Endpoint Protection

 View Only
Expand all | Collapse all

Block RDP access of client using SEPM 11

Migration User

Migration UserNov 12, 2010 11:56 PM

Migration User

Migration UserNov 13, 2010 01:49 AM

Migration User

Migration UserNov 13, 2010 01:59 AM

Migration User

Migration UserNov 13, 2010 06:49 AM

Migration User

Migration UserNov 15, 2010 05:38 AM

Migration User

Migration UserNov 15, 2010 06:16 AM

Migration User

Migration UserNov 15, 2010 07:14 AM

Migration User

Migration UserNov 16, 2010 07:30 AM

Migration User

Migration UserNov 18, 2010 01:51 AM

  • 1.  Block RDP access of client using SEPM 11

    Posted Nov 12, 2010 11:30 PM

    Hi,

    I have installed SEPM 11 in my office. I want to block the client machines from taking remote control of any other machines.

    I dont have any AD setup at my end.

    I want to block RDP using SEPM.

     

    Regards,

    Subodh



  • 2.  RE: Block RDP access of client using SEPM 11

    Posted Nov 12, 2010 11:56 PM

    Create a firewall rule for blocking RDP port(3389)



  • 3.  RE: Block RDP access of client using SEPM 11

    Posted Nov 12, 2010 11:57 PM

    You need to install all the components of SEP, you need to block the  port 3389 using SEPM.

    open sepm

    policies

    firewall policy

     

    Modify the   firewall rule to allow "Block Remote Administration"

    enabling the rule will allow Remote Desktop connections onto the computer.



  • 4.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 01:36 AM

    Hi,

     

    Thanks a lot.

    I donot want to block port 3389.

    We have application installed at my end that helps you to take remote of client machine directly. All users donot use that application. We want all users to use that app.

     

    When we go in Start -> Run type mstsc by default mstsc.exe file present in system32 is called. We want to block access of that file. We have create a application control but it is not working.

     

    Regards,

    Subodh R. Dangat



  • 5.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 01:40 AM

    For this features to work you need to install all the features in he client.Whether it is installed?



  • 6.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 01:44 AM

    Yes

    We have installed all features at the client site.

    Regards,

    Subodh R. Dangat



  • 7.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 01:49 AM

    Can you give us a screen shot of the policy?



  • 8.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 01:59 AM

    When we go in Start -> Run type mstsc by default mstsc.exe file present in system32 is called. We want to block access of that file. We have create a application control but it is not working.

    So you want to prevent people from using Microsoft's Remote Desktop Application?  You may want to double check your steps against this document.

    How to configure Application Control in Symantec Endpoint Protection 11.0 : Configuring Application Control Policies
    http://www.symantec.com/docs/TECH102525

    Bear in mind, Application and Device Control Policies do not work on 64-bit client computers.

    sandra



  • 9.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 01:59 AM

    I'm attaching the screen shots of the same.



  • 10.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 04:40 AM

    Keep this rule as the first rule and try.Also assure that this policy is got applied in the client.You can use policy serial number for that...



  • 11.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 04:59 AM

    I have done the same.

     

    But it not working. I am to mstsc from client machine.



  • 12.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 05:06 AM

    I have also enabled loggin in above rule set.

    From where can i find the logs. Where are the logs stored in SEPM

    Its urgent. Please help ASAP



  • 13.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 05:51 AM
    In SEPM go to Monitors--->logs-->application and device controls-->Application control,select appropriate time range and click on view log.....


  • 14.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 05:56 AM

    Also try by rebooting the system.It is observed that some times system required a reboot for getting the policy to work...



  • 15.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 05:57 AM

    Whether your system is 32 bit or 64 bit?If it is 64 bit application and device control policies will not work.....



  • 16.  RE: Block RDP access of client using SEPM 11

    Posted Nov 13, 2010 06:49 AM

    System is 32 bit



  • 17.  RE: Block RDP access of client using SEPM 11

    Posted Nov 15, 2010 01:33 AM

    I have tried rebboting both the client and SEPM server but its not working.

    Please help.



  • 18.  RE: Block RDP access of client using SEPM 11

    Posted Nov 15, 2010 03:56 AM

    Try by block using the hash value of mstc insted of file name....



  • 19.  RE: Block RDP access of client using SEPM 11

    Posted Nov 15, 2010 05:38 AM

    How to block hashvalue of mstc

     

    Regards,

    Subodh



  • 20.  RE: Block RDP access of client using SEPM 11
    Best Answer

    Posted Nov 15, 2010 05:57 AM
    Have a look at this thread How to block applications in SEP using MD5 https://www-secure.symantec.com/connect/forums/how-block-applications-sep-using-md5


  • 21.  RE: Block RDP access of client using SEPM 11

    Posted Nov 15, 2010 06:16 AM

    what will be the MD5 hash value foe mstsc.exe



  • 22.  RE: Block RDP access of client using SEPM 11

    Posted Nov 15, 2010 06:38 AM

    8148d865276c330ed47160728816bf12

     

    Note:This value I found using http://virustotal.com.My file version was 5.1.2600.2180.If in your system if it is different you may use this site/similar site/tool for determining the MD5 value of the file....



  • 23.  RE: Block RDP access of client using SEPM 11

    Posted Nov 15, 2010 07:12 AM

    Thanks a lot arvind!!!!!!

     

    The link was very much helpful!!!!!!!!!!

     

    thank you once again!!!!!!!!!!!!!!!!



  • 24.  RE: Block RDP access of client using SEPM 11

    Posted Nov 15, 2010 07:14 AM

    Happy to hear your problem got solved....



  • 25.  RE: Block RDP access of client using SEPM 11

    Posted Nov 16, 2010 07:12 AM

    Hi,

    As you know that i have blocked mstsc.exe.

     

    Now suppose i have process abc.exe which calls mstsc.exe. As abc.exe calls mstsc.exe abc.exe gets blocked.

    Now suppose it do not want abc.exe to get blocked then what should i do?



  • 26.  RE: Block RDP access of client using SEPM 11

    Posted Nov 16, 2010 07:30 AM

    Try by adding abc.exe in exception of that rule..



  • 27.  RE: Block RDP access of client using SEPM 11

    Posted Nov 17, 2010 12:49 AM

    Hi,

     

    I have added the exception for that rule.

    I have found the fingreprint of abc.exe using checksum.exe and added the execption.

    Will the above method work



  • 28.  RE: Block RDP access of client using SEPM 11

    Posted Nov 17, 2010 12:54 AM

    the exception process will not be blocked. It should work.



  • 29.  RE: Block RDP access of client using SEPM 11

    Posted Nov 17, 2010 01:05 AM

    NO!! My process is still getting blocked?

    abc.exe is not working it is getting block because it is calling some part of mstsc.exe



  • 30.  RE: Block RDP access of client using SEPM 11

    Posted Nov 18, 2010 01:51 AM

    Any 1 has a solution.

    plz help!!!!



  • 31.  RE: Block RDP access of client using SEPM 11

    Posted Nov 18, 2010 01:56 AM

    I think then it is not possible.abc.exe may be working like this.It will call mstsc and fining it is blocked and stopping the execution.If this is the case you may have to contact the abc.exe program developer to write in such a way that even if mstsc.exe got blocked abc.exe should not stop it's execution........



  • 32.  RE: Block RDP access of client using SEPM 11

    Posted Nov 19, 2010 12:56 AM

    Thanks a lot.

     

    I have run SEPSupport tools and saved its report.

    Now that report extension is .sdbz.

    How can I open that file?



  • 33.  RE: Block RDP access of client using SEPM 11

    Posted Nov 19, 2010 10:32 AM

    You can look at the file with the Support Tool for errors.  Support can look more in depth at the collected files, though I'm not sure what we could look at that would tell us why your policy isn't working.

    You would do better to use something like Process Monitor to see what's happening when abc.exe launches with the policy in place, and what happens when abc.exe is launched with the policy not in place.

    sandra



  • 34.  RE: Block RDP access of client using SEPM 11

    Posted Nov 22, 2010 01:27 AM

    abc.exe call mstsc.exe.

     

    When we run abc.exe and go to Task Manager right click on abc.exe (in Application Tab) click on go to process it goes to mstsc.exe.