Wrong HIP match

cancel
Showing results for 
Search instead for 
Did you mean: 

Wrong HIP match

L4 Transporter

Dear All,

issue:

 

I have the firewall 5220 with PAN-OS 10.0.3 and I am facing an below issue:-

As GlobalProtect 5.2.6 is released with support for OPSWAT v4 only while OPSWAT v3 is discontinued starting from 5.2.6, I tried to test it on a few machines.

 

We apply HIP checking for the below:

-        FireEye Endpoint Agent – Installed & Real Time Protection = Yes & Product Version >= 31.0.0 & Virus Definition Version is within last 7 days

In the HIP logs, I checked FireEye Endpoint Agent detect the wrong Virus Definition Version date as 1/1/1970.

I rolled back to GlobalProtect 5.2.5-c84, and FireEye Endpoint Agent is detected with the correct Virus Definition Version.

 

Below is the screenshot update GP -5.2.6 showing wrong information:-

Agent screen shot:-

 

Jafar_Hussain_0-1620221429240.png

 

 

The same HIP logs below:-

 

Jafar_Hussain_1-1620221429270.png

 

 

 

 

Once I rollback the GP version is 5.2.5 the logs showing correct.

 

Jafar_Hussain_2-1620221429286.png

 

 

Jafar_Hussain_3-1620221429307.png

 

 

# When I checked the logs by below command with GP version 5.2.6:-

 

  • debug user-id dump hip-report ip <IP address> user <domain\username> computer <system name>

 

<client-version>5.2.6-84</client-version>

<ProductInfo> <Prod vendor="FireEye, Inc." name="FireEye Endpoint Agent" version="32.30.0" defver="" engver="" datemon="1" dateday="1" dateyear="1970" prodType="3" osType="1"/>

<real-time-protection>yes</real-time-protection>

<last-full-scan-time>n/a</last-full-scan-time>

# When I checked the logs by below command with GP version 5.2.5:-

 

  • debug user-id dump hip-report ip <IP address> user <domain\username> computer <system name

 

<client-version>5.2.5-84</client-version>

<ProductInfo>

<Prod vendor="FireEye, Inc." name="FireEye Endpoint Agent" version="32.30.0" defver="2021.05.05" engver="" datemon="5" dateday="5" dateyear="2021" prodType="3" osType="1"/>

<real-time-protection>yes</real-time-protection>

<last-full-scan-time>n/a</last-full-scan-time>

 

Can any one help on this.

2 REPLIES 2

Community Team Member

Hi @Jafar_Hussain ,

 

From the looks of it the new OPSWAT database version is unable to correctly identify some of the product information. 

Please gather your findings and contact support as it might need a fix/update.

 

Cheers,

-Kiwi.

 

@kiwu 

I opened a case with TAC support. this issue with current version 5.2.6 they will fix this issue in new release. 5.2.7

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!