USBGuard
USBGuard enforces a default-block policy for USB devices attached to the Rocky Linux host. Recurring required devices receive explicit allow rules; an ordinary device without a matching rule is blocked. This is a host enforcement layer alongside network controls such as WireGuard and service authentication such as SSH and NoMachine.
Device rules, not port trust
Persistent allow rules match a USB vendor/product ID together with a device-reported serial number. They identify device attributes rather than a physical USB port. An allowed device can match its rule when moved to another port, while a different device connected to its former port does not inherit trust.
USBGuard also assigns runtime device IDs. Those IDs can change after reconnecting a device, restarting USBGuard, or rebooting. The persistent policy uses device attributes rather than runtime IDs, and USBGuard is configured to start at boot.
Network recovery boundary
The host's Ethernet interface depends on a USB Ethernet adapter covered by an allow rule. A policy error that blocks the adapter can remove an important remote administration path. Policy changes therefore keep an independent recovery path available while the USB and network state is checked.
Security limit
Vendor/product IDs and serial numbers are descriptors supplied by the device. Matching both narrows the allow rule and rejects ordinary unknown hardware, but it is not cryptographic device authentication. A device capable of impersonating the matching descriptors may pass the rule. Physical access security and normal operating-system and service authentication remain separate controls.