<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Applying different HIP Checks to different Global Protect App Groups in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/applying-different-hip-checks-to-different-global-protect-app/m-p/578877#M703</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're trying to figure out if there's a way to have different HIP Profiles attached to different Global Protect App groups. At the highest level, we have two Global Protect App Settings / Groups defined. One is default and one is for Contractors. Contractors who connect to Global Protect get assigned slightly different settings for a number of reasons.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right now the HIP Check Profile is globally assigned. Ideally, we'd like to create a tighter HIP check for the Default group since we have more control over those systems w/o impacting the other groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas or is this just a limitation with Prisma Access / Global Protect?&lt;/P&gt;</description>
    <pubDate>Thu, 29 Feb 2024 17:51:15 GMT</pubDate>
    <dc:creator>KevinPawloski</dc:creator>
    <dc:date>2024-02-29T17:51:15Z</dc:date>
    <item>
      <title>Applying different HIP Checks to different Global Protect App Groups</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/applying-different-hip-checks-to-different-global-protect-app/m-p/578877#M703</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're trying to figure out if there's a way to have different HIP Profiles attached to different Global Protect App groups. At the highest level, we have two Global Protect App Settings / Groups defined. One is default and one is for Contractors. Contractors who connect to Global Protect get assigned slightly different settings for a number of reasons.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right now the HIP Check Profile is globally assigned. Ideally, we'd like to create a tighter HIP check for the Default group since we have more control over those systems w/o impacting the other groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas or is this just a limitation with Prisma Access / Global Protect?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 17:51:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/applying-different-hip-checks-to-different-global-protect-app/m-p/578877#M703</guid>
      <dc:creator>KevinPawloski</dc:creator>
      <dc:date>2024-02-29T17:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Applying different HIP Checks to different Global Protect App Groups</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/applying-different-hip-checks-to-different-global-protect-app/m-p/578955#M704</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/242531"&gt;@KevinPawloski&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HIP Profiles are not attached to GP groups.&amp;nbsp; They are enforced in the security policy.&amp;nbsp; HIP failures do not cause users to disconnect from GP.&amp;nbsp; If the security policy is setup correctly, devices that do not match the profiles will still connect via GP, but cannot access resources except possibly remediation servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have current security policy rules for the GP source zone and contractors, you can add the HIP Profile and the users will not match the rule unless they match the HIP Profile.&amp;nbsp; You can also add the HIP Profile to your default GP rules, and the contractors will not match the "tighter" HIP Profile and not be allowed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For your gateway, you could setup a HIP match notification popup so that different users will get different notices when they match different profiles.&amp;nbsp; If you want a "not match" popup, you would need 2 gateways.&amp;nbsp; Otherwise the contractors would get the not match tight HIP Profile, and the default would get the not match contractor HIP Profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/community-blogs/leveraging-host-information-profile-hip/ba-p/291126" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/community-blogs/leveraging-host-information-profile-hip/ba-p/291126&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 19:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/applying-different-hip-checks-to-different-global-protect-app/m-p/578955#M704</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-03-15T19:24:52Z</dc:date>
    </item>
  </channel>
</rss>

