<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use HIPS to assign Gateway IP Address for external clients in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/use-hips-to-assign-gateway-ip-address-for-external-clients/m-p/580460#M5130</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/258249"&gt;@BenBrazil&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you mentioned, HIP is not available under the gateway Config Selection Criteria.&amp;nbsp; The bigger question is "What do you want to use the different IP pools to accomplish?"&amp;nbsp; If those different pools will be used in different security policy rules, then use the HIP Profiles in the rules instead of the IP pools.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Fri, 15 Mar 2024 02:05:14 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-03-15T02:05:14Z</dc:date>
    <item>
      <title>Use HIPS to assign Gateway IP Address for external clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/use-hips-to-assign-gateway-ip-address-for-external-clients/m-p/580234#M5123</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am looking at how to assign different IP Pool addresses to clients based on a HIPS check.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are currently achieving this by assigning a different IP Pool to users based on user group membership of an Active Directory group. When the client authenticates with the Gateway, it receives a Pre-logon IP Address - lets call this an IP Address in Pool A. We want the majority of the client machines to have an IP Address in Pool A, so when the user logs into their client, they continue to use that same IP Address.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The clients that we want to have an IP Address in Pool B, initially receive an IP Address in Pool A as it is received in the pre-logon phase. When the user logs in, the Gateway configuration evaluates AD group membership and will assign an IP Address in Pool B as long as the PANGPS service is restarted and the client reauthenticates with the Gateway. This is somewhat convoluted but works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd now like to change the way this has been implemented to use HIPS so that the client, depending on the HIPS check will either receive an IP address from Pool A or from Pool B at the pre-logon stage. From what I've been reading it looks like I would do the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The HIPS evaluation on the client is going to be based on a registry key, so I would create a HIP Data Collection custom registry check on the pre-logon Agent configuration on the Portal.&lt;/LI&gt;
&lt;LI&gt;Create a HIPS Object&lt;/LI&gt;
&lt;LI&gt;Create a HIPS Profile&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Is it then possible to use the HIPS configuration as the selection criteria to allocate an IP Address from IP Pool B? In the Gateway configuration for the agent, the only selection criteria options are based on Source User, OS, Source Address or IP Address. It doesn't appear to be obvious how to use the HIPS profile as a selection criteria to allocate an IP Pool.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestions would be appreciated.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 15:40:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/use-hips-to-assign-gateway-ip-address-for-external-clients/m-p/580234#M5123</guid>
      <dc:creator>BenBrazil</dc:creator>
      <dc:date>2024-03-13T15:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Use HIPS to assign Gateway IP Address for external clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/use-hips-to-assign-gateway-ip-address-for-external-clients/m-p/580460#M5130</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/258249"&gt;@BenBrazil&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you mentioned, HIP is not available under the gateway Config Selection Criteria.&amp;nbsp; The bigger question is "What do you want to use the different IP pools to accomplish?"&amp;nbsp; If those different pools will be used in different security policy rules, then use the HIP Profiles in the rules instead of the IP pools.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 02:05:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/use-hips-to-assign-gateway-ip-address-for-external-clients/m-p/580460#M5130</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-03-15T02:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Use HIPS to assign Gateway IP Address for external clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/use-hips-to-assign-gateway-ip-address-for-external-clients/m-p/580758#M5149</link>
      <description>&lt;P&gt;Thanks Tom,&lt;/P&gt;
&lt;P&gt;The design around the different IP Pool is to prevent access to resources. Agreed, this could be accomplished by a HIPS profile and deny access on policies.&lt;/P&gt;
&lt;P&gt;I found a similar post where a suggestion was to create a new Gateway and use the portal to direct the client to the new gateway. The Portal allows for a custom check which could look for a registry key and therefore achieve a similar result to a HIPS check.&lt;/P&gt;
&lt;P&gt;Is this a reasonable approach?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 09:31:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/use-hips-to-assign-gateway-ip-address-for-external-clients/m-p/580758#M5149</guid>
      <dc:creator>BenBrazil</dc:creator>
      <dc:date>2024-03-18T09:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Use HIPS to assign Gateway IP Address for external clients</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/use-hips-to-assign-gateway-ip-address-for-external-clients/m-p/580780#M5150</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/258249"&gt;@BenBrazil&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That could be a reasonable approach.&amp;nbsp; How would you "direct the client to the new gateway"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using IP pools for security policy is a very common approach with many vendors.&amp;nbsp; It generally involves 3 steps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Identify client attribute (user, group, machine attribute, etc.).&lt;/LI&gt;
&lt;LI&gt;Assign IP pool based upon attribute.&lt;/LI&gt;
&lt;LI&gt;Use IP pool in security policy.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;With User-ID and Device-ID, you can use the attribute (user, group, or HIP Profile) directly in the security policy and skip step 2.&amp;nbsp; This allows for the security policy to be more readable (without comments) as long as the user/group/HIP Profiles are well named, e.g. HR has access to ___ or non-corporate devices have access to ___.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could also create objects for you IP Pools and give them good names to accomplish the same purpose, but skipping step 2 makes for a little less complicated approach.&amp;nbsp; BTW, you need a GlobalProtect license for HIP checks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 13:05:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/use-hips-to-assign-gateway-ip-address-for-external-clients/m-p/580780#M5150</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-03-18T13:05:39Z</dc:date>
    </item>
  </channel>
</rss>

