To block or not to block... why is it so hard?
Created: 23 Apr 2008 | Updated: 23 May 2010 | 16 comments
Good morning all,
Here is the scenario:
I have a Windows XP SP2 machine with a Dual Channel Fibre Card connected to an external Framestore via 2 dual channel Fibre cables.
Windows deteects the Frame Store as a "Generic Volume". It doesn't really matter to me if the USB ports are blocked or not, what I do want is that No USB keys, harddrives or any other storage peripheral be allowed to be "enabled" on my mahcines, thus not allowing data to be "taken" from the network.
When I enable device control for "Mass Storage", the frame store gets blocked... 1 step forward and 2 steps back. I tried enabling access for "Disk Drives" and for "SCSI" (ATTO Celerity FC, falls under SCSI cards in Device Manager) but to no avail.
Is there some way around this? Or should I just "disable" USB support in the BIOS and leave things the way they are now? Hence, no access to anything USB (not even a mouse) and have access to my Framestore...
Thanks in advance.
Discussion Filed Under:
Comments 16 Comments • Jump to latest comment
00000001 00080000 00000000 000000b9 00000000 00000000000000b9 0000000e
000001d1 01c8a0bf3e01edb4 000000ee 00000007 2a01a8c0 00000000 00000000 00000000 00000000 01c8a0bf362049a4 01c8a0bf362049a4 00000001 00000000 Device Manager Message
Plug in the device again or restart to enable the device.
[name]:Generic volume
[class]:Storage volumes
[guid]:71a27cdd-812a-11d0-bec7-08002be2092f
[deviceID]:STORAGE\VOLUME\1&3735C57B&0&LDM#{80864CDC-35BC-4CEC-9C29-EA05D94AE86B}
Message Edited by Jason1222 on 04-24-2008 10:31 AM
Paul Murgatroyd
Principal Product Manager, Symantec Endpoint Protection
Endpoint twitter feed: http://twitter.com/symc_endpoint
Paul Murgatroyd
Principal Product Manager, Symantec Endpoint Protection
Endpoint twitter feed: http://twitter.com/symc_endpoint
[class]:Storage volumes
[guid]:71a27cdd-812a-11d0-bec7-08002be2092f
[deviceID]:STORAGE\VOLUME\1&3735C57B&0&LDM#{80864CDC-35BC-4CEC-9C29-EA05D94AE86B} à uß% ¨Û Default [user] [DOMAIN]
000001cf 01c8aa3aa70c75fa 000000ee 00000007 2a01a8c0 00000000 00000000 00000000 00000000 01c8aa3aa044e496 01c8aa3aa044e496 00000001 00000000
Device Manager Message
Plug in the device again or restart to enable the device.
[name]:Generic volume
[class]:Storage volumes
[guid]:71a27cdd-812a-11d0-bec7-08002be2092f
[deviceID]:STORAGE\VOLUME\1&3735C57B&0&LDM#{80864CDC-35BC-4CEC-9C29-EA05D94AE86B} à uß% 0Êè Default [user] [DOMAIN]
The device was enabled successfully."
Message Edited by Jason1222 on 04-29-2008 02:43 PM
Paul Murgatroyd
Principal Product Manager, Symantec Endpoint Protection
Endpoint twitter feed: http://twitter.com/symc_endpoint
Paul Murgatroyd
Principal Product Manager, Symantec Endpoint Protection
Endpoint twitter feed: http://twitter.com/symc_endpoint
I've been trying for a WEEK and can't make this work right! One time, the Kingston encrypted thumbdrive comes in as a CD, then as a floppy, it's never consistant.
Also, you can't PASTE into the new device class or ID.
I've run this thing on TWO computers and it will not let me paste, I mst type those bloody long strings by hand.
I've tried everything, wildcards, multiple IDs and classes, nothing works consistantly. It might work on one, then if I reboot, it won't work. Or it allows, then won't allow.
Each time you remove and reinsert, it's like a new device
Has anyone actually gotten it to work on multiple computers?
I want to block all thumbdrives, but ALLOW only the kingston secure data traveller.
Kingston encrypted USB "thumbdrive":
[class name]: <Unknown>
[guid]: {4d36e967-e325-11ce-bfc1-08002be10318}
[device id]: USBSTOR\DISK&VEN_KINGSTON&PROD_DTSECURE_PRIVACY&REV_6.51\0F7193711090989C&0
[MFG string]: (Standard disk drives)
[provider]: Microsoft
[driver data]: 6/21/2006
[driver version]: 6.0.6000.16386
[hidden device]: true
[Disabled]: false
[PNP device]: false
[can be disabled]: false
[device node]: 0x52fc
Kingston thumbdrive:
[class name]: <Unknown>
[guid]: {36fc9e60-c465-11cf-8056-444553540000}
[device id]: USB\VID_08EC&PID_204A\0F7193711090989C
[MFG string]: Compatible USB storage device
[provider]: Microsoft
[driver data]: 7/1/2001
[driver version]: 5.1.2600.0
[hidden device]: false
[Disabled]: false
[PNP device]: true
[can be disabled]: true
[device node]: 0x2d28
Kingston thumbdrive:
[class name]: <Unknown>
[guid]: {4d36e965-e325-11ce-bfc1-08002be10318}
[device id]: USBSTOR\CDROM&VEN_KINGSTON&PROD_DTSECURE_PRIVACY&REV_6.51\0F7193711090989C&1
[MFG string]: (Standard CD-ROM drives)
[provider]: Microsoft
[driver data]: 7/1/2001
[driver version]: 5.1.2535.0
[hidden device]: false
[Disabled]: false
[PNP device]: true
[can be disabled]: true
[device node]: 0x2d7c
[class name]: <Unknown>
[guid]: {71a27cdd-812a-11d0-bec7-08002be2092f}
[device id]: STORAGE\REMOVABLEMEDIA\7&B2A3224&0&RM
[MFG string]: Microsoft
[provider]: Microsoft
[driver data]: 7/1/2001
[driver version]: 5.1.2600.0
[hidden device]: false
[Disabled]: false
[PNP device]: true
[can be disabled]: true
[device node]: 0x2838
------------------------------------------------
Olympus DVR USB (dictation device):
[class name]: <Unknown>
[guid]: {4d36e967-e325-11ce-bfc1-08002be10318}
[device id]: USBSTOR\DISK&VEN_OLYMPUS&PROD_DVR&REV_1.00\6&3997D75&0
[MFG string]: (Standard disk drives)
[provider]: Microsoft
[driver data]: 6/21/2006
[driver version]: 6.0.6000.16386
[hidden device]: true
[Disabled]: false
[PNP device]: false
[can be disabled]: false
[device node]: 0x5398
[class name]: <Unknown>
[guid]: {4d36e965-e325-11ce-bfc1-08002be10318}
[device id]: USBSTOR\CDROM&VEN_KINGSTON&PROD_DTSECURE_PRIVACY&REV_6.51\0F7193711090989C&1
[MFG string]: (Standard CD-ROM drives)
[provider]: Microsoft
[driver data]: 7/1/2001
[driver version]: 5.1.2535.0
[hidden device]: true
[Disabled]: false
[PNP device]: false
[can be disabled]: false
[device node]: 0x5b70
Generic thumb-drive:
[class name]: <Unknown>
[guid]: {4d36e967-e325-11ce-bfc1-08002be10318}
[device id]: USBSTOR\DISK&VEN_&PROD_USB_DRIVE&REV_1.13\61460B04082D&0
[MFG string]: (Standard disk drives)
[provider]: Microsoft
[driver data]: 7/1/2001
[driver version]: 5.1.2535.0
[hidden device]: true
[Disabled]: false
[PNP device]: false
[can be disabled]: false
[device node]: 0x5c10
Dictation device:
[class name]: <Unknown>
[guid]: {36fc9e60-c465-11cf-8056-444553540000}
[device id]: USB\VID_07B4&PID_020B\5&1D3171BF&0&2
[MFG string]: Compatible USB storage device
[provider]: Microsoft
[driver data]: 7/1/2001
[driver version]: 5.1.2600.0
[hidden device]: false
[Disabled]: true
[PNP device]: true
[can be disabled]: true
[device node]: 0x345c
And how can you possibly paste - it won't let me.
My sites - http://theamcpages.com & http://antique-engines.com
Toy:
Shadow:
Would you like to reply?
Login or Register to post your comment.