Version 1.0 • Technical Case StudyCONFIDENTIAL
Security Engineering & Automated Coexistence Validation

PANW Interop Automation

GlobalProtect / Prisma Access Agent — Third-Party Interoperability & Automation Framework

A technical case study documenting the automated coexistence-testing framework validating GlobalProtect and Prisma Access Agent alongside third-party XDR, DLP, and VPN products across Windows and macOS endpoints.

Testing ScopeXDR · DLP · VPN
Target PlatformsWin 10/11 • macOS 13–15
Vendors Tested10+ Security Vendors
Test Lifecycle33-Step Unattended
01

Executive Summary

This document presents the technical case study of the PANW Interop Automation initiative — an engineering effort validating that Palo Alto Networks' GlobalProtect (GP) and Prisma Access Agent (PAA) remain fully functional, and that Host Information Profile (HIP) posture reporting stays accurate, when co-installed alongside third-party XDR/EDR, DLP, and VPN products on Windows and macOS endpoints.

Engineering Objectives

  • Validate GP and PAA remain fully functional with zero degradation between co-installed agents.
  • Confirm HIP posture data (antimalware, firewall, encryption, DLP, patches) remains accurate across all scenarios.
  • Verify tunnel priority, routing tables, and DNS resolution when a second VPN client is simultaneously connected.

Why Automate?

Manual coexistence testing is slow, inconsistent, and does not scale across 10+ vendors and two operating systems. Results vary widely between human testers and minor patch revisions.

This project converts the entire test lifecycle — installation, validation, scanning, and uninstallation — into an unattended framework with zero human interaction required after launch, enabling repeatable regression testing on every vendor release.

Core Framework Metrics & ScopeAuditable Evidence
10+
Vendors Tested
2
OS Platforms (Win & Mac)
33
Automated Lifecycle Steps
4
Report Formats Generated
5
HIP Posture Categories
02

Project Overview

2.1 The Problem Statement

Enterprise endpoints rarely run a single security agent in isolation. GP or PAA is typically deployed alongside an XDR/EDR product, a DLP agent, and — in many real-world environments — a second, third-party VPN client that predates or is layered onto the PANW deployment. Any of these combinations can interfere with kernel/network extensions, HIP data collection, or tunnel routing, and those failures are notoriously difficult to catch through ad-hoc manual testing.

2.2 What the Framework Does

1

Installs a target third-party product (XDR, DLP, or VPN client) on a clean Windows or macOS endpoint with GP/PAA already present.

2

Connects to VPN and downloads the HIP report, asserting that all five posture categories are populated correctly.

3

Runs a full health, detection, and network-policy validation suite against the coexisting products.

4

Uninstalls the third-party product and verifies clean removal, leaving the endpoint ready for the next test cycle.

2.3 Primary Stakeholders

Field Engineers & TAC

Consume HTML & PDF reports to troubleshoot customer coexistence escalations with proof-backed logs.

Partner & Product Teams

Use structured JSON results for regression tracking across frequent vendor agent version releases.

Security / QA & Compliance

Review raw HIP XML artifacts to confirm posture-reporting accuracy and baseline compliance standards.

03

Products & Vendors in Scope

All products are tested on Windows 10/11 and macOS 13, 14, and 15, unless otherwise noted.

3.1 Palo Alto Networks Core Products
GlobalProtect (GP)Endpoint VPN client with Host Information Profile (HIP) reporting for posture visibility and gateway policy enforcement.
Prisma Access Agent (PAA)Cloud-delivered ZTNA + security services agent — successor to GP in cloud-first and hybrid enterprise deployments.
3.2 XDR / EDR Products (Windows + macOS)
Trellix (McAfee) ENSENS 10.7+; requires coexistence mode configuration and specific exclusion policy.
SentinelOne Singularity XDRKernel extension present on macOS; agent tamper protection and deep packet inspection.
Symantec SEPSEPM-managed; firewall policy interaction and driver binding tested.
CrowdStrike FalconSensor + kernel driver; auto-updates in place; zero-degradation validation.
Trend Micro Apex OneOfficeScan / Apex One on-prem deployment and security agent hooks.
Sophos Intercept XCentral-managed; tamper protection enabled; exploit mitigation coexistence.
3.3 DLP (Windows + macOS)
Forcepoint DLPEndpoint agent + content classification filter.
Trellix DLP EndpointMcAfee-heritage product; policy managed via ePO/MVISION.
3.4 VPN Clients (Windows + macOS)
FortiClient VPNFortinet SSL and IPSec; split-tunnel override scenarios tested.
Ivanti Secure AccessPulse-heritage; ISAC agent coexistence and DNS binding.
Zscaler Client ConnectorZCC ZTNA; route and DNS conflict scenarios verified.
04

HIP Report Validation

After every VPN connect, the framework automatically downloads the Host Information Profile (HIP) report and asserts accurate posture extraction across five mission-critical categories on both Windows and macOS:

4.1 Antimalware

Asserts vendor & product name, engine version, definition/DAT version, Real-Time Protection (RTP) state, last full scan timestamp, on-access scan enabled.

Validates 3rd-party AV registers correctly without suppressing PANW detection.
4.2 Firewall

Asserts product name & vendor, enabled/disabled state, inbound traffic enforcement, outbound traffic enforcement, policy version string.

Confirms 3rd-party firewall never masks PANW policy evaluation.
4.3 Drive Encryption

Asserts FDE product name, encryption enabled state, algorithm (BitLocker / FileVault / other), drive-level encryption scope.

FDE posture remains readable alongside OS-native encryption.
4.4 DLP

Asserts product name, running/active state, policy version, and last policy sync timestamp.

Guarantees gateway can enforce DLP-based security rules.
4.5 Patch Management

Asserts patch management tool name, missing critical patches count, last assessment timestamp, and assessment tool version string.

Confirms patch compliance reporting remains undisturbed by 3rd-party update engines.
05

Automation Framework & Architecture

The framework is a Python-based orchestrator with OS-specific modules and vendor-native script overrides, invoked through native auto-elevating launchers on each platform.

panw-interop-automation/ Project ArchitecturePython 3.10+ Orchestrator
panw-interop-automation/
├── run.ps1 / run.sh           # Native Windows/macOS auto-elevating launchers
├── main.py                    # Core Python Orchestrator (--vendor, --phase, --os)
├── .env.template              # Template for API tokens & auto-logon secrets
├── config/
│   └── config.yaml            # Central single-source-of-truth configuration
├── installers/                # Directory structure for vendor binaries & secrets
│   └── <vendor>/{windows,mac}/
├── core/
│   ├── windows/, mac/         # OS-specific Install, Validate, Scan, Uninstall logic
│   ├── desktop/               # PyWinAuto wizard automation & dialog watchers
│   ├── network/               # Remote WinRM firewall probing modules
│   └── reporting/             # HTML, JSON, PDF & HIP report generation engine
├── scripts/
│   ├── common/                # Generic fallback PowerShell & Bash scripts
│   └── <vendor>/{windows,mac}/# Vendor-specific native script overrides
├── reports/                   # Output directory for HTML/JSON/PDF/HIP reports
└── logs/                      # Rotating execution logs & pending run states
5.2 Module Responsibilities & Capabilities
main.py — OrchestratorEntry point (--vendor --phase --os --hip --report). Reads config.yaml, injects credentials from .env, selects the OS-specific module chain, runs each phase in order, collects results.
core/windows/, core/mac/OS-specific phase handlers: Install, Validate, Scan, Uninstall. Self-contained execution — install handles elevation, popups and reboots; validate asserts service health; scan runs EICAR; uninstall performs full cleanup.
core/desktop/PyWinAuto-based GUI automation and dialog watchers — license dialogs, macOS extension-approval popups, Windows UAC prompts, and interactive uninstall menus, with vendor-specific dialog patterns registered per vendor.
core/network/Remote firewall policy probing via WinRM; validates inbound/outbound block rules, gateway reachability, DNS resolution, and HTTPS connectivity post-install.
core/reporting/Generates all report artifacts at run completion — HTML with pass/fail badges, timing and vendor logos; HIP XML parsed and annotated with per-category assertion results.
06

Automated Test Lifecycle (33 Steps)

A 33-step, fully unattended flow — zero human interaction from installer staging through post-uninstall cleanup — organized into six distinct execution phases:

6.1 Pre-Flight Phase6 Steps
• Stage / obtain installer file before script execution
• Execute automation script via terminal launcher
• Inject sudo / admin credentials automatically
• Approve security / system extension popup (macOS)
• Grant Full Disk Access (FDA) in System Settings
• Approve Network Extension / Content Filter popup (macOS)
6.2 Install Phase4 Steps
• Handle product setup (license key / passphrase / serial)
• Confirm in terminal after permissions granted
• Manage system reboot during or immediately post-install
• Installation package execution completes successfully
6.3 Validate Phase4 Steps
• Agent / product presence and overall health check
• System / kernel extension loaded verification
• Core service(s) and process running status check
• Real-Time Protection (RTP) active status check
6.4 Scan Phase4 Steps
• EICAR test file creation and drop on the endpoint
• EICAR threat detection verification (timed response wait)
• Threat quarantine / removal verification after EICAR alert
• Malware scan — scheduled / on-demand scan execution
6.5 Network Phase8 Steps
• Active network interface detection
• Default gateway reachability check
• DNS resolution validation
• Internet (HTTPS) outbound connectivity validation
• Network Extension / Content Filter active check
• Firewall policy — inbound traffic block verification
• Firewall policy — outbound traffic block verification
• DLP policy enforcement — file upload block verification
6.6 Uninstall Phase7 Steps
• Initiate uninstall sequence (script triggers uninstaller)
• Enter admin password during the uninstall process
• Approve / confirm extension removal prompt
• Select removal option from interactive menu
• Handle uninstall GUI — click Uninstall / close button
• Confirm system restart after uninstallation (y/n prompt)
• Post-uninstall verification — confirm processes & files purged
07

VPN Coexistence Testing

Enterprise endpoints frequently run a third-party VPN client alongside GP or PAA. This test suite validates that GP/PAA always asserts routing priority, enforces HIP policy, and maintains encrypted tunnel integrity, regardless of which third-party VPN is also connected.

7.1 Why Dual-VPN Behaviour Matters

A large share of real-world PANW deployments are not greenfield — the endpoint already has a legacy VPN client (FortiClient, Ivanti, Zscaler, or similar) from a prior remote-access rollout, or a business unit installs a second VPN for a specific application. If GP/PAA silently loses routing priority in that situation, users can be routed around PANW security enforcement without any visible symptom, which is a materially different risk than a simple crash or install failure. This is why VPN coexistence is treated as its own dedicated test category rather than folded into general product coexistence.

7.2 Coexistence Scenarios & Pass Criteria
ScenarioGP / PAA Tunnel3rd-Party VPN StateStrict Pass Criteria
GP + FortiClientConnected (primary)Connected (secondary)GP routes dominate; FortiClient routes demoted
GP + Ivanti SecureConnected (primary)Connected (secondary)GP routes dominate; DNS follows PANW config
GP + Zscaler ZCCConnected (primary)Connected (secondary)GP routes dominate; PANW canary DNS resolves
PAA + FortiClientZTNA active (primary)Connected (secondary)PAA policy applied; FortiClient tunnel subordinate
PAA + Ivanti SecureZTNA active (primary)Connected (secondary)PAA policy applied; Ivanti re-routed, no split-leak
PAA + Zscaler ZCCZTNA active (primary)Connected (secondary)PAA policy applied; no ZCC intercept on PANW traffic

7.3 Connection-Order Variations

  • GP/PAA-First: PANW connects first on a clean machine; third-party VPN launches on top.
  • Third-Party-First: Legacy VPN connected first; PANW initiates on top (unveils route conflicts).
  • Reconnect / Flap: One tunnel dropped and restored; confirms PANW automatically reclaims priority.

7.4 Automated Tunnel Priority Checks

  • • Route table metric comparison (PANW lowest metric)
  • • PANW canary DNS resolution (resolves only via PANW)
  • • HTTPS request to a GP/PAA-only internal resource
  • • Posture data HIP report download with co-active VPN
  • • Split-tunnel leak assertion against unmanaged tunnels
  • • OS Network adapter binding order validation
Windows Mechanics

Interface metrics and route table entries via PowerShell (Get-NetRoute, Get-NetIPInterface); DNS client server order via Get-DnsClientServerAddress; confirms the GP/PAA virtual adapter is bound with a lower (higher-priority) metric than the third-party VPN adapter.

macOS Mechanics

Network Service Order via networksetup -listnetworkserviceorder; route table via netstat -rn; DNS resolver order via scutil --dns; confirms the GP/PAA utun interface takes routing precedence over the third-party VPN's utun/tun interface.

08

Reporting & Deliverables

Every automated test run produces four distinct artifact types automatically, with zero manual post-processing required:

HTML — Interactive Web Report

Pass/fail badges per phase & step, collapsible sections, vendor branding, step timing/duration, embedded execution log.

Audience: Field engineers, TAC, partner SEs
JSON — Machine-Readable Result Set

Full structured result per step, CI/CD pipeline integration ready, dashboard/SIEM ingestion, diff-able across runs for regression tracking.

Audience: DevOps, automation pipelines, QA
PDF — Executive Summary

Printable one-page layout, phase pass/fail at a glance, HIP assertion matrix, VPN coexistence results, PANW-branded and marked confidential.

Audience: Leadership, customers, partner execs
HIP Report — Raw + Parsed XML

Raw HIP XML downloaded post-connect, per-category assertions highlighted, diffed against baseline, annotated pass/fail per posture field.

Audience: Security engineers, QA, compliance
09

Technical Glossary

HIP (Host Information Profile)The posture data GlobalProtect/Prisma Access collects from an endpoint — antimalware, firewall, disk encryption, DLP, and patch status — used to enforce security policy.
GlobalProtect (GP)Palo Alto Networks' endpoint VPN client that also submits HIP posture data for policy enforcement.
Prisma Access Agent (PAA)PANW's cloud-delivered Zero Trust Network Access (ZTNA) client, the successor to GP in cloud-first deployments.
XDR / EDRExtended/Endpoint Detection and Response — security agents that detect, investigate, and respond to threats on an endpoint.
DLP (Data Loss Prevention)Software that monitors and blocks unauthorized movement of sensitive data off an endpoint.
EICAR test fileA harmless, industry-standard test string used to safely verify that antimalware detection is working, without using real malware.
Tunnel priorityWhich VPN client's routes and DNS settings take precedence when more than one VPN is connected simultaneously.
WinRMWindows Remote Management — a protocol used here to remotely probe firewall and network state on Windows endpoints.
ZTNA (Zero Trust Network Access)A security model that grants access to specific applications only after verifying identity and device posture, rather than trusting an entire network.
Kernel / System ExtensionLow-level OS components (drivers on Windows, system extensions on macOS) that security agents use for real-time monitoring and enforcement.
10

Value for Future Engagements

The modular architecture built for the PANW Interop Automation framework provides immediately transferable capabilities for any organization delivering endpoint security solutions:

Vendor-Agnostic Architecture

New XDR, DLP, or VPN vendors are onboarded simply by adding a config entry and vendor script override without modifying the core orchestrator.

Zero-Touch Unattended Execution

The full install → validate → scan → uninstall lifecycle runs without human intervention, enabling nightly CI/CD regression sweeps.

Multi-Format Unified Reporting

HTML, JSON, PDF, and raw HIP XML are generated simultaneously from a single run, serving field, engineering, and executive stakeholders.

Transferable Phase Model

The 6-phase model (Pre-Flight, Install, Validate, Scan, Network, Uninstall) transfers seamlessly to any complex agent compatibility testing matrix.

11

Conclusion

The PANW Interop Automation framework demonstrates that GlobalProtect and Prisma Access Agent remain fully functional and accurately report HIP posture when co-installed with 10+ third-party XDR, DLP, and VPN products across Windows and macOS, and that PANW tunnel priority is consistently maintained in dual-VPN scenarios.

By converting a previously manual, 33-step verification process into a zero-touch automated pipeline with structured multi-format reporting, this project delivers repeatable, auditable coexistence evidence — reducing regression risk on every third-party product update and giving field, partner, and executive stakeholders a shared, trustworthy source of truth.

Outcome Summary & Technical AssuranceThe framework guarantees that enterprise customers can safely deploy GlobalProtect or Prisma Access Agent without risking blind spots, broken tunnel routing, or incorrect posture enforcement in complex multi-vendor endpoint ecosystems.
Next Steps

Need automated coexistence or security test pipelines?

Schedule a technical consultation with our security automation architects to evaluate your endpoint testing challenges.