<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-Id Mapping / Ignore user list in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-ignore-user-list/m-p/383589#M89981</link>
    <description>&lt;P&gt;instead of adding the users to the ignore list, you could add the GlobalProtect IP Pool to the exclude list in the userID agent&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this will preserve GP user mapping at all time&lt;/P&gt;</description>
    <pubDate>Wed, 03 Feb 2021 09:40:25 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2021-02-03T09:40:25Z</dc:date>
    <item>
      <title>User-Id Mapping / Ignore user list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-ignore-user-list/m-p/383528#M89970</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am running into an issue with Global Protect users due to remoting into other machines with other credentials. I have read extensive articles about the issue and understand that the firewall can only map one user name to an IP. That appears to be exactly what is happening., A user logs in and has internal connectivity, then logs into an RDP session. After logout that user has no connectivity due to the mapping being retained to the admin or service account. From what I gather, I need to exclude those accounts from user mapping. My uncertainty is in our setup. Our internal firewall has a server monitoring setup with all the remote DC's showing connected (Device / User Identification / User Mapping Tab / Server Monitoring). Each remote firewall under (Device / User Identification / User-Id Agents tab) has a mapping to the internal firewall. What I am looking for clarification on is whether I need to create the ignore user list on the internal firewall or each individual firewall. I would assume it would be the internal firewall but not 100 percent sure on this. Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 23:49:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-ignore-user-list/m-p/383528#M89970</guid>
      <dc:creator>RobertNagy</dc:creator>
      <dc:date>2021-02-02T23:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: User-Id Mapping / Ignore user list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-ignore-user-list/m-p/383551#M89976</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49405"&gt;@RobertNagy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You would just need this on your internal firewall if you have your remote DCs setup through redistribution. You might want to think through all the ramifications of just blanket ignoring these accounts on the firewall however. You won't have these accounts to use in your rulebase or your logs anymore at all, so if they are being used in your rulebase at all to limit/allow traffic in other rules you'll have to take another look at that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 04:18:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-ignore-user-list/m-p/383551#M89976</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-02-03T04:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: User-Id Mapping / Ignore user list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-ignore-user-list/m-p/383589#M89981</link>
      <description>&lt;P&gt;instead of adding the users to the ignore list, you could add the GlobalProtect IP Pool to the exclude list in the userID agent&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this will preserve GP user mapping at all time&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 09:40:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-ignore-user-list/m-p/383589#M89981</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-02-03T09:40:25Z</dc:date>
    </item>
  </channel>
</rss>

