- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-21-2020 08:22 AM
Hello Community, I hope you are well. I need to apply our security posture for internal user browsing.
I would like to know if it is possible to apply HIP profiles for internal users (not vpn ssl connections). Just installing Globalprotect on the workstations is enough to collect the host information ?.
Thank you !
12-21-2020 02:13 PM
Good Day
Your company will have needed to purchase a Global Protect gateway license to utilize the HIP profile feature.
Thanks
12-21-2020 03:13 PM
On internal clients just having the GlobalProtect app installed actually isn't enough to do this properly. You'd want to setup Internal Host Detection so that the clients can identify when they are internal to your network, and then configure an internal gateway. There's quite a bit of documentation on how one would go about setting up an internal gateway but THIS is a really quick one which is essentially exactly what you're looking to do.
As @S.Cantwell pointed out, you will actually need a GlobalProtect subscription to support this. I'm assuming since you're asking that you already are aware of this and that you have one, but if not you'll need to get one to move forward.
12-22-2020 07:06 AM
Thanks for the answers,
I am clear that the globalprotect gateway license is required, and I am also clear about how to configure an internal gateway, my question was focused on whether there is any way to apply HIP profiles on internal traffic of users who do not have to authenticate in globalprotect app to connect to an internal gateway, but something more transparent for the user.
I am very grateful,
12-22-2020 08:27 AM
So that's where you need to have Always On enabled instead of on demand. If you setup certificate authentication or SSO your users will automatically authenticate to GlobalProtect and they don't need to interact with it at all. It essentially just becomes a background process that they don't have to worry about.
12-22-2020 08:46 AM
Thank you, that has been very useful for me.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!