Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: USB Defender & Specific Device Types

$
0
0

Yes, you will definitely want to import the list, but you may need to make some changes.

 

At a high level (easier said then done), here's what I would do:

 

1)  Put your rule in test mode.  (Be sure to hit Activate Rules)

2)  Import the UDLP list as a UDG (user defined group) - Import a text file to create a User Defined Group (UDG) - SolarWinds Worldwide, LLC. Help and Support

Note:  You will likely have to add some information to the UDLP file before you can import it as a UDG with the above instructions.

3)  Make sure the correct group is in your rule correlation.

4)  Make sure the rule is enabled and in test mode.

5)  Make sure it isn't blocking an approved device.

6)  Take the rule out of test mode (Activate Rules).

7)  Disable the UDLP connector.  Hopefully this is in a connector profile otherwise maybe you want to set one up if it makes sense and you can get all of your nodes or groups of nodes at once.

 

The idea is if both white lists are the same then an approved device shouldn't have any issues and you shouldn't see any end user side impact, it will be fully silent.

 

It cannot be stressed enough that you will want to test this for yourself.  So make sure you test (a few times if you want to be thorough) as there may be some environmental quirks you catch in the process.  To fully test it I would even suggest getting an unauthorized USB device or a new device if you're able, disable and delete the UDLP connector for a node, add it to the approved group for the rule and then test it to make sure that UDLP was fully removed and the device is allowed.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>