Endpoint Protection

 View Only
Expand all | Collapse all

Application and device control policy issue

  • 1.  Application and device control policy issue

    Posted Dec 16, 2013 12:50 PM

    Dear All,

    I have created a policy in SEPM 12.1.4 for USB Block and some data card  allow, But it is not working properly, after applying this policy all web camera get blocked even some scanner’s and printer’s are blocked.

    I have already excluded all printer and data card ( Vodafone 3 G, MTS, Tata photan) etc and printer. By device ID.

    Even it is very difficult to provide all printer’s device ID, and data cards device ID and scanner device ID.

    Is there any way to allow all printer by providing single device ID or class ID.



  • 2.  RE: Application and device control policy issue

    Posted Dec 16, 2013 12:52 PM

    Each manufacturer may have a different ID, there really isn't a clean cut solution for this. You can use DevViewer to get the ID and exclude using a wildcard

    Symantec Endpoint Protection Device Control: excluding devices from blocking show inconsistent results

    http://www.symantec.com/docs/TECH145804



  • 3.  RE: Application and device control policy issue

    Broadcom Employee
    Posted Dec 16, 2013 12:54 PM

    the devviewer tool can tell you the class id the one's thats not present in SEPM.



  • 4.  RE: Application and device control policy issue

    Posted Dec 16, 2013 12:57 PM

    how can I see class ID, pls share the screen shot



  • 5.  RE: Application and device control policy issue

    Posted Dec 16, 2013 01:09 PM

    Guid is class id, you can add it using dev viewer.

    dev.png



  • 6.  RE: Application and device control policy issue

    Posted Dec 16, 2013 01:13 PM

    Open devviewer and it will show you. You can see it here:

    DevViewer - a tool for finding hardware device ID for Device Blocking in Symantec Endpoint Protection

    Article:TECH103401  |  Created: 2007-01-19  |  Updated: 2011-12-28  |  Article URL http://www.symantec.com/docs/TECH103401

    Obtaining a class ID or device ID

    Article:HOWTO80755  |  Created: 2012-10-24  |  Updated: 2013-10-07  |  Article URL http://www.symantec.com/docs/HOWTO80755

     

    Untitled_2.jpg



  • 7.  RE: Application and device control policy issue

    Posted Dec 16, 2013 01:14 PM

    You mean guid means class ID.

    Means if I salect guid for HP printer then it will allow all HP printer.



  • 8.  RE: Application and device control policy issue

    Posted Dec 16, 2013 01:16 PM

    It will only allow for that specific device



  • 9.  RE: Application and device control policy issue

    Posted Dec 16, 2013 01:25 PM

    It will be very difficult for all HP scanner, means I have to add class ID for all scanner's and printer and data card too.

    is there any way to add a single class ID for all HP printer and all Tata photan data card etc. because there is lot's of scanner and printer's in my office and not possible to add one by one by adding class ID or device ID.



  • 10.  RE: Application and device control policy issue

    Posted Dec 16, 2013 01:29 PM

    If they have a similar ID than you can use a wildcard, for example *hp* or something similar to that.

    There is no option to add in bulk though

    SEPM already has a predefined set of hardware device IDs, although I don't see anything specific to an HP printer

    You're best bet is to use a wildcard * to define an entire dataset and see if this works.



  • 11.  RE: Application and device control policy issue
    Best Answer

    Posted Dec 16, 2013 01:38 PM

    You can add the device id of hp printer till rev. after that add the asteric(*) sign.

    http://www.symantec.com/avcenter/security/ADC/Configuring_Application_Control_1.1.pdf

    *Edit*

    Eg - USBSTOR\DISK&VEN_SANDISK&PROD_CRUZER_MICRO&REV_2033\0002071406&0

    Chooser till  - USBSTOR\DISK&VEN_SANDISK&PROD_CRUZER_MICRO* (add *)

    For more reff

    https://www-secure.symantec.com/connect/articles/how-block-or-allow-devices-symantec-endpoint-protection



  • 12.  RE: Application and device control policy issue

    Posted Dec 17, 2013 10:43 AM

    thank you all