<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: REQUEST: Grace period for GlobalProtect patch checking in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/340923#M85541</link>
    <description>&lt;P&gt;I strongly support this request. The current capabilities make HIP matching against patch-management almost useless for us. I cannot enforce patch based policies against ordinary users since the firewall would immediately block traffic as soon as a new patch becomes available. There needs to be a way to match/enforce patch policies only if a patch has not been applied within a configurable period of time after the client first detects the new patch. This would seem like a no-brainer to me. Puzzled as to why this function does not exist in such an expensive product.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jul 2020 19:14:32 GMT</pubDate>
    <dc:creator>abarhorst</dc:creator>
    <dc:date>2020-07-27T19:14:32Z</dc:date>
    <item>
      <title>REQUEST: Grace period for GlobalProtect patch checking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/64995#M38872</link>
      <description>&lt;P&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;Problem:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Because of occasional issues with vendor patches, like MS had early this year, (see URL below), very&amp;nbsp;few companies release&amp;nbsp;patches/updates to clients or servers on the day of release. They test the updates first, then release them days or even weeks later after testing has shown no major issues. GlobalProtect has no capability to delay patch checking to address this test cycle.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;A href="https://urldefense.proofpoint.com/v2/url?u=http-3A__blog.norsecorp.com_2015_02_16_microsoft-2Dusers-2Dbattle-2Dbuggy-2Dpatches-2Din-2Dfebruarys-2Dreleases_-3Fmkt-5Ftok-3D3RkMMJWWfF9wsRojv6nJZKXonjHpfsX56O4qWqG3lMI-252F0ER3fOvrPUfGjI4FTsRqI-252BSLDwEYGJlv6SgFTLjEMa9u1rgPUhI-253D&amp;amp;d=AwMF-g&amp;amp;c=V9IgWpI5PvzTw83UyHGVSoW3Uc1MFWe5J8PTfkrzVSo&amp;amp;r=hoINDyTr8Xk_WGX1cRzOVu1CXimR3-XC8pOx8LkZ5RM&amp;amp;m=m75xTNHdpznZgerU6_EoNLTNrzqMPGt4GARwDJMK5BM&amp;amp;s=UgJKlJCzM783LA7VPEB1tsMgTdUVz10H65w-FD-6ZbU&amp;amp;e=" target="_blank"&gt;http://blog.norsecorp.com/2015/02/16/microsoft-users-battle-buggy-patches-in-februarys-releases/?mkt_tok=3RkMMJWWfF9wsRojv6nJZKXonjHpfsX56O4qWqG3lMI%2F0ER3fOvrPUfGjI4FTsRqI%2BSLDwEYGJlv6SgFTLjEMa9u1rgPUhI%3D&lt;/A&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;Request:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Add a “grace period” capability into GlobalProtect to delay the checking of patch levels by "N" days from the date of release. Example: Wait 14&amp;nbsp;days before checking for Patch Tuesday patches to accomodate the testing of the patches.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;The grace period “out of the box” should be 0 days by default in order to not change existing behavior. Users can then change the default grace period from there.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Include groups for "batched" updates released by a vendor.&amp;nbsp;&lt;/SPAN&gt;For example; Group defined for each&amp;nbsp;MS Patch Tuesday, group defined for each Apple Security Day release, and so on.&lt;/LI&gt;&lt;LI&gt;Nested groups and user-defined groups should also be available.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Ability to set and/or&amp;nbsp;override the default grace period on a&amp;nbsp;per-patch basis or per-group basis. This would allow customers to address urgent issues such as Zero Day exploits (reduced grace period, possibly all the way to 0) and to delay or&amp;nbsp;prevent enforcement (increased grace period, or set to -1 for “do not enforce”) for low priority and/or problematic updates.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additional improvements (and corrections) always appreciated.&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 23 Sep 2015 09:58:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/64995#M38872</guid>
      <dc:creator>jjhernandez</dc:creator>
      <dc:date>2015-09-23T09:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: REQUEST: Grace period for GlobalProtect patch checking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/65069#M38912</link>
      <description>&lt;P&gt;I too have put this feature request in directly to our local Palo Alto rep. over 6 months ago.&amp;nbsp; We have been waiting to implement Windows Update HIP checks until this feature becomes available.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2015 17:43:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/65069#M38912</guid>
      <dc:creator>nwetech</dc:creator>
      <dc:date>2015-09-24T17:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: REQUEST: Grace period for GlobalProtect patch checking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/340923#M85541</link>
      <description>&lt;P&gt;I strongly support this request. The current capabilities make HIP matching against patch-management almost useless for us. I cannot enforce patch based policies against ordinary users since the firewall would immediately block traffic as soon as a new patch becomes available. There needs to be a way to match/enforce patch policies only if a patch has not been applied within a configurable period of time after the client first detects the new patch. This would seem like a no-brainer to me. Puzzled as to why this function does not exist in such an expensive product.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 19:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/340923#M85541</guid>
      <dc:creator>abarhorst</dc:creator>
      <dc:date>2020-07-27T19:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: REQUEST: Grace period for GlobalProtect patch checking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/340944#M85546</link>
      <description>&lt;P&gt;Amending my own request:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The GlobalProtect client simply queries the updaters on the system (Windows Update, Apple Updater, and other supported system updating tools) for what updates/patches they think needs to be applied and reports that information back to the firewalls to have HIP policy applied to them. The data is basically the update and sometimes (not always) the severity information.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Net: The firewalls today have no clue about the age of a given update/patch that needs to be applied, and therefore can't do a grace period.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to make it work: In the enterprise space, using Microsoft WSUS, centralized Apple Updates, etc. allows the enterprise to control the release of updates to the workstations to a schedule of the enterprise's choosing. I.E. Test updates before generally releasing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Net: If the central updating server doesn't release the updates, the workstations wont show as needing updates/patches, and the need for a grace period &lt;EM&gt;mostly&lt;/EM&gt; disappears.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That being said, there is STILL a need for a grace period:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;For Enterprise customers to have a bit of time between release from centralized update servers to everyone actually getting the patches.&lt;/LI&gt;&lt;LI&gt;For BYOD or personal devices to have a bit of time between updates being released from vendors and for them to actually received and apply the patches.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 27 Jul 2020 20:48:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/340944#M85546</guid>
      <dc:creator>jjhernandez</dc:creator>
      <dc:date>2020-07-27T20:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: REQUEST: Grace period for GlobalProtect patch checking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/341086#M85586</link>
      <description>&lt;P&gt;&lt;EM&gt;"That being said, there is STILL a need for a grace period: For Enterprise customers to have a bit of time between release from centralized update servers to everyone actually getting the patches."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is specifically what I was referring to. We use WSUS. If a patch is approved, then workstations are immediately locked out of controlled network resources as soon as Windows Update client scans the server at the next scheduled interval. There is no reason why the globalconnect client itself could not be modified to set it's own date/timestamp flag each time a new update is seen, and then pass this data on to the firewall for evaluating the rules.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 16:54:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/341086#M85586</guid>
      <dc:creator>abarhorst</dc:creator>
      <dc:date>2020-07-28T16:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: REQUEST: Grace period for GlobalProtect patch checking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/416938#M93472</link>
      <description>&lt;P&gt;Looks like we are still waiting for this :grace period" feature for almost 7 years?&amp;nbsp; This is a must so we can check on BYOD machines.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 19:44:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/416938#M93472</guid>
      <dc:creator>skuo2020</dc:creator>
      <dc:date>2021-07-02T19:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: REQUEST: Grace period for GlobalProtect patch checking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/1222924#M123537</link>
      <description>&lt;P&gt;We would also need a grace period, because enforcing patches as soon as they are released does is not really possible with Windows Client Auto Updates.&lt;/P&gt;
&lt;P&gt;People come to work after patch tuesday and expect to start working immediately and not start their day with updates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Furthermore, iOS and Android Patch Management would be great.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 15:54:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/request-grace-period-for-globalprotect-patch-checking/m-p/1222924#M123537</guid>
      <dc:creator>AlexHalbarth</dc:creator>
      <dc:date>2025-03-06T15:54:16Z</dc:date>
    </item>
  </channel>
</rss>

