Endpoint Protection

 View Only
  • 1.  Application policy for BESR (Backup Exec System Recovery)??

    Posted Oct 05, 2010 01:14 PM

    Has anybody configured one?? If so, how did you do it??

    We want to block most USB devices from being written or read but we have a few people with BESR backups to USB drives.

    It seems like the best approach is to configure an app policy for BESR and to configure allowing writes to its specific USB drive.

    Meanwhile I will RTFM.

    Thank you, Tom



  • 2.  RE: Application policy for BESR (Backup Exec System Recovery)??

    Posted Oct 05, 2010 01:38 PM

    If you don't want to allow users to access the USB drives, exceptions would need to be made to allow BESR to write to the devices.

    The other option would be to create exceptions for the specific USB devices and allow all users and software to write to them. This would be much simpler to configure, but would sacrifice some security.

    How to use Application and Device Control to block all USB devices except those I specifically want to allow
    http://www.symantec.com/business/support/index?page=content&id=TECH105770&locale=en_US

    How to configure Application Control in Symantec Endpoint Protection 11.0 : Configuring Application Control Policies
    http://www.symantec.com/business/support/index?page=content&id=TECH102525&locale=en_US



  • 3.  RE: Application policy for BESR (Backup Exec System Recovery)??

    Posted Oct 05, 2010 02:14 PM

    now I am puzzled again.

    I do not have access to the PC with BESR or the USB drive yet, and I don't know if BESR requires multiple files or processes etc. to do its backups...

    I probably should allow the USB device itself upon figuring out its Device ID.

    Can I use the DevViewer tool from any PC to detect the appropriate device ID for the specific USB device??

    Thank you, Tom



  • 4.  RE: Application policy for BESR (Backup Exec System Recovery)??

    Posted Oct 05, 2010 02:27 PM

    If you make your USB read only using Application Control.It will block BESR or any user writing to USB