Global Protect 1.2 & HIPS

Reply
DaveM
L1 Bithead

Global Protect 1.2 & HIPS

Hi,

Has anyone seen any problems with GP 1.2 and HIPS, particularly the domain check? Since upgrading to 1.2 the HIPS check we have to determine if the PC is a member of specific domains fails. When we look at the client on a PC (running windows 7) it no longer shows the domain under the host info section? It still shows the OS and Host Name as well as AV, NIC's etc but nothing about the domain.

Thanks

Dave

BrutalDismount
L1 Bithead

I see this with my installation of 1.2. however I do see it being populated correctly on the firewall HIP Match.

DaveM
L1 Bithead

I seem to be getting odd results with the firewall rule - it seems a bit hit and miss but certainly not consistent, I'm seeing some users hit rules further down the rule base rather than get matched by the rule with the HIP check.  The HIP match rule on the gateway which uses the same HIP profile is displaying the not matched message for all my users who are on the 1.2 client.

mikand
L6 Presenter

What if you run the "test" command in cli?

Will it be random aswell on which rule it will hit?

DaveM
L1 Bithead

Do you have the syntax for the command?

mikand
L6 Presenter

Depends on which PANOS version you have, but check the "CLI Reference Guide" over at

DaveM
L1 Bithead

It actually looks like from 1.2 onwards the HIP check for the Domain no longer looks at the Host Domain of the PC you are connecting from but the Domain of the user authenticating with the global protect client. We where using this to restrict users with non company devices but with a domain account to specific applications, IP ranges etc. - This change has unfortunately broken this functionality for us.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!