<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HIP Notification question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/449855#M100984</link>
    <description>&lt;P&gt;Update here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;Reading some additional documentation, it does seem to indicate that the HIP notification message is displayed when HIP data is sent to the GP gateway from the GP client upon connection, and a defined HIP profile is matched or not matched (depending on your config). The HIP profile is then enforced when it is attached to a security policy rule (allow or deny).&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I have attached a few articles for you to review.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;I&gt;How do users know if their systems are compliant&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/host-information/about-host-information/how-do-users-know-if-their-systems-are-compliant.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/host-information/about-host-information/how-do-users-know-if-their-systems-are-compliant.html&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;I&gt;Leveraging Host Information profiles&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/leveraging-host-information-profile-hip/ba-p/291126" target="_blank"&gt;https://live.paloaltonetworks.com/t5/blogs/leveraging-host-information-profile-hip/ba-p/291126&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;I&gt;Configure HIP-Based policy enforcement&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/host-information/configure-hip-based-policy-enforcement.html#id168afbfe-e152-461e-8c0b-4a463685c401" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/host-information/configure-hip-based-policy-enforcement.html#id168afbfe-e152-461e-8c0b-4a463685c401&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;could you clarify or confirm the above&lt;/DIV&gt;</description>
    <pubDate>Mon, 29 Nov 2021 05:58:36 GMT</pubDate>
    <dc:creator>Ben-Price</dc:creator>
    <dc:date>2021-11-29T05:58:36Z</dc:date>
    <item>
      <title>HIP Notification question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/449183#M100903</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A question regarding HIP notifications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have enabled HIP notifications for GP clients connecting in and they trigger when a violation of the HIP profile is detected e.g. firewall turned off, but just wanted to clarify something in the Palo documentation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo documentation below seems to indicate that the HIP profile needs to be attached to a security policy rule before the HIP notification is triggered, but it seems to trigger correctly&amp;nbsp; whether it is attached to a security policy rule or not. I have tried 'any' and 'no-hip' in the source device section of a security policy rule and it seems to trigger either way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenPrice_0-1637729906099.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37791iD1EB5AEF302B4E80/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BenPrice_0-1637729906099.png" alt="BenPrice_0-1637729906099.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenPrice_1-1637729949128.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37792i2C8965C58BBE546E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BenPrice_1-1637729949128.png" alt="BenPrice_1-1637729949128.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any clarification on the Palo documentation would be appreciated?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 05:00:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/449183#M100903</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-11-24T05:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: HIP Notification question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/449855#M100984</link>
      <description>&lt;P&gt;Update here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;Reading some additional documentation, it does seem to indicate that the HIP notification message is displayed when HIP data is sent to the GP gateway from the GP client upon connection, and a defined HIP profile is matched or not matched (depending on your config). The HIP profile is then enforced when it is attached to a security policy rule (allow or deny).&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I have attached a few articles for you to review.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;I&gt;How do users know if their systems are compliant&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/host-information/about-host-information/how-do-users-know-if-their-systems-are-compliant.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/host-information/about-host-information/how-do-users-know-if-their-systems-are-compliant.html&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;I&gt;Leveraging Host Information profiles&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/leveraging-host-information-profile-hip/ba-p/291126" target="_blank"&gt;https://live.paloaltonetworks.com/t5/blogs/leveraging-host-information-profile-hip/ba-p/291126&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;I&gt;Configure HIP-Based policy enforcement&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/host-information/configure-hip-based-policy-enforcement.html#id168afbfe-e152-461e-8c0b-4a463685c401" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/host-information/configure-hip-based-policy-enforcement.html#id168afbfe-e152-461e-8c0b-4a463685c401&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;could you clarify or confirm the above&lt;/DIV&gt;</description>
      <pubDate>Mon, 29 Nov 2021 05:58:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/449855#M100984</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-11-29T05:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: HIP Notification question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/449860#M100985</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So HIP Notifications themselves would trigger when the matching HIP Profile is matched as you've configured. When you include the HIP Profile as a condition in the security policy it's used as matching criteria (IE: It would only match if the specified HIP Profile is triggered on the endpoint in question). These both utilize HIP Profiles to function, but they perform different functions. You don't have to use a HIP Profile in a security policy to use it as a HIP Notification match.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 06:06:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/449860#M100985</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-11-29T06:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: HIP Notification question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/449861#M100986</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Thanks for the feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way of implementing the below scenario.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Scenario:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have a “Staff” Global Protect client profile and a “Contractor” Global Protect client profile. HIP checks (Device Compliance) for Staff and Contractor will obviously be different.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How can we perform HIP notifications that are relevant to the client profile being used.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Eg. We don’t want to notify when a “contractor’s” device is not Active directory domain joined because we don’t expect it to be domain joined (Contractors have much less access than Staff). But we do want to notify Staff if their device is not domain joined (Staff profile provide mores access therefore, more compliance is required)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 06:15:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/449861#M100986</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-11-29T06:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: HIP Notification question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/449864#M100987</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Since this is done at the Gateway level the easiest way would be to just create two separate gateways. One gateway for your "Staff" clients and another for the "Contractor" clients. You would just direct access to the proper gateway via the Portal agent configurations if you didn't want to create a completely separate Portal for your contractors.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 06:25:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/449864#M100987</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-11-29T06:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: HIP Notification question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/450194#M101015</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;OK. A few further questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are the HIP profiles evaluated in a top down order?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does a client have to match all the requirements of a HIP profile for the notification to trigger e.g. if 2 profiles require firewall to be on, but have other different attributes like anti-virus requirements. Does the client match the first HIP profile in the list or does it have to match all attributes of the HIP profile?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will a HIP notification trigger when an endpoint tries to send traffic through a security policy rule that has a HIP profile assigned or does the notification only trigger when the client connects?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 22:27:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/450194#M101015</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-11-29T22:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: HIP Notification question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/450307#M101028</link>
      <description>&lt;P&gt;Are the HIP profiles evaluated in a top down order?&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;I'm not exactly sure what you are asking here. The HIP Profiles are just a collection of matching HIP Objects that&amp;nbsp;you've specified, so as long as the client matches all of the HIP Objects in the HIP Profile it'll "match" the HIP Profile. All of this is done at exactly the same time, so there's no top/down matching from a HIP aspect. If I have multiple profiles that a client all matches, every matching profile will match for that client.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Hopefully that makes sense.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does a client have to match all the requirements of a HIP profile for the notification to trigger e.g. if 2 profiles require firewall to be on, but have other different attributes like anti-virus requirements. Does the client match the first HIP profile in the list or does it have to match all attributes of the HIP profile?&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;You&amp;nbsp;&lt;EM&gt;may&amp;nbsp;&lt;/EM&gt;be interchanging HIP Profile when you're talking about HIP Objects? A HIP Profile is only matched when all of it's match criteria is matched. So if I built out a HIP Profile ("Issued-Win10-Device") that said to match on my "Supported-Win10-Build" HIP Object&amp;nbsp;&lt;EM&gt;and&amp;nbsp;&lt;/EM&gt;"Issued-Device" HIP Object, only clients matching on the "Supported-Win10-Build" and "Issued-Device" HIP Objects would match my "Issued-Win10-Device" profile. If you only matched one object or the other it wouldn't match the profile.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will a HIP notification trigger when an endpoint tries to send traffic through a security policy rule that has a HIP profile assigned or does the notification only trigger when the client connects?&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;The actual HIP Notification will only trigger when the client connects. It won't re-trigger every time it hits a security&amp;nbsp;policy that includes the HIP Profile as matching criteria.&amp;nbsp;These two features are independent of each other&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 02:09:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/450307#M101028</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-11-30T02:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: HIP Notification question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/450335#M101035</link>
      <description>&lt;P&gt;Awesome thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;that has cleared things up.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 06:25:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-notification-question/m-p/450335#M101035</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-11-30T06:25:08Z</dc:date>
    </item>
  </channel>
</rss>

