Block USB stick
Updated: 22 May 2010 | 21 comments
This issue has been solved. See solution.
Hello All
I would like to block USB Stick with the Symantec Endpoint Protection Manager.Today I using this forum (http://www.symantec.com/connect/forums/block-pen-d...).This forum will help.But from my notebook I have 4 usb port .Each usb port have different Device ID.I put all the device ID into the application & device control.It is work.If i want to block usb stick from the another PC.I will be put all the device ID into the application & device control.I think this is not the good way.So how can I block USB stick with only one device ID?
discussion Filed Under:
Comments
Do you mean this
How to block USB flash drives while allowing other USB devices.
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
you try by block using the
you try by block using the device id of your usb stick ..
You can also use guid (Device id) for blocking..
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
How to create a rule that
How to create a rule that will allow only specific USB’s on to your network
http://service1.symantec.com/support/ent-security.nsf/docid/2009031809381448
VMWARE-- SEP 12.1 vs McAfee vs Trend Micro
hello again
How can i try to block usb with device id?
usb stick
I need to block only usb stick with device id.
Try this
Identifying Devices in Device Manager with PCIDatabase
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
The doc above shows how to do
The doc above shows how to do that
http://service1.symantec.com/support/ent-security....
VMWARE-- SEP 12.1 vs McAfee vs Trend Micro
For more info refer
Device Identification Strings
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Hi
Hi
Download CD2 and use Dev Viewer
Try these Documents this may Help you
How to use Application and Device Control to block all USB devices except those I specifically want to allow
http://service1.symantec.com/support/ent-security.nsf/docid/2008083110540548
How to block USB Thumb Drives and USB Hard Drives, but allow specific USB Drives in the Application and Device Control Policy in Symantec Endpoint Protection.
http://service1.symantec.com/support/ent-security.nsf/docid/2008102008020548
I can block
I can block the usb stick from my notebook but if I replace another port from my notebook it can use.If i use this stick from the different notebook it can use.That notebook is in the same group of my note book.How could this happen?
Run Dev Viewer in notebooks
Run Dev Viewer in notebooks by connecting usb stick in various ports and see whether it is giving same id or different id
It should be same...
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
hello again
From the device view of my notebook it show device id is drifferent and GUI is same.Can i use GUI to block the USB stick?
Yes you can use guid.GUID
Yes you can use guid.GUID also known as class id..
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
hello
I cannot add the GUID as a class id because GUID is already have it in USB hardware class id.
I didn't get you Both GUID
I didn't get you
Both GUID and Class ID are same ,both are different names of same thing
ref:Page no 526 administration guide
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Below informations will be helpful to you
To obtain a class ID or device ID by using the DevViewer tool
1 On CD 3 of your product, locate the \TOOLS\NOSUPPORT\DEVVIEWER
directory, and then download the DevViewer.exe tool to the client computer.
2 On the client computer, run DevViewer.exe.
3 Expand the Device Tree and locate the device for which you want the device
ID or the GUID.
4 In the right-hand pane, right-click the device ID (it starts with [device id]),
and then click Copy Device ID.
5 Click Exit.
6 On the management server, paste the device ID into the list of hardware
devices.
To obtain a device ID from Control Panel
1 On the Windows taskbar, click Start > Settings > Control Panel > System.
2 On the Hardware tab, click Device Manager.
3 In the Device Manager list, double-click the device.
4 In the device's Properties dialog box, on the Details tab, select the Device ID.
By default, the Device ID is the first value displayed.
5 Press Control+C to copy the ID string.
6 Click OK or Cancel.
Adding a hardware device to the Hardware Devices
list
After you obtain a class ID or device ID for a hardware device, you can add the
hardware device to the default Hardware Devices list. You can then access this
default list from the device control part of the Application and Device Control
Policy.
To add hardware devices to the Hardware Devices list
1 In the console, click Policies.
2 Under Policy Components, click Hardware Devices.
3 Under Tasks, click Add a Hardware Device.
4 Enter the name of the device you want to add.
Both Class IDs and Device IDs are enclosed in curly braces by convention.
5 Select either Class ID or Device ID, and paste the ID that you copied from
the Windows Device Manager or the DevViewer tool.
6 You can use wildcard characters to define a set of device IDs. For example,
you can use the following string: *IDE\CDROM*.
7 Click OK.
Adding a hardware device to the Hardware Devices list
Editing a hardware device in the Hardware Devices
list
You can edit any hardware devices that you have added to the list. The default
devices that are listed cannot be edited.
To edit a hardware device in the Hardware Devices list
1 In the console, click Policies.
2 Under Policy Components, click Hardware Devices.
3 In the Hardware Devices list, click the hardware device you want to edit.
4 Click Edit the Hardware Device.
5 Edit either the device name, the class ID, or the device ID.
6 Click OK.
The updated device information is displayed in the Identification list.
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
After doing the above steps
1. In the SEPM, Under View Policies, select Application and Device Control
2. Right click your Application and Device Control Policy and select Edit
3.Select the Device Control view.
4 Under the Blocked Devices section, click Add, select the device name which you given earlier for your usb stick and click OK.
5 Click OK to the Application and Device Control policy window.
Now that device will be disabled..
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Your problem got solved?
Your problem got solved?
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Sounds like you were blocking
Sounds like you were blocking the device ID of the USB PORT and not the ID of the memory stick or thumb-drive.
There's a difference..............
You need to block the id of the device you plug in, not what you plug in to.
Look in the registry, local machine, system, current control, enum - and look under USBSTOR. All USB storage devices that have ever been connected will be there.
find the ID that goes with that thumb drive. They are listed by vendor and model such as VEN_KINGSTON for kingston brand devices, and PROD_DTSecure is the model of the Kingston thumbdrive.
My sites - http://theamcpages.com & http://antique-engines.com
Toy:
Shadow:
I think you can block the
I think you can block the USB port itself & allow the USB devices that you want to allow over it.
Try this document
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008022822274348
hello all
Today I fix it.I try kavin document and It is work.Thank you for helping me into this forum.
Would you like to reply?
Login or Register to post your comment.