[LIST=1]
- Does the Device Control feature stop all USB devices or just storage devices?
- Is it possible to create a list of approved devices and have the endpoint protection only allow those devices?
This thread was automatically locked due to age.
1) In WebAdmin, navigate to Endpoint Protection > Device Control > Policies. click Add Device. Look at the configuration options available. These are the available device types to configure. Notice there is no USB category.
2) Use the Block ALL policy to block most devices by default. Then you can create exceptions as needed.
This information was easily available just by looking at the GUI in WebAdmin and reading 2 short pages of the built-in help.
The delay is due to how the Endpoint system works in UTM. The Endpoints never "talk" directly to the UTM or vice-versa. There's Sophos Broker server in the "cloud" between the two, so communication looks like this:
UTM ----> Broker ----> Endpoints
Endpoints ----> Broker ----> UTM
This means there will always be a delay in transfer of data between the two.
Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.
Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.