r/networking 14d ago

Design Global Protect

[deleted]

10 Upvotes

21 comments sorted by

View all comments

7

u/rahomka 14d ago

Look at HIP checks

2

u/trafficblip_27 14d ago

Yep HIP rules is the way to go

5

u/RagingNoper 14d ago

Depends on their infrastructure. HIP checks still let users connect and authenticate. HIP security profile can't be applied until after they've connected and sent the HIP data. If this is an unwanted device, you're better off preventing connections completely. Portal auth configs allow you to specify OS as match criteria. Or you could combine saml with machine certs so only devices with assigned and installed certs can connect and authenticate.

3

u/trafficblip_27 14d ago

Yep agree. We deployed in such a way that it checks OS and patches and certain things that would be deployed while the pc was issued. Even deployed for a coffee shop style of office but very granular. It doesnt necessarily tear the tunnel but agree to your point