Fortinet black logo

EMS Administration Guide

Removable media access

Removable media access

Control access to removable media devices, such as USB drives. You can configure rules to allow or block specific removable devices.

For the class, manufacturer, vendor ID, product ID, and revision, you can find the desired values for the device in one of the following ways:

  • Microsoft Windows Device Manager: select the device and view its properties.
  • USBDeview

Options

Description

Show bubble notifications

Display a bubble notification when FortiClient takes action with a removable media device.

Action

Configure the action to take with removable media devices connected to the endpoint that match this rule. Available options are:

  • Allow: allow access to removable media devices connected to the endpoint that match this rule.
  • Block: block access to removable media devices connected to the endpoint that match this rule.
  • Monitor: log removable media device connections to the endpoint that match this rule.

Description

Enter the desired rule description.

Type

Select Simple or Regular Expression for the rule type.

When you select Simple, FortiClient performs case-insensitive matching against classes, manufacturers, vendor and product IDs, and revisions.

When you select Regular Expression, FortiClient uses Perl Compatible Regular Expressions to perform matching against classes, manufacturers, vendor IDs, product IDs, and revisions.

Class

Enter the device class.

Manufacturer

Enter the device manufacturer.

Vendor ID

Enter the device vendor ID.

Product ID

Enter the device product ID.

Revision

Enter the device revision number.

Remove this rule

Remove this rule from the profile.

Add a new rule

Add a new removable media access rule.

Move this rule up/down

Move this rule up or down. If a connected device is eligible for multiple rules, FortiClient applies the highest rule to the device.

Default removable media access

Configure the action to take with removable media devices that do not match any configured rules. Available options are:

  • Allow: allow access to removable media devices connected to the endpoint that do not match any configured rules.
  • Block: block access to removable media devices connected to the endpoint that do not match any configured rules.
  • Monitor: log removable media device connections to the endpoint that do not match any configured rules.

Removable media access

Control access to removable media devices, such as USB drives. You can configure rules to allow or block specific removable devices.

For the class, manufacturer, vendor ID, product ID, and revision, you can find the desired values for the device in one of the following ways:

  • Microsoft Windows Device Manager: select the device and view its properties.
  • USBDeview

Options

Description

Show bubble notifications

Display a bubble notification when FortiClient takes action with a removable media device.

Action

Configure the action to take with removable media devices connected to the endpoint that match this rule. Available options are:

  • Allow: allow access to removable media devices connected to the endpoint that match this rule.
  • Block: block access to removable media devices connected to the endpoint that match this rule.
  • Monitor: log removable media device connections to the endpoint that match this rule.

Description

Enter the desired rule description.

Type

Select Simple or Regular Expression for the rule type.

When you select Simple, FortiClient performs case-insensitive matching against classes, manufacturers, vendor and product IDs, and revisions.

When you select Regular Expression, FortiClient uses Perl Compatible Regular Expressions to perform matching against classes, manufacturers, vendor IDs, product IDs, and revisions.

Class

Enter the device class.

Manufacturer

Enter the device manufacturer.

Vendor ID

Enter the device vendor ID.

Product ID

Enter the device product ID.

Revision

Enter the device revision number.

Remove this rule

Remove this rule from the profile.

Add a new rule

Add a new removable media access rule.

Move this rule up/down

Move this rule up or down. If a connected device is eligible for multiple rules, FortiClient applies the highest rule to the device.

Default removable media access

Configure the action to take with removable media devices that do not match any configured rules. Available options are:

  • Allow: allow access to removable media devices connected to the endpoint that do not match any configured rules.
  • Block: block access to removable media devices connected to the endpoint that do not match any configured rules.
  • Monitor: log removable media device connections to the endpoint that do not match any configured rules.