<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow internet only after HIP fail in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-internet-only-after-hip-fail/m-p/233366#M66929</link>
    <description>&lt;P&gt;to keep it simple could you not just add an allow rule based on HIP fail to allow access to proxies only, followed by your RFC1918 block if still needed... you may only need the first allow...&lt;/P&gt;</description>
    <pubDate>Tue, 02 Oct 2018 14:20:24 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2018-10-02T14:20:24Z</dc:date>
    <item>
      <title>Allow internet only after HIP fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-internet-only-after-hip-fail/m-p/233264#M66903</link>
      <description>&lt;P&gt;We are looking to configure the firewall rules where if a known user fails the HIP check, the user has access to only the internet, and not the intranet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I currently have the rules configured such that failing the HIP check allows the user to access to both the internet and the intranet. We tried blocking RFC1918 in the destination address field, but this blocks my proxy servers that all outward traffic must go through.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2018 23:52:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-internet-only-after-hip-fail/m-p/233264#M66903</guid>
      <dc:creator>mikembau</dc:creator>
      <dc:date>2018-10-01T23:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: Allow internet only after HIP fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-internet-only-after-hip-fail/m-p/233366#M66929</link>
      <description>&lt;P&gt;to keep it simple could you not just add an allow rule based on HIP fail to allow access to proxies only, followed by your RFC1918 block if still needed... you may only need the first allow...&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 14:20:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-internet-only-after-hip-fail/m-p/233366#M66929</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-10-02T14:20:24Z</dc:date>
    </item>
  </channel>
</rss>

