This section will provide information on how to create host compliance profile with
host compliance objects.
You can create a HCP that you plan to use in your security policy rules by adding
existing HCOs that you have created for your endpoints. The HCP then acts as a
matching condition within your security policy rules.
HCP uses one or more HCOs to define a security checklist for your firewall. When a
device connects, the firewall performs a HIP match to verify the device meets all
the criteria defined in the HCP.
Based on this information, the firewall automatically enforces security rules to
allow or deny access to the GlobalProtect user, ensuring that only compliant
endpoints can connect.
When a traffic flow is evaluated against a security policy, it is checked against the
Host Compliance Profile:
- If there is a match: The corresponding security
policy rule is enforced.
- If there is no match: The flow is evaluated against
the next rule in sequence, as with any other security policy matching
criteria.
To configure a HCP: