HIP profiles for internal outbound traffic

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

HIP profiles for internal outbound traffic

L1 Bithead

Hello Community, I hope you are well. I need to apply our security posture for internal user browsing.

 

I would like to know if it is possible to apply HIP profiles for internal users (not vpn ssl connections). Just installing Globalprotect on the workstations is enough to collect the host information ?.

 

Thank you !

5 REPLIES 5

Cyber Elite
Cyber Elite

Good Day

 

Your company will have needed to purchase a Global Protect gateway license to utilize the HIP profile feature.

 

Thanks

 

 

Help the community: Like helpful comments and mark solutions

Cyber Elite
Cyber Elite

@MauricioPerez,

On internal clients just having the GlobalProtect app installed actually isn't enough to do this properly. You'd want to setup Internal Host Detection so that the clients can identify when they are internal to your network, and then configure an internal gateway. There's quite a bit of documentation on how one would go about setting up an internal gateway but THIS is a really quick one which is essentially exactly what you're looking to do. 

 

As @SCantwell_IM pointed out, you will actually need a GlobalProtect subscription to support this. I'm assuming since you're asking that you already are aware of this and that you have one, but if not you'll need to get one to move forward. 

Thanks for the answers,

 

I am clear that the globalprotect gateway license is required, and I am also clear about how to configure an internal gateway, my question was focused on whether there is any way to apply HIP profiles on internal traffic of users who do not have to authenticate in globalprotect app to connect to an internal gateway, but something more transparent for the user.

 

I am very grateful,

@MauricioPerez,

So that's where you need to have Always On enabled instead of on demand. If you setup certificate authentication or SSO your users will automatically authenticate to GlobalProtect and they don't need to interact with it at all. It essentially just becomes a background process that they don't have to worry about. 

Thank you, that has been very useful for me.

  • 3110 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!