<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ignore users for IP subnet in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/287806#M76745</link>
    <description>&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I'm not sure if this would fit in our environment.&lt;/P&gt;&lt;P&gt;We want to include the admin accounts in the user-id, e.g. for the servers and no internetaccess with the admin accounts on them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But thanks for your hint, I will have a look at it &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;</description>
    <pubDate>Wed, 11 Sep 2019 05:53:34 GMT</pubDate>
    <dc:creator>OliverGreimers</dc:creator>
    <dc:date>2019-09-11T05:53:34Z</dc:date>
    <item>
      <title>ignore users for IP subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/287647#M76729</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with the risk that this was already discussed, I have a question regarding ignore users with User-ID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configured User-ID for our clients, also for the IT department.&lt;BR /&gt;In the IT, we also using admin accounts. So when I started a programm in admin mode, the firewall registered this in the DCs. So my client gets the adm account linked with my client IP.&lt;/P&gt;&lt;P&gt;This is correct but annoying, because our admin accounts have no internet access. So I have to start a normal user login from my client, for example restarting Outlook.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is if it's possible to add entries in the ignore list in connection with IP subnets. So I can tell the PA to ignore admin logins for our clients in the IT department.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did not found any possibility to configure it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and best Regards&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 14:14:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/287647#M76729</guid>
      <dc:creator>OliverGreimers</dc:creator>
      <dc:date>2019-09-10T14:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: ignore users for IP subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/287665#M76731</link>
      <description>&lt;P&gt;Howdy Oliver.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just wanted to acknowledge that I saw the post, but agree that I am not sure there is a way to filter out.&lt;/P&gt;&lt;P&gt;I do know that the FW is capable of not learning based on subnets (dont attempt to learn VoIP softphone subnet, as example), but as for not learning a specific user type.&amp;nbsp; But you may want to focus in the Group Mapping section of UserID, to see if you can create a certain pattern that will be learned/associated with group mappings, and try to not have the admin accounts part of the pattern.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then you may be able to do something.&amp;nbsp; It is a long shot, but wanted to give you some encouragement.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 15:26:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/287665#M76731</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-09-10T15:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: ignore users for IP subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/287806#M76745</link>
      <description>&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I'm not sure if this would fit in our environment.&lt;/P&gt;&lt;P&gt;We want to include the admin accounts in the user-id, e.g. for the servers and no internetaccess with the admin accounts on them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But thanks for your hint, I will have a look at it &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 05:53:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/287806#M76745</guid>
      <dc:creator>OliverGreimers</dc:creator>
      <dc:date>2019-09-11T05:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: ignore users for IP subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/287886#M76764</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We encountered a similar issue. I you use Exchange for email using Outlook. Have the User-ID agents use it instead of the DC's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 16:18:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/287886#M76764</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-09-11T16:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: ignore users for IP subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/288038#M76789</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already configured the Exchange servers to poll the user logons.&lt;/P&gt;&lt;P&gt;But in your suggestion, I have to configure only the Exchange servers and delete the DCs in the User-ID Agent configuration, right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 07:11:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/288038#M76789</guid>
      <dc:creator>OliverGreimers</dc:creator>
      <dc:date>2019-09-12T07:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: ignore users for IP subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/288112#M76792</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;That is correct, you have to stop monitoring the DC's for it to work as I have described.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 14:17:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ignore-users-for-ip-subnet/m-p/288112#M76792</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-09-12T14:17:17Z</dc:date>
    </item>
  </channel>
</rss>

