Endpoint Protection

 View Only
Expand all | Collapse all

How to UN-do USB blocking??

  • 1.  How to UN-do USB blocking??

    Posted Dec 06, 2010 03:52 PM

    Two PCs got put into a client group with USB blocking turned on.

    On each one I moved the client PC into a 'group' that does NOT have USB enabled but the PCs still have USB blocked, how to fix this??

    On one PC we can try a re-install of the client with the correct policy chosen by the installer, but the 2nd one should have worked by it just being moved to a new client/policy group.

    What is the best remedy?? Re-install?? It is annoying that the move clients does not effect the desired policy changes.

    Thank you, Tom



  • 2.  RE: How to UN-do USB blocking??

    Posted Dec 06, 2010 03:56 PM

    Did you reboot the client after moving to the new group? Anytime you make a change to the Application and Device control policy a reboot is required.

     



  • 3.  RE: How to UN-do USB blocking??

    Posted Dec 06, 2010 03:57 PM

    Can you confirm the client picked up the new policy to disable the application and device control policy?



  • 4.  RE: How to UN-do USB blocking??

    Posted Dec 06, 2010 04:02 PM

    Other way around -- we want to ENABLE the USB drive usage, not disable it.

    Yes, reboots have been done...will double-check on this.

    Thank you, Tom



  • 5.  RE: How to UN-do USB blocking??

    Posted Dec 06, 2010 04:06 PM

    What is your heartbeat set to? Perhaps the clients just haven't picked up the policy yet.

    You can verify in the System log on the client under View Logs >> Client Management >> System Log. You should see something along of the lines of Applied New Policy, reboot is needed.....

    Also, application and device control does not work on 64-bit so if these are 64-bit machines, your out of luck.



  • 6.  RE: How to UN-do USB blocking??

    Posted Dec 06, 2010 04:10 PM

    On the Client..Right Click on the SEP Client Icon--update Policy.



  • 7.  RE: How to UN-do USB blocking??

    Posted Dec 06, 2010 07:49 PM

    Brian81 said: "Also, application and device control does not work on 64-bit so if these are 64-bit machines, your out of luck."

    Does this refer to the processor or the OS??

    If the processor is 64-bit but the OS is 32-bit XP, what happens??

    Thank you, Tom



  • 8.  RE: How to UN-do USB blocking??

    Posted Dec 06, 2010 07:50 PM

    We already did the update policy, part of the problem is I forgot ADP does not work on 64-bit PCs...please see my question above about the processor vs. OS.

    One for sure is 64-bit cpu, the other one is XP SP3 on I *think* 64-bit CPU, it is not clear to me if this will or will not work.

    Thank you, Tom



  • 9.  RE: How to UN-do USB blocking??

    Posted Dec 06, 2010 08:13 PM

    It will not, device control is not suport on 64-bit systems

    Symantec Endpoint Protection 11.0 compatibility with 64-bit platform

    http://www.symantec.com/business/support/index?page=content&id=TECH102143&locale=en_US



  • 10.  RE: How to UN-do USB blocking??

    Posted Dec 06, 2010 09:32 PM

    The above-mentioned Symantec site does not say anything about 32-bit OS on 64-bit processor.

    It says "...64-bit processors and operating systems."

    Which is what I have on one PC wherein USB drives ARE blocked within the package's ADC policy and will not appear and I want to UN-do this...I already unsuccessfully tried moving the PC to a different client group with a different policy.

    Tomorrow I plan to re-install to the same PC the 32-bit client with a different policy that does not block USB drives and see what happens.

    I can also make and install a package without ADC enabled...32-bit as the OS on this PC is XP SP3.

    I know I'm being picky so I will continue testing etc. and try to post my results here.

    Thank you, Tom



  • 11.  RE: How to UN-do USB blocking??

    Posted Dec 06, 2010 10:02 PM

    Yes, it is dependent on OS. So if x86, it will work. Otherwise, it will not.



  • 12.  RE: How to UN-do USB blocking??

    Posted Dec 07, 2010 03:41 AM

    It's gonna work fine on 32-bit Windows XP even if the CPU is 64-bit. It is due to some limitations on 64-bit OS - kernel patch protection for example.



  • 13.  RE: How to UN-do USB blocking??

    Posted Dec 07, 2010 11:03 AM

    I fixed by doing the following:

    1) reinstall a client with the correct policy settings, still did not work

    2) moved client to a different group with USB enabled, re-enabled the drives

    3) moved client back to desired group, drives still worked

    Also I added 'Disk Drives' to the USB enabling part so they would work...kind of clunky but it works as desired for that PC...most PCs we do not want USB stuff enabled...

    Thank you, Tom



  • 14.  RE: How to UN-do USB blocking??

    Posted Dec 07, 2010 03:53 PM

    Hello,

    I think so your registy key cannot fix itself. Please check this key HKEY_Local_Machine\System\CurrentControlSet\Services\usbstor. in this place start key must be 3

    Please check it. And maybe your hard drive cannot take a path. Please rigth click on computer and choice manage. click disk management and be sure your hard drive in there. If havent got a driver name rigth click and change name and path

    Best Regards.

    Fatih



  • 15.  RE: How to UN-do USB blocking??

    Posted Dec 13, 2010 02:11 PM

    Hello Tom,

    Did you try my suggest?

    Best Regards.

    Fatih