- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-12-2023 12:09 PM
Hello valued community, unfortunately, I am still seeking answers for my issue.
I have an HIP profile that works when defined as an example for someone establishing a VPN connection using RDP. However, I am unable to achieve results when applied to a WAN rule.
Precisely, what I want to achieve is this: If it doesn't meet the conditions specified in HIP, it should not establish a VPN connection. Based on the information I gathered through my research, it seems I need to apply the HIP profile to the WAN rule.
When I test it, it does not seem to apply to that rule conclusively. It passes through to the next rule without HIP checks, which I have created as a backup.
What do you think I should do? I am eagerly awaiting the responses of esteemed professionals. Thank you.
09-12-2023 04:44 PM
Hi @omertaskin ,
A failed HIP check does NOT cause GlobalProtect (GP) to disconnect.
Instead, the HIP Profile is used in a security policy rule to allow access. To deny access to traffic that does not match, do not have any rule with the GP source zone that allows traffic without a HIP Profile.
It your GP clients do not match your rule with a HIP Profile, they may not be matching. Here is how you can troubleshoot.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boP1CAI
Thanks,
Tom
09-12-2023 04:44 PM
Hi @omertaskin ,
A failed HIP check does NOT cause GlobalProtect (GP) to disconnect.
Instead, the HIP Profile is used in a security policy rule to allow access. To deny access to traffic that does not match, do not have any rule with the GP source zone that allows traffic without a HIP Profile.
It your GP clients do not match your rule with a HIP Profile, they may not be matching. Here is how you can troubleshoot.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boP1CAI
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!