<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect HIPS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-hips/m-p/286375#M76583</link>
    <description>&lt;P&gt;Hi Steve -&lt;/P&gt;&lt;P&gt;Dead on!&amp;nbsp; The Host Information dropdown is the spot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm a little confused about the difference between GlobalProtect &amp;gt; Gateways &amp;gt; Agent &amp;gt; Client Settings &amp;gt; Configs &amp;gt; IP Pools tab and&amp;nbsp;GlobalProtect &amp;gt; Gateways &amp;gt; Agent &amp;gt; Client IP Pool&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm guessing that if a vendor isn't listed in say Anti-Malware for example, I'll have to do a workaround with a Custom check?&lt;/P&gt;</description>
    <pubDate>Tue, 03 Sep 2019 19:19:03 GMT</pubDate>
    <dc:creator>Shawverr</dc:creator>
    <dc:date>2019-09-03T19:19:03Z</dc:date>
    <item>
      <title>GlobalProtect HIPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-hips/m-p/286338#M76572</link>
      <description>&lt;P&gt;Apologies for new guy question.&lt;/P&gt;&lt;P&gt;I've been asked to set up GlobalProtect VPN with MFA and a HIPS check.&amp;nbsp; For example if there isn't a particular brand of AV the client is rejected.&amp;nbsp; My question (well, one of my thousand) is I don't understand how HIPS ties to the GlobalProtect connection.&amp;nbsp; I don't see anywhere in the setup where it says, "Use this HIP Profile for this Portal and if it doesn't match display this message".&amp;nbsp; I understand that is a pretty simplistic version of what I'm looking for, but hopefully someone gets what I'm saying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for your time.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 17:31:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-hips/m-p/286338#M76572</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-03T17:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect HIPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-hips/m-p/286354#M76575</link>
      <description>&lt;P&gt;Good Day!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You are pretty close in your logical thinking, but it is the GP Gateway that looks at the HIP profile, not the Portal.&lt;/P&gt;&lt;P&gt;When you create the Gateway ==&amp;gt; Agent Tab ==&amp;gt; HIP Notification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is where you ask the gateway to compare your HIP objects/profiles to what is being presented by the user, and determine if a person should connect or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What other questions do you have?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 18:24:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-hips/m-p/286354#M76575</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-09-03T18:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect HIPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-hips/m-p/286375#M76583</link>
      <description>&lt;P&gt;Hi Steve -&lt;/P&gt;&lt;P&gt;Dead on!&amp;nbsp; The Host Information dropdown is the spot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm a little confused about the difference between GlobalProtect &amp;gt; Gateways &amp;gt; Agent &amp;gt; Client Settings &amp;gt; Configs &amp;gt; IP Pools tab and&amp;nbsp;GlobalProtect &amp;gt; Gateways &amp;gt; Agent &amp;gt; Client IP Pool&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm guessing that if a vendor isn't listed in say Anti-Malware for example, I'll have to do a workaround with a Custom check?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 19:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-hips/m-p/286375#M76583</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-03T19:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect HIPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-hips/m-p/286376#M76584</link>
      <description>&lt;P&gt;Howdy again!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;GlobalProtect &amp;gt; Gateways &amp;gt; Agent &amp;gt; Client IP Pool&amp;nbsp; &amp;nbsp;= 1 pool for ALL users. Plus!!!! this web pool.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;GlobalProtect &amp;gt; Gateways &amp;gt; Agent &amp;gt; Client Settings &amp;gt; Configs &amp;gt; IP Pools tab&amp;nbsp; = a different pool per group or however.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Example... BAD... you have a mix of employees, vendors, and suppliers that need access... if you use Client Pool, everyone has same IP subnet, and kind of hard to control/manager.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Better would be Client Settings (and have 3 profiles)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;profile 1. Employees (Subnet A)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;profile 2. Vendors&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;profile 3. Suppliers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;just a general example.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In testing... I have seen IT ppl create a profile for themselves only, so that they can get the same subnet/IP everytime they log in. Then make rules allowing that specific subnet/IP access to networking/mgmt vlan, or whatever....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 19:31:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-hips/m-p/286376#M76584</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-09-03T19:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect HIPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-hips/m-p/286377#M76585</link>
      <description>&lt;P&gt;Just so I'm clear, you'd have three different subnets in your example?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Better would be Client Settings (and have 3 profiles)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;profile 1. Employees (Subnet A)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;profile 2. Vendors (Subnet B)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;profile 3. Suppliers (Subnet C)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Correct?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can't thank you enough for clearing some of this up for me.&amp;nbsp; I'm sure I'll be posting more here as soon as I actually start to go though the process.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 19:40:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-hips/m-p/286377#M76585</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-03T19:40:21Z</dc:date>
    </item>
  </channel>
</rss>

