<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GP HIP Profile Applied to Security Policy with Multiple Zones in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-hip-profile-applied-to-security-policy-with-multiple-zones/m-p/581365#M5172</link>
    <description>&lt;P&gt;Hi everyone!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First LIVE post, hoping to learn about how HIP profiles function when applied to security policies.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a zone created for my Global Protect VPN users, I want to apply a HIP Profile that checks if the computer is domain joined and denies access to the gateway if the check fails. My understanding is that the HIP profile needs to be applied to a security policy. Adding it to my GP zone is not an issue however, I have security policies that preceded the GP zone that have “any” zone set as the source, meaning if a VPN user matches it is allowed to certain destinations. What happens if I apply the HIP profile with a security policy that has “any” as the source zone? Will it only deny traffic for Global Protect users who have HIP collection or will this also effect other endpoints coming from different zones?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2024 15:53:12 GMT</pubDate>
    <dc:creator>EvanSotcheff</dc:creator>
    <dc:date>2024-03-22T15:53:12Z</dc:date>
    <item>
      <title>GP HIP Profile Applied to Security Policy with Multiple Zones</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-hip-profile-applied-to-security-policy-with-multiple-zones/m-p/581365#M5172</link>
      <description>&lt;P&gt;Hi everyone!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First LIVE post, hoping to learn about how HIP profiles function when applied to security policies.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a zone created for my Global Protect VPN users, I want to apply a HIP Profile that checks if the computer is domain joined and denies access to the gateway if the check fails. My understanding is that the HIP profile needs to be applied to a security policy. Adding it to my GP zone is not an issue however, I have security policies that preceded the GP zone that have “any” zone set as the source, meaning if a VPN user matches it is allowed to certain destinations. What happens if I apply the HIP profile with a security policy that has “any” as the source zone? Will it only deny traffic for Global Protect users who have HIP collection or will this also effect other endpoints coming from different zones?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 15:53:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-hip-profile-applied-to-security-policy-with-multiple-zones/m-p/581365#M5172</guid>
      <dc:creator>EvanSotcheff</dc:creator>
      <dc:date>2024-03-22T15:53:12Z</dc:date>
    </item>
  </channel>
</rss>

