<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HIP check Patch Management in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/m-p/615608#M6035</link>
    <description>&lt;P&gt;Hi, not sure if you ever achieved this but you're on the right track. One must first create the hip object and then the hip profile to include the hip object. The hip profile is the one that should be assigned to the security rule where you want the check to occur. Since you mentioned antimalware and firewall are already working correctly, I assume the "HIP data collection" is already turned on in your portal agent config. All you must be missing is a "deny" rule with the hip profile for the patch management criteria.&lt;BR /&gt;For example, if we are looking for any missing patches with severity 3 or greater, create the HIP object as pictured and the HIP profile with the HIP object. Then place the HIP profile under source device for the specific security rule which allows users onto your vpn.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="YvetteParra_0-1730220764546.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63644iCEB267ACC2BC77B5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="YvetteParra_0-1730220764546.png" alt="YvetteParra_0-1730220764546.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="YvetteParra_2-1730221350155.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63646i3DFE105F26E12DC3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="YvetteParra_2-1730221350155.png" alt="YvetteParra_2-1730221350155.png" /&gt;&lt;/span&gt;&lt;BR /&gt;detailed steps here: &lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/host-information/configure-hip-based-policy-enforcement" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/host-information/configure-hip-based-policy-enforcement&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Oct 2024 17:06:04 GMT</pubDate>
    <dc:creator>YvetteParra</dc:creator>
    <dc:date>2024-10-29T17:06:04Z</dc:date>
    <item>
      <title>HIP check Patch Management</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/m-p/449066#M2166</link>
      <description>&lt;P&gt;Hello, I am trying to setup a HIP Profile for contractors accessing our network over Global Protect.&lt;BR /&gt;This HIP Profile is checking if version of Windows is supported(allowing only 8.1 and 10), then checking if Anti-Malware and Firewall is enabled and as a last check I want to check if Windows patches are up to date.&lt;BR /&gt;Checks for OS, Anti-Malware and Firewall are working fine but I am struggling with Patch-Management check.&lt;/P&gt;&lt;P&gt;On Global Protect Client on my not-updated test computer I can see that I am missing 3 patches. Two of them are of severity 2 and one is severity -1.&lt;/P&gt;&lt;P class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hip check.PNG" style="width: 751px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37776i00A4236A315E1821/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="hip check.PNG" alt="hip check.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class=""&gt;I was trying several combinations like the on on picture, on Patch Management HIP object tab but without success.&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hip object.PNG" style="width: 577px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37777i25A7B9F8BE63209D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="hip object.PNG" alt="hip object.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I want to achive that this HIP Profile will only allow user if there are no severity 2 or 3 Patches missing. What I need to set-up on Patch management tab to do so?&lt;/P&gt;&lt;P&gt;Thanks for any hint or help.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 09:56:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/m-p/449066#M2166</guid>
      <dc:creator>Henley</dc:creator>
      <dc:date>2021-11-23T09:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: HIP check Patch Management</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/m-p/527445#M3595</link>
      <description>&lt;P&gt;shot in the dark here since this is 15 months old. but did you ever happen to get this figured out?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 19:13:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/m-p/527445#M3595</guid>
      <dc:creator>wcoulson</dc:creator>
      <dc:date>2023-01-17T19:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: HIP check Patch Management</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/m-p/589081#M5439</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/117117"&gt;@Henley&lt;/a&gt;&amp;nbsp;were you able to achieve this?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 16:03:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/m-p/589081#M5439</guid>
      <dc:creator>SaiKiranS</dc:creator>
      <dc:date>2024-06-07T16:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: HIP check Patch Management</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/m-p/615608#M6035</link>
      <description>&lt;P&gt;Hi, not sure if you ever achieved this but you're on the right track. One must first create the hip object and then the hip profile to include the hip object. The hip profile is the one that should be assigned to the security rule where you want the check to occur. Since you mentioned antimalware and firewall are already working correctly, I assume the "HIP data collection" is already turned on in your portal agent config. All you must be missing is a "deny" rule with the hip profile for the patch management criteria.&lt;BR /&gt;For example, if we are looking for any missing patches with severity 3 or greater, create the HIP object as pictured and the HIP profile with the HIP object. Then place the HIP profile under source device for the specific security rule which allows users onto your vpn.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="YvetteParra_0-1730220764546.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63644iCEB267ACC2BC77B5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="YvetteParra_0-1730220764546.png" alt="YvetteParra_0-1730220764546.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="YvetteParra_2-1730221350155.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63646i3DFE105F26E12DC3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="YvetteParra_2-1730221350155.png" alt="YvetteParra_2-1730221350155.png" /&gt;&lt;/span&gt;&lt;BR /&gt;detailed steps here: &lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/host-information/configure-hip-based-policy-enforcement" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/host-information/configure-hip-based-policy-enforcement&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 17:06:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/hip-check-patch-management/m-p/615608#M6035</guid>
      <dc:creator>YvetteParra</dc:creator>
      <dc:date>2024-10-29T17:06:04Z</dc:date>
    </item>
  </channel>
</rss>

