HP ProLiant xw2x220c Remote Graphics Software 5.3.0 User Guide - Page 112

Vendor ID-idVendor, Device BCD-bcdDevice

Page 112 highlights

Rules may contain filters based on the 11 parameters listed previously. These parameters are repeated below along with the name of the filter element. 1. Device Class-bDeviceClass 2. Device Subclass-bDeviceSubclass 3. Device Protocol-bDeviceProtocol 4. Vendor ID-idVendor 5. Product ID-idProduct 6. Device BCD-bcdDevice 7. Manufacturer-manufacturer 8. Product Type-product 9. Serial Number-serialNumber CAUTION: Filtering on device strings (manufacturer, product, and serial number) may not be reliable. Device vendors are not required to add data to these fields, and many do not. Before deploying a solution that depends on a string-based filter, ensure that the devices you wish to use implement the appropriate device strings. • IP address of the Local Computer-peerAddress • The domain group of the local user-group The following ACL file allows only USB devices with a Device Class (bDeviceClass) of 7 to be remotely attached while denying everything else: Allow printing devices The following ACL file denies USB devices for a specific range of Local Computer IP addresses while allowing all other Local Computers to use remote USB: Allow all devices Deny 192.168.9.0 subnet The following ACL file allows USB connections for members of the DEFAULT-DOMAIN\administrators group while denying all other USB connections: Allow members of DEFAULT-DOMAIN\administrators Advanced capabilities 112

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196

Advanced capabilities 112
Rules may contain filters based on the 11 parameters listed previously. These parameters are repeated below
along with the name of the filter element.
1.
Device Class—
bDeviceClass
2.
Device Subclass—bDeviceSubclass
3.
Device Protocol—bDeviceProtocol
4.
Vendor ID—idVendor
5.
Product ID—idProduct
6.
Device BCD—bcdDevice
7.
Manufacturer—manufacturer
8.
Product Type—product
9.
Serial Number—serialNumber
CAUTION:
Filtering on device strings (manufacturer, product, and serial number) may not be reliable.
Device vendors are not required to add data to these fields, and many do not. Before deploying a
solution that depends on a string-based filter, ensure that the devices you wish to use implement the
appropriate device strings.
IP address of the Local Computer—
peerAddress
The domain group of the local user—
group
The following ACL file allows only USB devices with a Device Class (
bDeviceClass
) of 7 to be remotely
attached while denying everything else:
<hprUsbAcl>
<ruleset>
<rule type="allow">
<name>Allow printing devices</name>
<filter bDeviceClass="07"/>
</rule>
</ruleset>
</hprUsbAcl>
The following ACL file denies USB devices for a specific range of Local Computer IP addresses while allowing all
other Local Computers to use remote USB:
<hprUsbAcl>
<ruleset>
<rule type="allow">
<name>Allow all devices</name>
</rule>
<rule type="deny">
<name>Deny 192.168.9.0 subnet</name>
<filter peerAddress="192.168.9.0/20"/>
</rule>
</ruleset>
</hprUsbAcl>
The following ACL file allows USB connections for members of the DEFAULT-DOMAIN\administrators group while
denying all other USB connections:
<hprUsbAcl>
<ruleset>
<rule type="allow">
<name>Allow members of DEFAULT-DOMAIN\administrators</name>
<filter group="DEFAULT-DOMAIN\administrators"/>
</rule>
</ruleset>
</hprUsbAcl>