- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-16-2019 03:22 AM
(GlobalProtect only) Select this option if you want the firewall to block sessions when the serial number attribute in the subject of the client certificate does not match the host ID that the GlobalProtect app reports for the endpoint. Otherwise, the firewall allows the sessions. This option applies only to GlobalProtect certificate authentication.
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-web-interface-help/device/device-certificate-man...
12-16-2019 09:31 AM
Hello!
I thought that you could only do HIP checks (like looking at the SN, wherever it is found) AFTER the license was purchased.
Is there something that has changed?
So I am not sure how you can test this adequately, because HIP is how it should be done with GP.
Let's keep working together towards a resolution.
12-16-2019 10:38 PM
Hi Steve
Thanks for your reply. I've tried with HiP. According our local Palo Alto partner here. Not all features on HiP check is implements for Linux as for Windows.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!