Hi, could you please explain how HIP check for certificates work or how to implement that certain check ?
@mode4480 Жыл бұрын
Hi, Certainly I can, it would be a bit long to put in a reply, but I will put together a lab sessions video as soon as I can, thank you for watching.
@cbesc Жыл бұрын
At 3:10, under host info you mentioned the Managed field. I couldn't find in Palo's docs that go into detail for MECM, Intune, jamf coverage. Is this what this field is for?
@mode4480 Жыл бұрын
Hi, That field is used to match on if an endpoint is managed or not, There is little to no documentation that I could find either to understand the mechanism it uses to determine if a device is managed or not, logically I guess it would look for the service running. If you have access to a firewall, when configuring a HIP object if you click the ? in the top right of the dialogue box you can access the help file that is on the box (apologies if you already know this) but alas that simply states that it checks for management but not what device management it supports, I can confirm that it works for intune and jamf however from experience. Hope this helps, and thank you very much for watching.
@cbesc Жыл бұрын
@Mode44 The question mark has the same description as the documentation, unfortunately. Luckily, we are using Intune as well. Thanks for replying! I'll do some testing now.
@jairathor58209 ай бұрын
Can you help me understand why logs are generated for policy verification realted to src hip and dst hip target negate no