Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
inadmin1
Participant

blocking USB pen drive

Hi, is it possible to block Pen (USB) disk on key drives?

13 Replies
_Val_
Admin
Admin

Yes

0 Kudos
inadmin1
Participant

How?

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Using Media Encryption & Port Protection (MEPP) features of Harmony Endpoint.

https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/...

CCSM R77/R80/ELITE
inadmin1
Participant

The link is dead...

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Not sure why following the link isn't working, just search the admin guide from support centre for Harmony Endpoint.

Section: "Configuring Media Encryption & Port Protection"

CCSM R77/R80/ELITE
0 Kudos
inadmin1
Participant

Under port protection, the only thing that i saw there was "Windows_CE_Devices_USB".

It did not block access to USB stick/pen drive.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Suggest investigating auto device discovery further e.g.

https://community.checkpoint.com/t5/Endpoint/Allow-only-authorized-USB/td-p/68039

CCSM R77/R80/ELITE
0 Kudos
inadmin1
Participant

but that explains how to exclude certain drives. I am at the previous stage- trying to block globally.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

How did you configure the default read/write settings or rather what configuration have you done?

CCSM R77/R80/ELITE
0 Kudos
TNatCLS
Explorer

Hi. I have the same question. I read the user guide here, and I am in the right place in the UI, but the list of ports does not specify a USB drive for windows.  How do I prevent USB (removable) storage from being used?

0 Kudos
alexeim
Employee
Employee

That works not on the port level, but on file IO level. Look for read/write policy settings for removable media. Untick "Allow unencrypted data" in read section and select "Block Any Data" in write section.

When you get removable storage media blocked you can create exclusions for specific drives based on the list of discovered devices.

0 Kudos
Mitja-S3NEXT
Collaborator

 
Windows Portable Devices - option blocked - in the port protection custom settings should solve the problem
 

 

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events