<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom HIP Check for Linux in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-hip-check-for-linux/m-p/226958#M65330</link>
    <description>&lt;P&gt;That's what I was thinking of as well. The two users are using Mint 18 Cinnamon. Mint isn't recognizing &lt;EM&gt;dnsdomainname&lt;/EM&gt;, but does respond with &lt;EM&gt;domainname&lt;/EM&gt;&amp;nbsp;though it reports&amp;nbsp;none. However, I can run&amp;nbsp;&lt;EM&gt;realm list&amp;nbsp;&lt;/EM&gt;and see the domain.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Aug 2018 18:36:54 GMT</pubDate>
    <dc:creator>Paul_Lupini</dc:creator>
    <dc:date>2018-08-13T18:36:54Z</dc:date>
    <item>
      <title>Custom HIP Check for Linux</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-hip-check-for-linux/m-p/226935#M65328</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been tasked to have Globalprotect only allow company owned devices over the VPN. I know I can create custom HIP checks for Windows/Mac (reg/plist value). How would I do the same for Linux clients?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two end users that work remote, and are on a Linux machine. Still having issues with getting the GlobalProtect client for linux to work properly. VNC with IPSec is how they currently connect, and it works fine. I'm only on version 4.1.2, and am working on upgrading to 4.1.4 in hopes it corrects my problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem I'm having with the Linux client is that it fails because it doesn't trust the server certificate. However, when you navigate to the portal there is no certificate error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Linux client problems aside... I'm trying to find the best answer to meet this initiative -&amp;gt; Only allow our devices on the VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the HIP check the best/easiest answer, or should I be looking elsewhere?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for all your help,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 16:58:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-hip-check-for-linux/m-p/226935#M65328</guid>
      <dc:creator>Paul_Lupini</dc:creator>
      <dc:date>2018-08-13T16:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Custom HIP Check for Linux</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-hip-check-for-linux/m-p/226955#M65329</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69977"&gt;@Paul_Lupini&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You could query 'dnsdomainname' and verify that the output matches your domain; this would at least ensure that the linux machine is joined to your AD. Just keep in mind that there really isn't anything stopping a user from doing a domain join on a different linux machine as long as they have a user within your domain unless you have restricted those permissions. Most enviroments seem to forget that by default users have the ability to do a domain join operation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 18:27:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-hip-check-for-linux/m-p/226955#M65329</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-13T18:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: Custom HIP Check for Linux</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-hip-check-for-linux/m-p/226958#M65330</link>
      <description>&lt;P&gt;That's what I was thinking of as well. The two users are using Mint 18 Cinnamon. Mint isn't recognizing &lt;EM&gt;dnsdomainname&lt;/EM&gt;, but does respond with &lt;EM&gt;domainname&lt;/EM&gt;&amp;nbsp;though it reports&amp;nbsp;none. However, I can run&amp;nbsp;&lt;EM&gt;realm list&amp;nbsp;&lt;/EM&gt;and see the domain.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 18:36:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-hip-check-for-linux/m-p/226958#M65330</guid>
      <dc:creator>Paul_Lupini</dc:creator>
      <dc:date>2018-08-13T18:36:54Z</dc:date>
    </item>
  </channel>
</rss>

