<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Globalprotect with Cisco ISE in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/590112#M5497</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232848"&gt;@dcawood1&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is where you check certificates with HIP:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1719000371107.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60470iD6667AA901E6C996/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1719000371107.png" alt="TomYoung_0-1719000371107.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could also configure certificate authentication and/or username/password.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jun 2024 20:06:56 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-06-21T20:06:56Z</dc:date>
    <item>
      <title>Globalprotect with Cisco ISE</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/391056#M1023</link>
      <description>&lt;P&gt;we are using PA Globalprotect for Remote VPN users. Currently planning to implement Cisco ISE posture for RVPN clients.&amp;nbsp;&lt;/P&gt;&lt;P&gt;how can I integrate Globalprotect with Cisco ISE posture module.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 05:50:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/391056#M1023</guid>
      <dc:creator>charles07</dc:creator>
      <dc:date>2021-03-13T05:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect with Cisco ISE</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/433466#M1698</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71149"&gt;@charles07&lt;/a&gt;&amp;nbsp;for posting question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ultimate answer is no. The Cisco ISE posture module will only work with Cisco AnyConnect client. Unfortunately there is no integration support for 3d party vpn clients. This information is backed by my Cisco SE. You can still use ISE for authentication of Global Protect clients. If posture check by ISE is a must, then you will unfortunately have to go with AnyConnect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 13:08:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/433466#M1698</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-13T13:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect with Cisco ISE</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/433501#M1699</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71149"&gt;@charles07&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you considered using HIP-Based Policy Enforcement?&amp;nbsp; This is the PANW equivalent of ISE posture.&amp;nbsp; This feature is integrated with your existing GlobalProtect (GP) clients.&amp;nbsp; However, it does require a GP license.&amp;nbsp; GP is easy to integrate with ISE as a RADIUS server.&amp;nbsp; The easiest solution would be to let the firewall determine HIP compliance and access, but that possibly could be accomplished with ISE using VSAs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/host-information/configure-hip-based-policy-enforcement.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/host-information/configure-hip-based-policy-enforcement.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 14:31:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/433501#M1699</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-13T14:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect with Cisco ISE</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/433728#M1701</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;GP HIP profile is not equivalent to ISE posture. Much features with ISE are missing in GP HIP.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 09:05:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/433728#M1701</guid>
      <dc:creator>ceapen01</dc:creator>
      <dc:date>2021-09-14T09:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect with Cisco ISE</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/433784#M1702</link>
      <description>&lt;P&gt;That statement is not supported by facts.&amp;nbsp; (I'm not saying you don't have any.&amp;nbsp; You didn't state any.) A HIP object can be configured to check mobile device info/settings/apps, PC patch info, personal firewalls, anti-malware/virus software, disk backup, disk encryption, DLP software, certificates, process checks, registry entries, etc.&amp;nbsp; What specific features does ISE Posture check that are not included?&amp;nbsp; I am interested in knowing.&amp;nbsp; I would like to keep this forum technical.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 20:49:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/433784#M1702</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-14T20:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect with Cisco ISE</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/590091#M5496</link>
      <description>&lt;P&gt;I haven't found a way to check certs with HIP after login. This seems like it should... be something that GP can do via HIP but Palo TAC is not sure how and there is no documentation on how to check for a cert on a pc/mac. If anyone has found a way - please let me know. So far, seems Palo professional services is the only way to get it done since no one bothered to document this in the administration guide.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 14:50:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/590091#M5496</guid>
      <dc:creator>dcawood1</dc:creator>
      <dc:date>2024-06-21T14:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect with Cisco ISE</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/590112#M5497</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232848"&gt;@dcawood1&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is where you check certificates with HIP:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1719000371107.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60470iD6667AA901E6C996/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1719000371107.png" alt="TomYoung_0-1719000371107.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could also configure certificate authentication and/or username/password.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 20:06:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/590112#M5497</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-06-21T20:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect with Cisco ISE</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/590125#M5498</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;, I have a couple of hip cert checks (issuer&amp;amp;certficate-template-oid) and they match on my laptop. I basically exported the issuing cert for my laptop machine cert from mmc. However, when another test user connects to the test gateway - no cert info is collected from his machine. Any idea what would be causing this and is there another cert I should be using for the cert profile for these hip matches. I haven't found any information yet that would clue me into what I am doing wrong here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Steps taken:&lt;/P&gt;
&lt;P&gt;1 - export cert that shows up as the issuing cert for my laptop&lt;/P&gt;
&lt;P&gt;2 - import cert to portal/gateway&lt;/P&gt;
&lt;P&gt;3 - create cert profile and add imported cert&lt;/P&gt;
&lt;P&gt;4 - create hip objects that validate issuer/template criteria&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5 - add cert profile to portal/agent - hip data collection&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 21:35:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-cisco-ise/m-p/590125#M5498</guid>
      <dc:creator>dcawood1</dc:creator>
      <dc:date>2024-06-21T21:35:35Z</dc:date>
    </item>
  </channel>
</rss>

