How to configure Global Protect for certificate-based HIP match
9926
Created On 07/06/22 19:45 PM - Last Modified 03/15/26 09:16 AM
Objective
Steps to configure the Global Protect for certificate-based HIP match
Environment
- GlobalProtect
- Prisma Access
- Existing PKI
Procedure
- Navigate to Device > Certificates and import the CA certificate
- Navigate to Device> Certificate Profile and configure certificate profile
- Navigate to Portal > Agent > (Config-name) > HIP data collection and use the certificate profile configured in step 2 for HIP processing
- Navigate to Objects > HIP Objects and configure the HIP object with match criteria.
NOTE: Do note the format in which the value is configured. The value has to match the subject in the Certificate information. Here it is /DC=local/DC=su-lab/CN=SU-LAB-CA
- Import the client certificate on the user's machine in the local machine store. The certificate should be installed with the KEY.
- Navigate to the Global Protect App Host information tab for validation
Additional Information
For best practices regarding certificate configuration for GlobalProtect, please refer to the following document: