When you configure policies,
you can configure policy scanning exceptions if you have selected either Selected
users and groups or Selected network objects for the traffic
source.
Entries in an exception list will not be scanned even if they are a match to other
criteria in the policy.
-
Selected users and groupsIf a user or group is included in both the selected users and groups list and the users and group exceptions list, the presence in the exceptions list has higher priority.
-
Selected network objectsIf an IP address is included in both the selected network objects list and the network objects exceptions list, the presence in the exceptions list has higher priority.If the client's IP address is part of a network object in the exception list of a policy, this policy will not be matched. Instead, Deep Discovery Web Inspector will look at the next policy to search for a match to this client's IP address.