<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does anyone use HIP check on the local LAN as a NAC solution? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-use-hip-check-on-the-local-lan-as-a-nac-solution/m-p/144208#M48851</link>
    <description>&lt;UL&gt;&lt;LI&gt;How effective is this as a NAC solution for the internal LAN?&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Depneding on how you setup your HIP check it could make a pretty effective 'NAC' enviroment. You could HIP check to make sure that they were within your networks requipments (av current and ran in a timely manner, domain joined), and then setup security policies that wouldn't allow anybody to your different security policies unless they had a named user account.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Without 802.1x authentication, does a machine without GP installed simply bypass the internal gateway (and HIP check)?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;You could potentially deny any non-named user access to anything within your network, or outside internet access with ease as long as you setup your security zones with this in mind. Otherwise you could just make it so that your servers/internal resources were in a dedicated 'zone' that the user would not have access to unless they had logged into GlobalProtect and recieved a GP address that had security policies that allowed zone access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This can, and has been, done. It works well as long as you are aware that, like any NAC solution, you will likely run into occasional issues. It doesn't act as a true 'NAC' as you don't have all of the checks that a traditional NAC would employ to verify that the device was supposed to be on your network. That being said most people don't utilize any of the features in a NAC deployment that couldn't be done with a HIP check and the proper security policies on the firewall. I wouldn't really want to make this change in a working enterprise enviroment though, as switching over to something like this would be a fairly substantial upgrade; NAC has the advantage of being something that you can easily tune and assure management that it's working prior to a full roll-out.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Feb 2017 22:16:32 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-02-21T22:16:32Z</dc:date>
    <item>
      <title>Does anyone use HIP check on the local LAN as a NAC solution?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-use-hip-check-on-the-local-lan-as-a-nac-solution/m-p/144181#M48840</link>
      <description>&lt;P&gt;I understand that a HIP check can be used on the local LAN when the GlobalProtect client connects to the internal gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;How effective is this as a NAC solution for the internal LAN?&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;Without 802.1x authentication, does a machine without GP installed simply bypass the internal gateway (and HIP check)?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 20:57:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-use-hip-check-on-the-local-lan-as-a-nac-solution/m-p/144181#M48840</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2017-02-21T20:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone use HIP check on the local LAN as a NAC solution?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-use-hip-check-on-the-local-lan-as-a-nac-solution/m-p/144208#M48851</link>
      <description>&lt;UL&gt;&lt;LI&gt;How effective is this as a NAC solution for the internal LAN?&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Depneding on how you setup your HIP check it could make a pretty effective 'NAC' enviroment. You could HIP check to make sure that they were within your networks requipments (av current and ran in a timely manner, domain joined), and then setup security policies that wouldn't allow anybody to your different security policies unless they had a named user account.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Without 802.1x authentication, does a machine without GP installed simply bypass the internal gateway (and HIP check)?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;You could potentially deny any non-named user access to anything within your network, or outside internet access with ease as long as you setup your security zones with this in mind. Otherwise you could just make it so that your servers/internal resources were in a dedicated 'zone' that the user would not have access to unless they had logged into GlobalProtect and recieved a GP address that had security policies that allowed zone access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This can, and has been, done. It works well as long as you are aware that, like any NAC solution, you will likely run into occasional issues. It doesn't act as a true 'NAC' as you don't have all of the checks that a traditional NAC would employ to verify that the device was supposed to be on your network. That being said most people don't utilize any of the features in a NAC deployment that couldn't be done with a HIP check and the proper security policies on the firewall. I wouldn't really want to make this change in a working enterprise enviroment though, as switching over to something like this would be a fairly substantial upgrade; NAC has the advantage of being something that you can easily tune and assure management that it's working prior to a full roll-out.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 22:16:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-use-hip-check-on-the-local-lan-as-a-nac-solution/m-p/144208#M48851</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-02-21T22:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone use HIP check on the local LAN as a NAC solution?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-use-hip-check-on-the-local-lan-as-a-nac-solution/m-p/443239#M100193</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I found this while searching for the same solution we're asked for our cyber compliance checks, is there any docs I can read on this on the PAN support portal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 17:27:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-use-hip-check-on-the-local-lan-as-a-nac-solution/m-p/443239#M100193</guid>
      <dc:creator>cdcirexx</dc:creator>
      <dc:date>2021-10-25T17:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone use HIP check on the local LAN as a NAC solution?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-use-hip-check-on-the-local-lan-as-a-nac-solution/m-p/443289#M100201</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23401"&gt;@cdcirexx&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/host-information/configure-hip-based-policy-enforcement.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/host-information/configure-hip-based-policy-enforcement.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-quick-configs/globalprotect-for-internal-hip-checking-and-user-based-access.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-quick-configs/globalprotect-for-internal-hip-checking-and-user-based-access.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 23:10:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-use-hip-check-on-the-local-lan-as-a-nac-solution/m-p/443289#M100201</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-10-25T23:10:41Z</dc:date>
    </item>
  </channel>
</rss>

