<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect HIP Check when connecting to external gateway in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/375200#M716</link>
    <description>&lt;P&gt;No I don't think this is possible as HIP info is collected and sent after the GW connection is established.&lt;/P&gt;&lt;P&gt;You could add a deny policy at the top of your ruleset to deny all from sslvpn zone&amp;nbsp; if HIP&amp;nbsp; is "Not" a match.&lt;/P&gt;&lt;P&gt;this would save you adding to all other policies but you will then need to move up any policies that you may have that would allow traffic with a no match (If you have any).&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Dec 2020 12:22:56 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2020-12-18T12:22:56Z</dc:date>
    <item>
      <title>GlobalProtect HIP Check when connecting to external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/374952#M711</link>
      <description>&lt;P&gt;I have GlobalProtect portal/gateway configured and working in my environment. External users can connect to the GP portal/gateway and receive network access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set up a HIP profile to check for domain joined and AV updated in the last 3 days. What I'd like to do is have the HIP check run during the initial connection to GP portal/gateway, so basically if HIP check passes, user is allowed to connect to GP, if HIP check fails, user is not allowed to connect to GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not want to set the HIP check profile for SSLVPN zone on every single firewall rule (we have a huge ruleset). I only want the HIP check enforced on connection to the GP portal/gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried applying the HIP check profile to the firewall rule that allows GP connection from WAN, but that did not do the trick.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 14:55:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/374952#M711</guid>
      <dc:creator>TomKisiel</dc:creator>
      <dc:date>2020-12-17T14:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect HIP Check when connecting to external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/375200#M716</link>
      <description>&lt;P&gt;No I don't think this is possible as HIP info is collected and sent after the GW connection is established.&lt;/P&gt;&lt;P&gt;You could add a deny policy at the top of your ruleset to deny all from sslvpn zone&amp;nbsp; if HIP&amp;nbsp; is "Not" a match.&lt;/P&gt;&lt;P&gt;this would save you adding to all other policies but you will then need to move up any policies that you may have that would allow traffic with a no match (If you have any).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 12:22:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/375200#M716</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-18T12:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect HIP Check when connecting to external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/375233#M719</link>
      <description>&lt;P&gt;I understand what you're saying, but trying to figure out how I would design that rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone- SSLVPN&lt;/P&gt;&lt;P&gt;Source- User, Address- Any&lt;/P&gt;&lt;P&gt;HIP Profile- HIP-Checks&lt;/P&gt;&lt;P&gt;Destination- Zone, User, Address- Any&lt;/P&gt;&lt;P&gt;Action- Deny?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 16:20:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/375233#M719</guid>
      <dc:creator>TomKisiel</dc:creator>
      <dc:date>2020-12-18T16:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect HIP Check when connecting to external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/375234#M720</link>
      <description>&lt;P&gt;OK I will try to keep it simple and us an OS as the example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what we are trying to achieve is to allow all win10&amp;nbsp; devices access via the policies.&lt;/P&gt;&lt;P&gt;But we do not want to add this to all of the policies as there is hundreds of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so...&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;objects/hip object&amp;nbsp; &amp;nbsp;add name win10-check&amp;nbsp; &amp;nbsp; &amp;nbsp;general/host info/OS contains msoft windows 10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;objects/hip profiles&amp;nbsp; add&amp;nbsp; name not-win10&amp;nbsp; &amp;nbsp; match add &lt;U&gt;&lt;STRONG&gt;NOT&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt; win10-check&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy add from sslvpn&amp;nbsp; &amp;nbsp;to private&amp;nbsp; &amp;nbsp;hip not-win10&amp;nbsp; any any any deny&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i hope i got that correct as popping out...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so...&amp;nbsp; &amp;nbsp;if you only allow a certain level in, AV etc. then block those that do not meet the requirement with a NOT hip profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 16:44:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/375234#M720</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-18T16:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect HIP Check when connecting to external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/375238#M721</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1608310070352.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29202i79F40E40F5698C5E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1608310070352.png" alt="MickBall_0-1608310070352.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 16:48:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/375238#M721</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-18T16:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect HIP Check when connecting to external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/375264#M722</link>
      <description>&lt;P&gt;Perfect, this works!!&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 17:01:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-hip-check-when-connecting-to-external-gateway/m-p/375264#M722</guid>
      <dc:creator>TomKisiel</dc:creator>
      <dc:date>2020-12-18T17:01:22Z</dc:date>
    </item>
  </channel>
</rss>

