<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Agent exclusion list in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214647#M62357</link>
    <description>&lt;P&gt;Thanks but do you have any use case in mind why we want to exclude certain subnets either at user-id-agent level or zone level on firewall?&lt;/P&gt;</description>
    <pubDate>Fri, 18 May 2018 00:16:25 GMT</pubDate>
    <dc:creator>faizankhurshid</dc:creator>
    <dc:date>2018-05-18T00:16:25Z</dc:date>
    <item>
      <title>User-ID Agent exclusion list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214583#M62343</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it good practice to exlude all server subnets in exclude list as I believe we are not interested in&amp;nbsp;administrators to IP mapping for servers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be the user cases for exlcude list on firewall and user-id-agent?&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 16:17:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214583#M62343</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-05-17T16:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent exclusion list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214600#M62344</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This depends on the enviroment and your security structure. Most enviroments likely aren't going to utilize user-id mapping for generating security policies for their server VLAN; others will make it so that only specific service-accounts can access certain restricted machines on the network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We currently restrict what different admin users can access while logged into a server; and what service-accounts actually have access to different resources depending on which one is being utilized at that time.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 16:41:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214600#M62344</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-17T16:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent exclusion list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214607#M62346</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;thanks but do you have any use case where you are using exclude list on firewall or user-id-agent? I can think of like guest user subnet that are not authenticating through DC so we can exclude that subnet on firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 18:33:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214607#M62346</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-05-17T18:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent exclusion list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214610#M62349</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Are you talking about excluded networks in the user-id agent configuration or in the zone configuration on the firewall?&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 19:32:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214610#M62349</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-05-17T19:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent exclusion list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214620#M62351</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;actually I am asking about both? what is the difference between two and use case of both. Thanks for the help&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 20:22:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214620#M62351</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-05-17T20:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent exclusion list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214638#M62356</link>
      <description>&lt;P&gt;The exclude lists only have an effect if you configure also an include list entry. So the exclude entries are only for exclusion of a subset of the subnets specified in the include list. Specifying only exclude entries result in an exclusion of any network.&lt;/P&gt;&lt;P&gt;The difference between the user-id agent and zone config is ...&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User-ID agent configuration applies globally to the user-id configurstion and also for the redestribution feature.&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/user-identification/device-user-identification-user-mapping/include-or-exclude-subnetworks-for-user-mapping" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/user-identification/device-user-identification-user-mapping/include-or-exclude-subnetworks-for-user-mapping&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Zone User-ID configuration applies only to that zone where you configure include/exclude entries.&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/network/network-zones/building-blocks-of-security-zones#id15b17daf-f222-447c-bfee-a0c4cb8ae9f7" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/network/network-zones/building-blocks-of-security-zones#id15b17daf-f222-447c-bfee-a0c4cb8ae9f7&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 17 May 2018 23:07:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214638#M62356</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-05-17T23:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent exclusion list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214647#M62357</link>
      <description>&lt;P&gt;Thanks but do you have any use case in mind why we want to exclude certain subnets either at user-id-agent level or zone level on firewall?&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 00:16:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214647#M62357</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-05-18T00:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent exclusion list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214652#M62360</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So an example for this would be something along the ways of this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Say that I'm using the same IP range across multiple different zones. For example my&amp;nbsp;'WSL' zone is 10.0.0.0/8 and I use this for all internal clients, however I also have a 'DOJ' zone on this firewall that also uses the same 10.0.0.0/8 IP range. In this scenario I'm likely going to want to exclude different subnets within that range on each zone. So on the Zone's User-ID configuration I might exclude 10.191.0.0/16 on 'WSL' since that's a GUEST network, but on 'DOJ' the GUEST network might be 10.172.0.0/16.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Likewise you could run into a situation where I have a shared IP range across multiple different zones similar to the above example, but they all fall within the same subnet. So for example if I had settled on all&amp;nbsp;server addresses&amp;nbsp;&lt;EM&gt;always&lt;/EM&gt; using 10.191.190.0/24 within all of the different zones, and I didn't want to enable User-ID on the servers, I might use the User-ID Agent Exclude list to exclude 10.191.190.0/24 from&amp;nbsp;&lt;EM&gt;all&lt;/EM&gt; user-id collections across the enviroment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully that helps a little bit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 04:57:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-exclusion-list/m-p/214652#M62360</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-18T04:57:55Z</dc:date>
    </item>
  </channel>
</rss>

