<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID ignored user list not being respected in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignored-user-list-not-being-respected/m-p/429269#M94852</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We leverage a deployment software at our organization and when a computer is having software deployed or is being scanned for inventory by this software a service account does a network logon to create a temp service to run the process. This process generates a logon event on our domain controllers and maps the IP of the device being scanned/deployed to the the service account on the firewall. This has created some issues with security policies on our firewall as we leverage user-id for most policies. The fix for this seems to be to add the service account to the ignore user list in the user-id configuration and we have successfully done this config on one HA pair of firewalls, however we went to do the same on another pair of firewalls and I continue to see sessions established with the service account as the source user. I have the account added to the list in the same format it is displayed on the traffic logs "domain\user", this is also how we have it successfully setup on the other pair of firewalls. Any ideas on what may be causing the service account to continue to show up on this pair of firewalls?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Aug 2021 20:13:17 GMT</pubDate>
    <dc:creator>sellington</dc:creator>
    <dc:date>2021-08-25T20:13:17Z</dc:date>
    <item>
      <title>User-ID ignored user list not being respected</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignored-user-list-not-being-respected/m-p/429269#M94852</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We leverage a deployment software at our organization and when a computer is having software deployed or is being scanned for inventory by this software a service account does a network logon to create a temp service to run the process. This process generates a logon event on our domain controllers and maps the IP of the device being scanned/deployed to the the service account on the firewall. This has created some issues with security policies on our firewall as we leverage user-id for most policies. The fix for this seems to be to add the service account to the ignore user list in the user-id configuration and we have successfully done this config on one HA pair of firewalls, however we went to do the same on another pair of firewalls and I continue to see sessions established with the service account as the source user. I have the account added to the list in the same format it is displayed on the traffic logs "domain\user", this is also how we have it successfully setup on the other pair of firewalls. Any ideas on what may be causing the service account to continue to show up on this pair of firewalls?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 20:13:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignored-user-list-not-being-respected/m-p/429269#M94852</guid>
      <dc:creator>sellington</dc:creator>
      <dc:date>2021-08-25T20:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID ignored user list not being respected</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignored-user-list-not-being-respected/m-p/429564#M94919</link>
      <description>&lt;P&gt;Looks like I am no longer seeing new sessions initiated with that source user. I am guessing what I was observing was user-id mappings made before I excluded the service account that had not timed out yet.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 22:19:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignored-user-list-not-being-respected/m-p/429564#M94919</guid>
      <dc:creator>sellington</dc:creator>
      <dc:date>2021-08-26T22:19:19Z</dc:date>
    </item>
  </channel>
</rss>

