Endpoint Protection

 View Only
  • 1.  How to Block USB Wireless Broadband thru SEP

    Posted Dec 02, 2009 02:46 AM
    hi guys,

    i need your expertise with the subject matter. i tried manipulating application and device control but my tests produce unstable results. how can i effectively block usb wireless broadband thru SEP without affecting other USB functionalities?
    (* specific wireless broadband device: HUAWEI made by ZTE)

    thank yah!

    ^_^


  • 2.  RE: How to Block USB Wireless Broadband thru SEP

    Posted Dec 02, 2009 03:11 AM
    How to block USB Thumb Drives and USB Hard Drives, but allow specific USB Drives in the Application and Device Control Policy in Symantec Endpoint Protection. 

    It is better to block by using its GUID( Class ID)
    It will be available in the same options of device id...
    It may req. small modification in the above doc...


  • 3.  RE: How to Block USB Wireless Broadband thru SEP

    Posted Dec 02, 2009 03:28 AM
    thanks! i'll take a look at the reference you gave me.. ^_^


  • 4.  RE: How to Block USB Wireless Broadband thru SEP

    Posted Dec 02, 2009 03:55 AM

     Gather the Device ID of device(s) to exclude using the DevViewer tool:

    1. Find the DevViewer.exe tool on the SEP 11.0.X CD2 in the CD2\Tools\NoSupport\DevViewer folder.

    2. Plug in the device( USB Broad Band Modem) you want to gather the GUID from.

    3. Run the DevViewer.exe tool and browse to find the device. (Example, for a thumb drive, look under Disk drives)

    4. Select the device, and on the right you will see information about the device.

    5. Right click the [GUID] and select Copy GUID.

    6. Exit the DevViewer Tool.

    Add the Hardware Device into SEPM policy:

    1. In the SEPM, select the Policies view.

    2. In the upper left corner of the console, under the View Policies section, click on Policy Components to expand the sub-list.

    3. Under Policy Components, select Hardware Devices.

    4. Under Tasks, select Add a Hardware Device

    5. Type in the Name you wish to call your device (example: Administrator's Thumbdrive).

    6. Select the class ID option, click in the text box and use CTRL-V to paste the Device ID you copied from the DevViewer tool.

    7. Click OK.

    Add Hardware Device to Blocking list:

    1. In the SEPM, Under View Policies, select Application and Device Control

    2. Right click your Application and Device Control Policy and select Edit.

    3. Select the Device Control view.

    4. Under the Blocked Devices section, click Add, select t the device you added in the previous section and click OKand click OK

     


  • 5.  RE: How to Block USB Wireless Broadband thru SEP

    Posted Dec 02, 2009 01:10 PM
    Blocking via App/device control referencing device/GUID is the only reliable way; everything  else leaves too many open holes in my not so humble opinion.