<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic UserID Exclude Not Working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/userid-exclude-not-working/m-p/28086#M20499</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem where the 'User ID Exclude List' setting within the Zone setup on a Palo is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set my UserID agents to collect events from all IP addresses, then want to filter them on the PA itself as this seems the most logical sequence.&amp;nbsp; I initially only added the objects to the 'Include' list that I wanted to collect ID's from (Desktops) but it still pulled back user ID's from the servers, so I added specifi objects to the 'Exclude' section.&amp;nbsp; This too failed.&amp;nbsp; I have tried multiple combinations of include/excludes, using PA objects and direct IP subnets, and all fail - if the data is on the UserID agent cache, it is pulled into the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else seen this? Am I misunderstanding this feature - even though the Help section is explicit in saying this is what it's for?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Mar 2012 21:58:02 GMT</pubDate>
    <dc:creator>apackard</dc:creator>
    <dc:date>2012-03-07T21:58:02Z</dc:date>
    <item>
      <title>UserID Exclude Not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-exclude-not-working/m-p/28086#M20499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem where the 'User ID Exclude List' setting within the Zone setup on a Palo is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set my UserID agents to collect events from all IP addresses, then want to filter them on the PA itself as this seems the most logical sequence.&amp;nbsp; I initially only added the objects to the 'Include' list that I wanted to collect ID's from (Desktops) but it still pulled back user ID's from the servers, so I added specifi objects to the 'Exclude' section.&amp;nbsp; This too failed.&amp;nbsp; I have tried multiple combinations of include/excludes, using PA objects and direct IP subnets, and all fail - if the data is on the UserID agent cache, it is pulled into the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else seen this? Am I misunderstanding this feature - even though the Help section is explicit in saying this is what it's for?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2012 21:58:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-exclude-not-working/m-p/28086#M20499</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-03-07T21:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Exclude Not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-exclude-not-working/m-p/28087#M20500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...After you enter the IPs into the Exclude List, did you commit for the change to take effect?&amp;nbsp; Also, you may want to clear the user cache via the CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@PA-2050&amp;gt; clear user-cache&lt;BR /&gt;&amp;gt; all&amp;nbsp;&amp;nbsp; Clear all ip to user cache in data plane&lt;BR /&gt;&amp;gt; ip&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear the specified ip to user cache in data plane&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2012 22:15:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-exclude-not-working/m-p/28087#M20500</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-03-07T22:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Exclude Not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-exclude-not-working/m-p/28088#M20501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, change committed on the Palo, user cache cleared via the CLI and Palo agents restarted for good measure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;None of the above stop IP addresses that are either explicitly excluded, nor implicity excluded, from being registered with the PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2012 22:37:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-exclude-not-working/m-p/28088#M20501</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-03-07T22:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Exclude Not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-exclude-not-working/m-p/28089#M20502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please open a case with support to have it reviewed in more details.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2012 00:01:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-exclude-not-working/m-p/28089#M20502</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-03-09T00:01:24Z</dc:date>
    </item>
  </channel>
</rss>

