r/networking 14d ago

Design Global Protect

[deleted]

10 Upvotes

21 comments sorted by

View all comments

1

u/sxtn1996 13d ago

HIP checks work but they let the connection happen first. Better to block at the portal config level with OS matching. Or use machine certs plus SAML so only approved devices even get that far.