<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Globalprotect check operational system on the portal/gateway without collecting HIP data and using HIP profiles/HIP objects? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-check-operational-system-on-the-portal-gateway/m-p/407383#M92227</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you need HIP data collection for HIP checks.&lt;/P&gt;&lt;P&gt;- Data collection will tell the client to generate XML report and submit it to the gateway. It will also tell it what information to add in the report&lt;/P&gt;&lt;P&gt;- Once FW receives the report it will run it agains the configured HIP profiles and check what is matching&lt;/P&gt;&lt;P&gt;- It will then cache/associate that username/soure-ip with all matching HIP profiles.&lt;/P&gt;&lt;P&gt;You can see all matching HIP profiles for given user with:&lt;/P&gt;&lt;P&gt;&amp;gt; show user ip-user-mapping ip &amp;lt;ip-address&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt; that OS type, that is used as match criteria for gp client config is not data submitted by host, but it is information that FW is detecting by identifying what application is used to connect. If you have noticed the same way you can configure different authentication method based on the client OS. If you think about it, this means that FW needs to know what OS used even before the user has authenticated. In this case it make sense client OS to be determed by HTTP User-Agent or any banner that GlobalProtect application sent when is trying to connect. But this information is not kept and it is not used for HIP check. Information submitted by the client as HIP report is used for that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 May 2021 21:55:59 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2021-05-17T21:55:59Z</dc:date>
    <item>
      <title>Globalprotect check operational system on the portal/gateway without collecting HIP data and using HIP profiles/HIP objects?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-check-operational-system-on-the-portal-gateway/m-p/406804#M92159</link>
      <description>&lt;P&gt;I found out that you can use the operational system without a HIP object/profile to do things on the Gateway/Portal even if the collection of HIP data is stopped on the Portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Portal config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NikolayDimitrov_1-1621011523428.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33842iCAAC1A1B3F3172F1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="NikolayDimitrov_1-1621011523428.png" alt="NikolayDimitrov_1-1621011523428.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gateway Config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NikolayDimitrov_0-1621011296270.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33841i2E9395AE61DF0A9F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="NikolayDimitrov_0-1621011296270.png" alt="NikolayDimitrov_0-1621011296270.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone tell me why when I try to check if the operational system is Linux in a HIP object/profile and I attach it to security policy I get blocked? I see that even without HIP checks the Gateway knows the operational system of the client even when Portal HIP data collection is stopped?&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 16:59:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-check-operational-system-on-the-portal-gateway/m-p/406804#M92159</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-05-14T16:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect check operational system on the portal/gateway without collecting HIP data and using HIP profiles/HIP objects?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-check-operational-system-on-the-portal-gateway/m-p/406871#M92170</link>
      <description>&lt;P&gt;I think that the gateway knowing what operating system the client using and then using that information to block or allow are 2 different things. The client is clearly announcing to the gateway what it is because of the software being used.&lt;/P&gt;
&lt;P&gt;Was this working for you and then stopped?&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 21:32:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-check-operational-system-on-the-portal-gateway/m-p/406871#M92170</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-05-14T21:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect check operational system on the portal/gateway without collecting HIP data and using HIP profiles/HIP objects?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-check-operational-system-on-the-portal-gateway/m-p/406967#M92176</link>
      <description>&lt;P&gt;Nothing my idea is that I am testting the general HIP checks as a new design/project but we have stopped the HIP data collection option on the portal and it does not work but as I mentioned outside the HIP checks like making split tunnel just for Linux or Windows or Mac etc. devices on the Gateway seems to work in my lab even without the HIP data collection option being enabled on the portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So even without HIP data collection being enabled on the portal the gateway can do some rules based on the workstation OS or domain but not for a HIP object/profile attached under security that checks the operational system. Is this how it works?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For any HIP check do I need to enable the option for HIP data collection on the portal even if it is just the OS that the gateway seems to know even before the HIP checks?&lt;/P&gt;</description>
      <pubDate>Sat, 15 May 2021 10:17:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-check-operational-system-on-the-portal-gateway/m-p/406967#M92176</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-05-15T10:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect check operational system on the portal/gateway without collecting HIP data and using HIP profiles/HIP objects?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-check-operational-system-on-the-portal-gateway/m-p/407383#M92227</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you need HIP data collection for HIP checks.&lt;/P&gt;&lt;P&gt;- Data collection will tell the client to generate XML report and submit it to the gateway. It will also tell it what information to add in the report&lt;/P&gt;&lt;P&gt;- Once FW receives the report it will run it agains the configured HIP profiles and check what is matching&lt;/P&gt;&lt;P&gt;- It will then cache/associate that username/soure-ip with all matching HIP profiles.&lt;/P&gt;&lt;P&gt;You can see all matching HIP profiles for given user with:&lt;/P&gt;&lt;P&gt;&amp;gt; show user ip-user-mapping ip &amp;lt;ip-address&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt; that OS type, that is used as match criteria for gp client config is not data submitted by host, but it is information that FW is detecting by identifying what application is used to connect. If you have noticed the same way you can configure different authentication method based on the client OS. If you think about it, this means that FW needs to know what OS used even before the user has authenticated. In this case it make sense client OS to be determed by HTTP User-Agent or any banner that GlobalProtect application sent when is trying to connect. But this information is not kept and it is not used for HIP check. Information submitted by the client as HIP report is used for that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 21:55:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-check-operational-system-on-the-portal-gateway/m-p/407383#M92227</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-05-17T21:55:59Z</dc:date>
    </item>
  </channel>
</rss>

