<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HIP Profile monitor only initially in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/hip-profile-monitor-only-initially/m-p/355957#M87596</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133520"&gt;@FWPalolearner&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So the thing to remember about HIP is that it never takes any action unless you've specifically told it to. By default, HIP is just going to be informational. What you would do here is just create a HIP Object matching your criteria and commit. The HIP Match logs on the firewall will tell you which connecting clients are matching your HIP Object.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to quickly see what machines aren't meeting your defined HIP parameters, you could do that easily enough by creating two HIP Profiles. You would simply set it to match or NOT match your HIP Object you defined above, and then you could search for either HIP Profile in your logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So for an example, lets say that I created a HIP Object called "Secured-Clients" and had it match all the criteria you defined. I would then create two HIP Profiles, with the first being "Trusted-Clients" for example that would simply match on the "Secured-Clients" HIP object you created previously. You would then create another HIP Profile called "NonTrusted-Clients" and simply have the match criteria as NOT "Secured-Clients".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When it came to searching who was matching which profile, you can log into the firewall and search the HIP Match logs. To filter on the Trusted-Clients HIP Profile you would simply use the search&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;( matchname eq Trusted-Clients )&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;to find everyone who meets your HIP criteria and then&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;( matchname eq NonTrusted-Clients )&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;to find everyone who doesn't.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just keep in mind that nothing will actually take into account your HIP Profiles until you actually configure it to do so. Simply creating new HIP Objects or HIP Profiles will never cause any issues to your existing profiles.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Oct 2020 01:01:21 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2020-10-13T01:01:21Z</dc:date>
    <item>
      <title>HIP Profile monitor only initially</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-profile-monitor-only-initially/m-p/355641#M87567</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have got requirement to implement HIP profile for GP users ;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But first we want to run it in Monitor mode without any enforcement or without blocking any users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are the requirements&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="289"&gt;&lt;P&gt;OS&lt;/P&gt;&lt;/TD&gt;&lt;TD width="89"&gt;&lt;P&gt;Windows 10&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="289"&gt;&lt;P&gt;AV&lt;/P&gt;&lt;/TD&gt;&lt;TD width="82"&gt;&lt;P&gt;Mcafee&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="291"&gt;&lt;P&gt;AV updates not older than&lt;/P&gt;&lt;/TD&gt;&lt;TD width="81"&gt;&lt;P&gt;5 days&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="289"&gt;&lt;P&gt;Patch management&lt;/P&gt;&lt;/TD&gt;&lt;TD width="82"&gt;&lt;P&gt;/&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="289"&gt;&lt;P&gt;Disk encryption&lt;/P&gt;&lt;/TD&gt;&lt;TD width="82"&gt;&lt;P&gt;Enabled&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="289"&gt;&lt;P&gt;Firewall&lt;/P&gt;&lt;/TD&gt;&lt;TD width="82"&gt;&lt;P&gt;Enabled&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So do i just have to create HIP Object with all these conditions ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And how will i check which machines will not hit these HIP objects ?&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 21:23:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-profile-monitor-only-initially/m-p/355641#M87567</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2020-10-11T21:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: HIP Profile monitor only initially</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-profile-monitor-only-initially/m-p/355957#M87596</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133520"&gt;@FWPalolearner&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So the thing to remember about HIP is that it never takes any action unless you've specifically told it to. By default, HIP is just going to be informational. What you would do here is just create a HIP Object matching your criteria and commit. The HIP Match logs on the firewall will tell you which connecting clients are matching your HIP Object.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to quickly see what machines aren't meeting your defined HIP parameters, you could do that easily enough by creating two HIP Profiles. You would simply set it to match or NOT match your HIP Object you defined above, and then you could search for either HIP Profile in your logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So for an example, lets say that I created a HIP Object called "Secured-Clients" and had it match all the criteria you defined. I would then create two HIP Profiles, with the first being "Trusted-Clients" for example that would simply match on the "Secured-Clients" HIP object you created previously. You would then create another HIP Profile called "NonTrusted-Clients" and simply have the match criteria as NOT "Secured-Clients".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When it came to searching who was matching which profile, you can log into the firewall and search the HIP Match logs. To filter on the Trusted-Clients HIP Profile you would simply use the search&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;( matchname eq Trusted-Clients )&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;to find everyone who meets your HIP criteria and then&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;( matchname eq NonTrusted-Clients )&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;to find everyone who doesn't.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just keep in mind that nothing will actually take into account your HIP Profiles until you actually configure it to do so. Simply creating new HIP Objects or HIP Profiles will never cause any issues to your existing profiles.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 01:01:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-profile-monitor-only-initially/m-p/355957#M87596</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-13T01:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: HIP Profile monitor only initially</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-profile-monitor-only-initially/m-p/358464#M87883</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and apolgies for getting back to you late&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured HIP profiles but i have doubt in the syntax&lt;/P&gt;&lt;P&gt;I have created 4 HIP objects for checking AV , OS ,FW and Disk enc for machine in old domain . to check non compliant machines i have done below syntax for HIP profile&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(not "GP-Internal-AV" or not "GP-Internal-OS" or not "GP-Internal-FW" or not "GP-Internal-DiskEncryption" ) and "GP-Internal-Domain-old"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or do i have to put parantheseis like below&lt;/P&gt;&lt;P&gt;((not "GP-Internal-AV" )or (not "GP-Internal-OS") or (not "GP-Internal-FW" )or (not "GP-Internal-DiskEncryption" ) )and "GP-Internal-Domain-old"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Similarly for external machines i have below&lt;/P&gt;&lt;P&gt;(not "GP-External-AV" or not "GP-External-OS" or not "GP-External-FW" or not "GP-External-DiskEncryption" ) and (not "GP-Internal-Domain-Old" )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or the syntax should be ?&lt;/P&gt;&lt;P&gt;((not "GP-External-AV") or (not "GP-External-OS") or (not "GP-External-FW") or (not "GP-External-DiskEncryption" )) and (not "GP-Internal-Domain-New" )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am confused by paranthesis&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 13:29:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-profile-monitor-only-initially/m-p/358464#M87883</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2020-10-23T13:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: HIP Profile monitor only initially</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-profile-monitor-only-initially/m-p/358623#M87902</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133520"&gt;@FWPalolearner&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The syntax for this is a little weird. You don't actually need to include brackets around things you don't want to group. So in your first example, the syntax that I would use would be:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;not ("GP-Internal-AV" or&amp;nbsp; "GP-Internal-OS" or&amp;nbsp; "GP-Internal-FW" or "GP-Internal-DiskEncryption" ) and "GP-Internal-Domain-old"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Likewise your second example I would use:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;not ("GP-External-AV" or "GP-External-OS" or "GP-External-FW" or "GP-External-DiskEncryption" ) and not "GP-Internal-Domain-Old"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Oct 2020 17:19:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-profile-monitor-only-initially/m-p/358623#M87902</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-24T17:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: HIP Profile monitor only initially</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hip-profile-monitor-only-initially/m-p/359882#M88023</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; Thanks . this works . Thanks for your help as always &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 11:35:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hip-profile-monitor-only-initially/m-p/359882#M88023</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2020-10-30T11:35:13Z</dc:date>
    </item>
  </channel>
</rss>

