&gt;@Stevenjw0728&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;How did you build out the profile and what did you actually want it to do? If you included every OS in the profile and denied access through the security policy, the firewall did what you told it to do. If you're just trying to prevent Windows 7 clients from connecting, include only the Windows 7 HIP-Object in the associated profile and make a Deny entry. You wouldn't want to group everything together in some overarching allow entry.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As to why your traffic stop flowing, did you give any time between the creation of the HIP-Object/Profile and putting it into effect on the security rulebase at the same time? Generally speaking whenever you build out a new Object/Profile, you're going to want to validate using the HIP logs that it's actually matching clients as expected before you ever include it in a policy. That ensures that your order of operations is actually correct, and it ensures that the clients active at the moment actually have time to send the update in their next HIP report.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 15:50:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533793#M3771</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-03-09T15:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS to prevent windows 7 clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533799#M3773</link>
      <description>&lt;P&gt;Well dang it. Missed that. I thought when you add it to a profile its like "hey any of these match your good" so that was indeed the issue, radio button for AND was checked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 16:21:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hips-to-prevent-windows-7-clients/m-p/533799#M3773</guid>
      <dc:creator>Stevenjw0728</dc:creator>
      <dc:date>2023-03-09T16:21:55Z</dc:date>
    </item>
  </channel>
</rss>

