<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Agentless User-ID not processing ingore-user list in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15161#M11126</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Joshua,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you try using individual set commands for each user you are adding to the ignore list?&amp;nbsp; You may want to clear the ignore list prior to the test with "delete user-id-collector ignore-user".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;set user-id-collector ignore-user "domain\test1"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;set user-id-collector ignore-user test1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;set user-id-collector ignore-user "domain\user"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;set user-id-collector ignore-use&lt;/SPAN&gt;r user&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;-- Kevin&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Jan 2013 19:00:05 GMT</pubDate>
    <dc:creator>kfindlen</dc:creator>
    <dc:date>2013-01-09T19:00:05Z</dc:date>
    <item>
      <title>Agentless User-ID not processing ingore-user list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15158#M11123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've been working on trying to configure all the firewalls with the Agentless User-ID setup but despite several attempts to enable it I cannot get it to ignore users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I establish a session and enter config mode and type in the command &lt;EM&gt;set user-id-collector ignore-user [ domain\serviceaccount ]&lt;/EM&gt; then commit the changes and despite doing so I still see all my normal user ID mappings being overwritten with domain\serviceaccount&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried clearing the mapping cache and when the list starts repopulating I'm still seeing entries only for the domain\serviceaccount &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried several methods of entering the accounts such as matching case and without the domain but it still refuses to match the list, the only thing I haven't tried is entering something like &lt;EM&gt;cn=Service Account,cn=Users,dc=domain,dc=com&lt;/EM&gt; but I really think at this point if nothing I've done before hasn't worked that this will not work either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure what I'd doing wrong and I cannot seem to find anything in the release notes or KnowledgePoint leading me to believe that there are known issues or it doesn't work so I'm open to suggestions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 18:41:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15158#M11123</guid>
      <dc:creator>jfarm</dc:creator>
      <dc:date>2013-01-08T18:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID not processing ingore-user list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15159#M11124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Joshua, &lt;/P&gt;&lt;P&gt;Is it a multi vsys system by any change. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;If you have multiple vsys, depending on what vsys you need to add the ignore list you can use the following command&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;#Set vsys vsys1 user-id-collector ignore-user [ AD2008\test1 test1 ]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also i have worked with a customer and it did work for me. I am not sure why it is not working for you. Try adding both user with domain and with domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 20:06:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15159#M11124</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-01-08T20:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID not processing ingore-user list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15160#M11125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;I have tried every combination of entering the AD account names except for something like &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:test1@ad2008.com"&gt;test1@ad2008.com&lt;/A&gt;&lt;SPAN&gt; or cn=test1, dc=ad2008, dc=com or something like that.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This particular firewall itself does not have any configured virtual systems as well so I am entering the command set user-id-collector ignore-user [ domain\test1 test1 Domain\Test1 Test1 ] to account for with and without the domain and to confirm that the system is not case sensitive as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll continue to look around and see if there is anything else I may be missing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 14:34:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15160#M11125</guid>
      <dc:creator>jfarm</dc:creator>
      <dc:date>2013-01-09T14:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID not processing ingore-user list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15161#M11126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Joshua,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you try using individual set commands for each user you are adding to the ignore list?&amp;nbsp; You may want to clear the ignore list prior to the test with "delete user-id-collector ignore-user".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;set user-id-collector ignore-user "domain\test1"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;set user-id-collector ignore-user test1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;set user-id-collector ignore-user "domain\user"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;set user-id-collector ignore-use&lt;/SPAN&gt;r user&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;-- Kevin&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 19:00:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15161#M11126</guid>
      <dc:creator>kfindlen</dc:creator>
      <dc:date>2013-01-09T19:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID not processing ingore-user list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15162#M11127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Joshua, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another thing to make sure is that you clear the user ip mapping after you have created the ignore user list entry.&lt;/P&gt;&lt;P&gt;I see above you did clear it but was it before committing the changes or after.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 19:13:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15162#M11127</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-01-09T19:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID not processing ingore-user list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15163#M11128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are the steps I have been following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. log into CLI session and add all the entries to the ignore list&lt;/P&gt;&lt;P&gt;2. verify the entries via the Web UI are showing up properly in the candidate config context view&lt;/P&gt;&lt;P&gt;3. Stop the User-ID agent running on the local file print server.&lt;/P&gt;&lt;P&gt;3. From the CLI run the commit command.&lt;/P&gt;&lt;P&gt;4. Wait for confirmation the config has applied&lt;/P&gt;&lt;P&gt;5. Issue from the CLI clear user-cache all&lt;/P&gt;&lt;P&gt;6. After that I issue from the CLI show user ip-user-mapping all | match utilityaccount which shows entries for all the local IP addresses that should be identified by local users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I disable the agentless config and re-enable the Application based User-ID agent to make sure the user entries are not overwritten with the service account.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 20:52:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15163#M11128</guid>
      <dc:creator>jfarm</dc:creator>
      <dc:date>2013-01-09T20:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID not processing ingore-user list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15164#M11129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On another one of our firewalls we had multiple vsys objects defined but went back to just one, I tried the above steps and this firewall doesn't observe the ignore list either so knowing this FW did have a second vsys at one point I tried the command like so:&lt;/P&gt;&lt;P&gt;fwadmin@PA-4050# set vsys vsys1 user-id-collector ignore-user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Invalid syntax.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It doesn't appear to like the command when entered with the "vsys vsys1" part.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 14:34:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-processing-ingore-user-list/m-p/15164#M11129</guid>
      <dc:creator>jfarm</dc:creator>
      <dc:date>2013-01-18T14:34:53Z</dc:date>
    </item>
  </channel>
</rss>

