User Identification ACL Include List | By default, if you do not specify subnetworks
in this list, the firewall applies the user mapping information
it discovers to all the traffic of this zone for use in logs, reports,
and policies. To limit the application of user mapping information
to specific subnetworks within the zone, then for each subnetwork
click Add and select an address (or address
group) object or type the IP address range (for example, 10.1.1.1/24).
The exclusion of all other subnetworks is implicit because the Include
List is an allow list, so you do not need to add them
to the Exclude List. Add entries to
the Exclude List only to exclude user mapping
information for a subset of the subnetworks in the Include
List. For example, if you add 10.0.0.0/8 to the Include
List and add 10.2.50.0/22 to the Exclude
List, the firewall includes user mapping information
for all the zone subnetworks of 10.0.0.0/8 except 10.2.50.0/22,
and excludes information for all zone subnetworks outside of 10.0.0.0/8. |