<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector Exclusion List in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9432#M22801</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please explain what this comment has to do with the topic&amp;nbsp;Identity Collector Exclusion List ?&lt;/P&gt;&lt;H1 style="color: #000000; background-color: #ffffff; border: 0px; font-weight: 200; font-size: 2rem;"&gt;&lt;/H1&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 Oct 2018 10:58:05 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2018-10-31T10:58:05Z</dc:date>
    <item>
      <title>Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9420#M22789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you leave the excluded and included items blank, are all items sent, or do you have to specify all networks you want to include?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I add one subnet in the included list, does that mean everything else is excluded, even if not defined in the excluded list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's no real documentation I can find for this. The Identity awareness guide just says "Defines IP addresses and networks to include or exclude".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would just like to test Identity Collector in one subnet, and exclude that subnet from AD Query.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2018 12:34:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9420#M22789</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2018-10-24T12:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9421#M22790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You find more information in the Identity Collector R77.30 Release Notes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2018 14:14:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9421#M22790</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-10-24T14:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9422#M22791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;r 77.30 release notes show the same thing as the r80.10. It says you can use it to exclude and include, but no details as to how the exclusions work. (Does include inherently exclude all non included networks?)&lt;BR /&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/72024_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2018 14:19:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9422#M22791</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2018-10-24T14:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9423#M22792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/46230"&gt;Royi Priov&lt;/A&gt;‌ - could you help here pls? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2018 14:25:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9423#M22792</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-10-24T14:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9424#M22793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would assume that basic principles of logic do apply &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;. Main feature here is optimization by excluding unnecessary information, but it&amp;nbsp;makes also possible to strictly limit the collected information by using include.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2018 14:27:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9424#M22793</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-10-24T14:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9425#M22794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's what I would assume as well. The features seem almost mutually exclusive, kinda like a fail open or fail close. I wonder which one is determined first, the exclude or the include?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2018 14:41:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9425#M22794</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2018-10-24T14:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9426#M22795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does make no sense to use both - this filters the data from Collector before forwarding it to the GWs. As explained in the documentation, this comes handy to filter unnecessary data. The other side would be a kind of whitelist, limiting which data shall be forwarded to the GWs, that can be usefull&amp;nbsp;under special circumstances.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2018 14:56:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9426#M22795</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-10-24T14:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9427#M22796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does make sense to use both. Example:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Include: 10.105.0.0/16&lt;/LI&gt;&lt;LI&gt;Exclude: 10.105.20.0/24&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I agree with David, the R80.10 and R80.20 documentation regarding the Identity Collector does not have the right quality.&lt;/P&gt;&lt;P&gt;It looks like it's done on purpose, in order to sell professional services, isn't it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2018 20:26:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9427#M22796</guid>
      <dc:creator>Kris_Pellens</dc:creator>
      <dc:date>2018-10-24T20:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9428#M22797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;Kris Pellens wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;It looks like it's done on purpose, in order to sell professional services, isn't it?&lt;/STRONG&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hi Kris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really feel sorry this is your opinion.&lt;/P&gt;&lt;P&gt;Taking this into the&amp;nbsp;constructive side, I will appreciate if you could tell me what you are missing in our documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Royi Priov&lt;/P&gt;&lt;P&gt;Team Leader, Identity Awareness R&amp;amp;D.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2018 05:23:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9428#M22797</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2018-10-25T05:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9429#M22798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As written here, when identity is received on the Identity collector, in order to be sent to the gateway, it should pass all filters for both global and local gateway filter (available in our latest version -&amp;nbsp;sk134312).&lt;/P&gt;&lt;P&gt;Therefore, if there are both inclusion and exclusion lists, both filters will be applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Royi Priov&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Team Leader, Identity Awareness R&amp;amp;D.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2018 05:25:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9429#M22798</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2018-10-25T05:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9430#M22799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So if I have nothing in the inclusion list, everything with pass.&lt;/P&gt;&lt;P&gt;If I have 1 subnet in the inclusion list, only that subnet will pass.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that correct?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2018 12:28:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9430#M22799</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2018-10-25T12:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9431#M22800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Royi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your feedback. We're currently implementing Identity Management (using Microsoft Active Directory and Cisco ISE).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment, we have the following set up:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;A VSX/VSLS cluster (R80.20)&lt;/LI&gt;&lt;LI&gt;A Security Management Server (R80.20)&lt;/LI&gt;&lt;LI&gt;Identity Collector (sk134312)&lt;/LI&gt;&lt;LI&gt;Identity Agent Terminal Server (sk134312), running on Windows 2012&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The online documentation (i.e. the Identity Awareness R80.20 Administration Guide) is not reflecting those updates. It would be nice to have the online documentation be aligned with the latest updates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're also experiencing connections issues on the terminal servers.&lt;/P&gt;&lt;P&gt;Since the installation of the Terminal Server Agent, sometimes all tcp ports on the server are occupied (port starvation); resulting in connection errors (hence: user frustration). The number of users is less than 20.&lt;/P&gt;&lt;P&gt;Today, we've experienced a TS crash, caused by the agent:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/72543_error.png" /&gt;&lt;/P&gt;&lt;P&gt;(A TAC case has been opened for that).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Check Point community is also asking for a best practices and configuration document on how to integrate Check Point Identity with Cisco ISE. Is this something you can provide, because your team did the tests up to ISE 2.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Kris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2018 11:09:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9431#M22800</guid>
      <dc:creator>Kris_Pellens</dc:creator>
      <dc:date>2018-10-26T11:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9432#M22801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please explain what this comment has to do with the topic&amp;nbsp;Identity Collector Exclusion List ?&lt;/P&gt;&lt;H1 style="color: #000000; background-color: #ffffff; border: 0px; font-weight: 200; font-size: 2rem;"&gt;&lt;/H1&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2018 10:58:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9432#M22801</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-10-31T10:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9433#M22802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2018 12:16:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/9433#M22802</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2018-10-31T12:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/243640#M47346</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I still have a question regarding the Include / Exclude option for identities.&lt;/P&gt;&lt;P&gt;Currently I have an Identity Filter that excludes all service Accounts (regex identity svc*), yet we need to include an account named svcJohnDoe. So I added a new Include entry for that account, but is still not seen by the gateways.&lt;/P&gt;&lt;P&gt;According to your explanation, both should be applied, but it seems to me that the exclusion is overriding the include entry.&lt;/P&gt;&lt;P&gt;Can you please help?&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Nuno Ramalho&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 12:14:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/243640#M47346</guid>
      <dc:creator>nmpramalho</dc:creator>
      <dc:date>2025-03-12T12:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/251130#M49151</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;unfortunately I still can't find any comprehensive documentation which explains how the identity collector manages filters. In the documentation "&lt;A href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics/Identity-Collector-Filters-for-Login-Events.htm&amp;quot;" target="_blank"&gt;https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics/Identity-Collector-Filters-for-Login-Events.htm"&lt;/A&gt;&amp;nbsp;you only document how to use the interface. I guess that should be a given, that an administrator understands the interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's the logic behind the filters?&lt;/P&gt;&lt;P&gt;I have a global filter which is completely empty so everything is allowed.&lt;/P&gt;&lt;P&gt;I have a second filter which excludes certain subnets and includes certain access roles via AD.&lt;/P&gt;&lt;P&gt;Now I would like to add exceptions for the excluded subnets to allow some machines access to the internet.&lt;/P&gt;&lt;P&gt;Which filter has precedens over the other. Are they processed top to bottom, although I can't change the order they are listed in? Can I use includes and excludes per section (network, identity, domain ) within one filter at the same time or do I need separate Filters?&lt;/P&gt;&lt;P&gt;I hope you can update either the documentation or some links:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics/Introduction.htm" target="_blank"&gt;sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics/Introduction.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Jürgen&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 09:06:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/251130#M49151</guid>
      <dc:creator>Ju_Ka</dc:creator>
      <dc:date>2025-06-12T09:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/251132#M49153</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Jürgen,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;From what I remember, the filters are applied in one action (both global and local filters). It means, for the identity to be sent to a PDP gateway, it should pass the global and all local filters.&lt;/P&gt;
&lt;P&gt;By the way, in Infinity Identity we are about to present a new filtering mechanism, which will support also group filtering and other parameters. I have attached a snippet from our UI.&lt;/P&gt;
&lt;P&gt;Send me a private message if you want to get more information about it.&lt;/P&gt;
&lt;DIV id="tinyMceEditor_63228d08287eb8Royi_Priov_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_63228d08287eb8Royi_Priov_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="AddMessageTags lia-message-tags lia-component-message-view-widget-tags"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 12 Jun 2025 09:41:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/251132#M49153</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2025-06-12T09:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/251139#M49156</link>
      <description>&lt;P&gt;Hi Royi,&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;You say that filters are applied in one action, both Global and Local filters, but still there is no reference to how include and exclude filters are applied when used together.&lt;/P&gt;&lt;P&gt;In our case, we have no exclusions at Global level. we only have a local filter that includes both excluded accounts (svc*) and some include filters (e.g. svcTEST), but the account svcTEST is not passed to the gateways. It seems that the exclusion is overlapping the inclusion, but I can't find any information about this, neither a way to address this need.&lt;/P&gt;&lt;P&gt;New feature looks very nice, thank you for sharing. Is this included in new IDC R82, released May 11th?&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Nuno Ramalho&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 11:05:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/251139#M49156</guid>
      <dc:creator>nmpramalho</dc:creator>
      <dc:date>2025-06-12T11:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/251141#M49157</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/126984"&gt;@nmpramalho&lt;/a&gt;&amp;nbsp;I think I understand your point.&lt;/P&gt;
&lt;P&gt;as the filter applied in once bulk, soon as one of the condition matches, the action is performed. so the svcTEST applies on svc* therefore dropped.&lt;/P&gt;
&lt;P&gt;If this is indeed the case, it seems that it is a legit RFE to send with your local SE team.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for Infinity Identity, it is a new application in Infinity Portal, which communicates with Identity Collector and also with Entra ID, Intune, Defender and Harmony clients.&lt;/P&gt;
&lt;P&gt;Check this thread for more details:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;A class="external-link" href="https://community.checkpoint.com/t5/General-Topics/Simplifying-Zero-Trust-with-Infinity-Identity-Centralized/m-p/246632#M41214" rel="nofollow" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Simplifying-Zero-Trust-with-Infinity-Identity-Centralized/m-p/246632#M41214&lt;/A&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The filters page I showed is part of this application. In case you will create the following filters it will work with Infinity Identity:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;1. identity "svcTEST" include&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. Identity regex "svc*" exclude&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If needed, contact me for more details privately here or at royip@checkpoint.com&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 11:23:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/251141#M49157</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2025-06-12T11:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Exclusion List</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/251203#M49173</link>
      <description>&lt;P&gt;Hello Royi,&lt;/P&gt;&lt;P&gt;thank you for your reply. So from this thread I understand that the first match applies the filter. I will try out this logic for Identity Collector filters in R81.20.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Go from specific rules to general rules&lt;/LI&gt;&lt;LI&gt;Go from top to bottom&lt;/LI&gt;&lt;LI&gt;Includes come before Excludes&lt;/LI&gt;&lt;LI&gt;once a filter matches - no more processing&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;If anyone else has tried out a couple of things feel free to share your experience.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a nice weekend!&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Jürgen&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 06:57:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Exclusion-List/m-p/251203#M49173</guid>
      <dc:creator>Ju_Ka</dc:creator>
      <dc:date>2025-06-13T06:57:56Z</dc:date>
    </item>
  </channel>
</rss>

