<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wrong HIP match in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-hip-match/m-p/409191#M92418</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155591"&gt;@kiwu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I opened a case with TAC support. this issue with current version 5.2.6 they will fix this issue in new release. 5.2.7&lt;/P&gt;</description>
    <pubDate>Wed, 26 May 2021 11:50:53 GMT</pubDate>
    <dc:creator>Jafar_Hussain</dc:creator>
    <dc:date>2021-05-26T11:50:53Z</dc:date>
    <item>
      <title>Wrong HIP match</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-hip-match/m-p/404948#M91958</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the firewall 5220 with PAN-OS 10.0.3 and I am facing an below issue:-&lt;/P&gt;&lt;P&gt;As GlobalProtect 5.2.6 is released with support for OPSWAT v4 only while OPSWAT v3 is discontinued starting from 5.2.6, I tried to test it on a few machines.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We apply HIP checking for the below:&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FireEye Endpoint Agent – Installed &amp;amp; Real Time Protection = Yes &amp;amp; Product Version &amp;gt;= 31.0.0 &amp;amp; Virus Definition Version is within last 7 days&lt;/P&gt;&lt;P&gt;In the HIP logs, I checked FireEye Endpoint Agent detect the wrong Virus Definition Version date as 1/1/1970.&lt;/P&gt;&lt;P&gt;I rolled back to GlobalProtect 5.2.5-c84, and FireEye Endpoint Agent is detected with the correct Virus Definition Version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the screenshot update GP -5.2.6 showing wrong information:-&lt;/P&gt;&lt;P&gt;Agent screen shot:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1620221429240.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33639i69AD174C36B1140B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1620221429240.png" alt="Jafar_Hussain_0-1620221429240.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The same HIP logs below:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_1-1620221429270.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33638i2C2C28931BFA0027/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_1-1620221429270.png" alt="Jafar_Hussain_1-1620221429270.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once I rollback the GP version is 5.2.5 the logs showing correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_2-1620221429286.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33637iACA14BD879A67141/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_2-1620221429286.png" alt="Jafar_Hussain_2-1620221429286.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_3-1620221429307.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33640i93552257F0F14BF1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_3-1620221429307.png" alt="Jafar_Hussain_3-1620221429307.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# When I checked the logs by below command with GP version 5.2.6:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;debug user-id dump hip-report ip &amp;lt;IP address&amp;gt; user &amp;lt;domain\username&amp;gt;&amp;nbsp;computer &amp;lt;system name&amp;gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;client-version&amp;gt;5.2.6-84&amp;lt;/client-version&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;ProductInfo&amp;gt; &amp;lt;Prod vendor="FireEye, Inc." name="FireEye Endpoint Agent" version="32.30.0" defver="" engver="" &lt;FONT face="times new roman,times" color="#3366FF"&gt;&lt;EM&gt;&lt;STRONG&gt;datemon="1" dateday="1" dateyear="1970"&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt; prodType="3" osType="1"/&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;real-time-protection&amp;gt;yes&amp;lt;/real-time-protection&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;last-full-scan-time&amp;gt;n/a&amp;lt;/last-full-scan-time&amp;gt;&lt;/P&gt;&lt;P&gt;# When I checked the logs by below command with GP version 5.2.5:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;debug user-id dump hip-report ip &amp;lt;IP address&amp;gt; user &amp;lt;domain\username&amp;gt;&amp;nbsp;computer &amp;lt;system name&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;client-version&amp;gt;5.2.5-84&amp;lt;/client-version&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;ProductInfo&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Prod vendor="FireEye, Inc." name="FireEye Endpoint Agent" version="32.30.0" &lt;FONT face="times new roman,times" color="#0000FF"&gt;&lt;EM&gt;&lt;STRONG&gt;defver="2021.05.05" engver="" datemon="5" dateday="5" dateyear="2021&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;" prodType="3" osType="1"/&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;real-time-protection&amp;gt;yes&amp;lt;/real-time-protection&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;last-full-scan-time&amp;gt;n/a&amp;lt;/last-full-scan-time&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can any one help on this.&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 13:34:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wrong-hip-match/m-p/404948#M91958</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2021-05-05T13:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Wrong HIP match</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-hip-match/m-p/405429#M92002</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the looks of it the new OPSWAT database version is unable to correctly identify some of the product information.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please gather your findings and contact support as it might need a fix/update.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 07 May 2021 07:24:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wrong-hip-match/m-p/405429#M92002</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-05-07T07:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Wrong HIP match</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-hip-match/m-p/409191#M92418</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155591"&gt;@kiwu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I opened a case with TAC support. this issue with current version 5.2.6 they will fix this issue in new release. 5.2.7&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 11:50:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wrong-hip-match/m-p/409191#M92418</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2021-05-26T11:50:53Z</dc:date>
    </item>
  </channel>
</rss>

