Network Security
Add a HIP Object (Strata Cloud Manager)
Table of Contents
Expand All
|
Collapse All
Network Security Docs
Add a HIP Object (Strata Cloud Manager)
Define objects for a host information profile (HIP).
Select to define objects for a host information profile (HIP). HIP objects
provide the matching criteria for filtering the raw data reported by an app that you
want to use to enforce policy. For example, if the raw host data includes
information about several antivirus packages on an endpoint, you might be interested
in a particular application because your organization requires that package. For
this scenario, you create a HIP object to match the specific application you want to
enforce.
Manage
Configuration
NGFW and Prisma Access
Objects
HIP
HIP Objects
The best way to determine the HIP objects you need is to determine how you will use
the host information to enforce the policy. Keep in mind that the HIP objects are
merely building blocks that allow you to create the HIP Profiles that your security
rules can use. Therefore, you may want to keep your objects simple, matching on one
thing, such as the presence of a particular type of required software, membership in
a specific domain, or the presence of a specific endpoint OS. With this approach,
you have the flexibility to create a very granular, HIP-augmented policy.
To create a HIP object, select
Add HIP Object
to open the HIP
object dialog. For a description of what to enter in a specific field, see the
tables that follow.For more detailed information on creating HIP-augmented security rules, refer
to Configure HIP-Based Policy Enforcement in
the GlobalProtect Administrator’s Guide.
Create a HIP Profile
HIP Profile is a collection of HIP objects to be evaluated together
either for monitoring or for Security policy enforcement that you use to set up
HIP-enabled security rules. When creating HIP Profiles, you can combine
the HIP objects you previously created (as well as other HIP Profiles) by using
Boolean logic, so that when a traffic flow is evaluated against the resulting
HIP Profile, it will either match or not match. Upon a match, the corresponding
security rule is enforced; if there is no match, the flow is evaluated against the
next rule (as with any other policy matching criteria).
- Go to.ManageConfigurationNGFW and Prisma AccessObjectsHIPHIP Profiles
- Add HIP Profile.
- Configure the settings in this table:HIP Profile SettingsDescriptionNameEnter a name for the profile (up to31characters). The name is case-sensitive and must be unique. Use only letters, numbers, spaces, hyphens, and underscores.Description(Optional) Enter a description.MatchClickAdd Match Criteriato open the HIP Objects/Profiles Builder.Select the first HIP object or profile you want to use as match criteria and then add it to theMatchtext box on the HIP Objects or Profiles Builder dialog. Keep in mind that if you want the HIP Profile to evaluate the object as a match only when the criteria in the object are not true for a flow, selectNOTbefore adding the object.Continue adding match criteria as appropriate for the profile you're building, and ensure you select the appropriate Boolean operator (ANDorOR) between each addition (and using theNOToperator when appropriate).To create a complex Boolean expression, you must manually add the parenthesis in the proper places in theMatchtext box to ensure that the HIP Profile is evaluated using the intended logic. For example, the following expression indicates that the HIP Profile will match traffic from a host that has either FileVault disk encryption (Mac OS systems) or TrueCrypt disk encryption (Windows systems) and also belongs to the required Domain and has a Symantec antivirus client installed:((“MacOS” and “FileVault”) or (“Windows” and “TrueCrypt”)) and “Domain” and “SymantecAV”When you have finished adding the objects and profiles to the new HIP Profile, clickOK.
- Saveyour configuration.
- SelectPush Configto save your configuration and deploy it to your network.
Disable Default HIP Profiles
In
Strata Cloud Manager
, the default HIP objects and HIP profiles are moved from
the Global-Default snippet to the HIP-Default snippet. This gives you more
flexibility in managing the default HIP profiles. You have the option to disable
these default HIP profiles by disassociating the HIP Default snippet from the
global folder.- Log intoStrata Cloud Manager.
- Selectand expand theManageConfigurationNGFW and Prisma AccessOverview ScopeConfiguration Scopeto view theSnippets.
- SelectHIP-Default.You’re redirected to the snippetOverview.
- Edit theSnippet Associationsto disassociate HIP profiles from the Global folder.
- Exit the snippet association screen to apply the changes.
- Follow these steps to selectively enable the default HIP profiles.
- Go toand select theObjectsHIPHIP ProfilesHIP Profiles.
- Expand the Configuration Scope to view theSnippets.
- Click the three vertical dots of theHIP-Defaultsnippet andClonethe HIP profile as a custom snippet.
- Give the cloned snippet a new name.
- Select the cloned snippet underCustom.
- Select thethat you want toHIP ProfilesDelete.
- Go to, and edit theHIP-DefaultOverviewSnippet Associationsto associate the cloned snippet to the global folder.