Maybe El Capitan is supported by 2.3.2 (it's working, yep) but I cannot choose the OS version in HiP Objects on the Firewall.
I know that I can type in "10.11"manually and the GP client shows me the running version in "Host State -> Host-info -> OS" but it looks like the GP Client cannot check things like the status of the disk-encryption.
Does anyone know when PaloAlto will support 10.11 for the HiP configuration?
We have users trying 10.11.1 and while it appears the VPN portion of GlobalProtect is working, the HIP checks are failing to operate, as expected, since the v2.3.2 client doesn't officially support OSX 10.11.
Here is a Hip Check detailed record from one of our 10.11.1 users:
I'm disappointed that PAN didn't support OSX 10.11.0 at release, let alone at 10.11.1, since Developer / beta versions were available for quite a long period prior to release.
I look forward to a version of the GlobalProtect client that fully supports OSX 10.11 so I can make my users happy.
Update: Working well in production - recommended.
One cosmetic caveat: In the OSX client, if you go into the Panel -> Host State tab, you will find that for many categories, the Prod data is not displayed. Its cosmetic only - the correct data does go to the firewalls. Fix is slated for version 2.3.4.
Some good news for the day: The GlobalProtect 2.3.3-5 client with application content 539 (or later) seems to be the magic combination. Both VPN and HIP Checks are working properly on our OSX 10.11.1 test "victim" machines. User testing is scheduled - but so far, so good
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!