Avamar: Gen4T and Gen4S Hardware: How to disable "boot from USB"
Summary: This article provides the steps to disable "boot from USB" option inside the BIOS for Avamar Gen4S and Gen4T Hardware.
Instructions
The Avamar Product Security Guide provides the following guidelines about the "Boot from USB" option:
Disable boot from USB and boot from CD/DVD in the BIOS settings of the Avamar system computers to prevent starting the computers from remote media. Do not put the USB interface in the boot path.
The BIOS settings can be modified to prevent USB devices from appearing in the boot option menu.
Perform these steps:
1. Take a checkpoint, and verify that there is a recent checkpoint validation (hfscheck).
2. Shut down the Avamar services using Avamar: How to to Safely Shut Down and Restart
3. After the services are stopped, reboot each node one at a time and perform the following steps on each:
-
-
During Boot, Press <F2> or <Del> to enter BIOS setup.
-
Navigate to Advanced -> USB Configuration
-
Set "USB Mass Storage Drive" to Disabled (This disables USB Mass Storage Driver Support so that no USB drives appear as a boot option)
-
Save and exit
-
-
-
During Boot, Press <F2> or <Del> to enter BIOS setup.
-
Navigate to Advanced -> USB Configuration
-
Set "Make USB Devices Non-Bootable" to Enabled
-
Press <F10> to save changes and reset
-
4. Once all nodes are back online, restart the Avamar Services. (Avamar: How to to Safely Shut Down and Restart)