08-13-2018 09:58 AM
I've been tasked to have Globalprotect only allow company owned devices over the VPN. I know I can create custom HIP checks for Windows/Mac (reg/plist value). How would I do the same for Linux clients?
I have two end users that work remote, and are on a Linux machine. Still having issues with getting the GlobalProtect client for linux to work properly. VNC with IPSec is how they currently connect, and it works fine. I'm only on version 4.1.2, and am working on upgrading to 4.1.4 in hopes it corrects my problem.
The problem I'm having with the Linux client is that it fails because it doesn't trust the server certificate. However, when you navigate to the portal there is no certificate error.
Linux client problems aside... I'm trying to find the best answer to meet this initiative -> Only allow our devices on the VPN
Is the HIP check the best/easiest answer, or should I be looking elsewhere?
Thanks for all your help,
08-13-2018 11:27 AM
You could query 'dnsdomainname' and verify that the output matches your domain; this would at least ensure that the linux machine is joined to your AD. Just keep in mind that there really isn't anything stopping a user from doing a domain join on a different linux machine as long as they have a user within your domain unless you have restricted those permissions. Most enviroments seem to forget that by default users have the ability to do a domain join operation.
08-13-2018 11:36 AM
That's what I was thinking of as well. The two users are using Mint 18 Cinnamon. Mint isn't recognizing dnsdomainname, but does respond with domainname though it reports none. However, I can run realm list and see the domain.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!