<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using User-ID v4, how do I exclude users in certain groups? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23311#M16990</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very close, Kadak, thank for that - but still not quite working, sadly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This ignore_users_list.txt does prevent the sccm user from being mapped to a given IP address, BUT the user agent now simply deletes the IP mapping instead. So I've got 192.168.1.10 mapped as neil.broadley in the User-ID agent and I can see that in the "Monitoring" tool. Then I launch my Windows system tool as the sccm user and... bam! My entry in User-ID is deleted, no mapping exists for my 192.168.1.10 (it vanishes in real time on the "Monitoring" tool) and since I'm not identified, I lose all my web browsing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any way to change that behaviour that you know of?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Oct 2012 09:36:10 GMT</pubDate>
    <dc:creator>broadleyn</dc:creator>
    <dc:date>2012-10-10T09:36:10Z</dc:date>
    <item>
      <title>Using User-ID v4, how do I exclude users in certain groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23309#M16988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the old style v3 user-ID agent, I could exclude certain groups of users from being mapped. How do I do so in v4?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Background :&lt;/P&gt;&lt;P&gt;We have certain users in a department group "Infosys" who are being blocked from web browsing. It turns out they're launching an MS tool under administrative credentials and user-ID is matching their IP against this new credential. The policy only allows "infosys" users from browsing, so they're blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The admin credential, called "sccm" is not in the "Infosys" group - it's in the "Sysuser" group. In the Palo Alto policy User Identication/Group Mappings, we've made sure that only Infosys is listed, not Sysuser, but as the IP mapping happens at the agent, it's already too late.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, how do we replicate the v3 agent configuration of excluding certain group's members from ever being mapped?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;p.s. if this doesn't exist any more, we'll just downgrade the agents to the v3 client, I suppose.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2012 10:34:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23309#M16988</guid>
      <dc:creator>broadleyn</dc:creator>
      <dc:date>2012-10-09T10:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Using User-ID v4, how do I exclude users in certain groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23310#M16989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can create/ modify ignore_user_list.txt file in the User-ID directory under the Palo Alto Networks Folder.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link which will guide through the process thoroughly:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" data-containerid="2027" data-containertype="14" data-objectid="2893" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-2893"&gt;https://live.paloaltonetworks.com/docs/DOC-2893&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2012 15:02:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23310#M16989</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2012-10-09T15:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Using User-ID v4, how do I exclude users in certain groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23311#M16990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very close, Kadak, thank for that - but still not quite working, sadly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This ignore_users_list.txt does prevent the sccm user from being mapped to a given IP address, BUT the user agent now simply deletes the IP mapping instead. So I've got 192.168.1.10 mapped as neil.broadley in the User-ID agent and I can see that in the "Monitoring" tool. Then I launch my Windows system tool as the sccm user and... bam! My entry in User-ID is deleted, no mapping exists for my 192.168.1.10 (it vanishes in real time on the "Monitoring" tool) and since I'm not identified, I lose all my web browsing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any way to change that behaviour that you know of?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 09:36:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23311#M16990</guid>
      <dc:creator>broadleyn</dc:creator>
      <dc:date>2012-10-10T09:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Using User-ID v4, how do I exclude users in certain groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23312#M16991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What specific version of the User-ID agent are you running?&amp;nbsp; 4.1.(?).&lt;/P&gt;&lt;P&gt;This information will be very helpful in determining expected behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Oct 2012 00:16:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23312#M16991</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2012-10-20T00:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Using User-ID v4, how do I exclude users in certain groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23313#M16992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this behavior is a known Bug in User Agent 4.1.4 &amp;amp; 4.1.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Although there is no hint in the Release Notes&lt;/P&gt;&lt;P&gt;it seems that User Agent 4.1.6 is working again.&lt;/P&gt;&lt;P&gt;(as far as i can see in my own tests yet)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 10:22:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23313#M16992</guid>
      <dc:creator>ExclusiveNetworksGermany</dc:creator>
      <dc:date>2012-10-22T10:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Using User-ID v4, how do I exclude users in certain groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23314#M16993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct, there is a known issue with UID Agent 4.1.4 &amp;amp; 4.1.5 wherein the ignore_user_list was not properly observed.&lt;/P&gt;&lt;P&gt;This has been resolved with the release of UID Agent 4.1.6 and should not be an issue with UID Agent version 4.1.3 and earlier.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 19:03:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23314#M16993</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2012-11-29T19:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Using User-ID v4, how do I exclude users in certain groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23315#M16994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've applied the 4.1.6 agent to both User-ID servers and updated the ignore_user_list.txt on each. This has resolved the problem. Not sure if this support group ignores, but user ignores will fix the present issue, so this thread is definitely closed. Thanks for your updates, everyone.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 12:00:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-user-id-v4-how-do-i-exclude-users-in-certain-groups/m-p/23315#M16994</guid>
      <dc:creator>broadleyn</dc:creator>
      <dc:date>2012-12-06T12:00:13Z</dc:date>
    </item>
  </channel>
</rss>

