VMware Horizon Community
btrabue
Enthusiast
Enthusiast

USB Redirection Question that has me puzzled

Hello -

I have been given the task to disable USB redirection for all VMware VIEW users but ONLY when connecting to an external broker.  I found the attached script that will disable thinprint when connecting to an external broker and was wondering if someone had a similiar way to disable USB redirection?

I have read that I could setup a GPO and I could also setup the pool to disable USB redirection but those two options are for both internal and external connections.

Thanks in advance for your help!

This is being applied to Windows 7 x64 virtual computers

Reply
0 Kudos
8 Replies
Linjo
Leadership
Leadership

You could disallow TCP 32111 from the security server to the desktops.

Best regards, Linjo Please follow me on twitter: @viewgeek If you find this information useful, please award points for "correct" or "helpful".
Reply
0 Kudos
btrabue
Enthusiast
Enthusiast

Would that only affect users connecting to the external broker?  How would I re enable it when they came back into the office?  Thank you!!

Reply
0 Kudos
Linjo
Leadership
Leadership

Typically you would have a security server for external users and a connection broker for your internal users.

So if you disallowed this port then it should not be possible to connect a USB device when coming from an external connection.

Best regards, Linjo Please follow me on twitter: @viewgeek If you find this information useful, please award points for "correct" or "helpful".
Reply
0 Kudos
btrabue
Enthusiast
Enthusiast

First, thank you for your help!

We have disabled the users from connecting via RDP.  If I was to disable TCP 32111 then I just want to make sure that they will still be able to use the USB devices here in the office.  Another thing, will this disable the USB keyboard and mouse that they could be using while at home?

Reply
0 Kudos
Linjo
Leadership
Leadership

Yes, if you are disallowing it from the correct server.

Keyboard, mouse and smartcard-readers will not be affected.

// Linjo

Best regards, Linjo Please follow me on twitter: @viewgeek If you find this information useful, please award points for "correct" or "helpful".
Reply
0 Kudos
btrabue
Enthusiast
Enthusiast

We have confirmed over and over that TCP 32111 is blocked on the external security brokers and USB redirection is still working when I try and access it from outside the office.  Any other ideas?

Reply
0 Kudos
Linjo
Leadership
Leadership

That's strange, maybe fire up a wireshark session to look at how the traffic goes.

This poster is pretty clear about the traffic: VMware KB: Network port diagram for Horizon View

Best regards, Linjo Please follow me on twitter: @viewgeek If you find this information useful, please award points for "correct" or "helpful".
Reply
0 Kudos
btrabue
Enthusiast
Enthusiast

We ended up upgrading our test environment to 5.3.  As soon as we did that I had TCP 32111 blocked on the security servers and after a few minutes USB redirection was no longer working when connecting from outside the office.  Could this possibly be working as needed because of the upgrade?  We were using 5.1.2 on our test environment when we did the USB redirection test the first time and it did not work.  Thanks for your help!

Reply
0 Kudos