<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can i apply different HIP Policy for external users? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-can-i-apply-different-hip-policy-for-external-users/m-p/556666#M4362</link>
    <description>&lt;P&gt;It has become even more complex.&lt;BR /&gt;I have 5 groups: software, dba, external, internal, etc...&lt;BR /&gt;I can create a lot of HIP profiles, that's not a problem, but I'm stuck on how to apply them targeting these groups. This part is currently confusing me.&lt;BR /&gt;GP &amp;gt; GW &amp;gt; agent &amp;gt; client settings, here I have 5 user types and integration with Office 365 for login authentication. Can I apply it from here? It's possible? I guess no.&lt;/P&gt;
&lt;P&gt;Can I only add them from the device section within the firewall access rules? Is there any other option? I'm using version 11.&lt;/P&gt;
&lt;P&gt;Company's computer feature: joined domain, company av, company dlp, generic hostname External comp. they have not same feature, you know..&lt;/P&gt;
&lt;P&gt;What's is your advice now?&lt;BR /&gt;thanks for your interest&lt;/P&gt;</description>
    <pubDate>Wed, 06 Sep 2023 05:53:42 GMT</pubDate>
    <dc:creator>omertaskin</dc:creator>
    <dc:date>2023-09-06T05:53:42Z</dc:date>
    <item>
      <title>How can i apply different HIP Policy for external users?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-can-i-apply-different-hip-policy-for-external-users/m-p/556498#M4357</link>
      <description>&lt;P&gt;Hello Dear Community,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I have 2 SSL VPN rules assigned to my username in Palo Alto firewall. For testing purposes, I added a HIP profile to only one of them. The device I tested does not comply with the HIP profile.&lt;/P&gt;
&lt;P&gt;The VPN connection is notifyed as failed. The rule to which I applied the HIP Profile is not working because the computer I'm using does not comply with the HIP profile.&lt;BR /&gt;That's OK&lt;/P&gt;
&lt;P&gt;I believe that the VPN connection should not be established since the computer does not comply with the HIP profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I did some research, they told me that I should apply the HIP profile to the SSLVPN WAN rule. However, it's not possible for me to apply the same policy to consultants/external users. What should I do exactly here?&lt;/P&gt;
&lt;P&gt;Do I need a new VPN Gateway? Or should I add a new WAN rule and apply HIP to it? Please enlighten me in simple terms.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 12:05:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-can-i-apply-different-hip-policy-for-external-users/m-p/556498#M4357</guid>
      <dc:creator>omertaskin</dc:creator>
      <dc:date>2023-09-05T12:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: How can i apply different HIP Policy for external users?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-can-i-apply-different-hip-policy-for-external-users/m-p/556517#M4358</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/313676"&gt;@omertaskin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If you wanted to use a HIP Profile on one of your security entries for corporate users and not for consultant or external users, you would simply build the security entry targeting the specific group of users. So as an example of all internal users were in a group called 'Internal-Users' and everyone else was in a group called 'Consultants', you would simply build a rule for each group. In the 'Internal-Users' group you would include the HIP-profile that you wish to target so that anyone matching that HIP profile hits the rule in question. Then with the 'Consultants' group you would simply not include that HIP-profile as match criteria.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 12:57:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-can-i-apply-different-hip-policy-for-external-users/m-p/556517#M4358</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-09-05T12:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: How can i apply different HIP Policy for external users?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-can-i-apply-different-hip-policy-for-external-users/m-p/556666#M4362</link>
      <description>&lt;P&gt;It has become even more complex.&lt;BR /&gt;I have 5 groups: software, dba, external, internal, etc...&lt;BR /&gt;I can create a lot of HIP profiles, that's not a problem, but I'm stuck on how to apply them targeting these groups. This part is currently confusing me.&lt;BR /&gt;GP &amp;gt; GW &amp;gt; agent &amp;gt; client settings, here I have 5 user types and integration with Office 365 for login authentication. Can I apply it from here? It's possible? I guess no.&lt;/P&gt;
&lt;P&gt;Can I only add them from the device section within the firewall access rules? Is there any other option? I'm using version 11.&lt;/P&gt;
&lt;P&gt;Company's computer feature: joined domain, company av, company dlp, generic hostname External comp. they have not same feature, you know..&lt;/P&gt;
&lt;P&gt;What's is your advice now?&lt;BR /&gt;thanks for your interest&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 05:53:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-can-i-apply-different-hip-policy-for-external-users/m-p/556666#M4362</guid>
      <dc:creator>omertaskin</dc:creator>
      <dc:date>2023-09-06T05:53:42Z</dc:date>
    </item>
  </channel>
</rss>

