HP 630n HP Jetdirect Print Servers - Administrator's Guide - Page 124

Security features V.38.xx, Summary of HP Jetdirect security features continued

Page 124 highlights

Table 6-1 Summary of HP Jetdirect security features (continued) IPv4 Access Control List NOTE: The Firewall feature provides improved security and can be used in place of the IPv4 ACL. ● Specify up to 10 IPv4 host systems, or IPv4 networks of host systems, that are allowed access to the HP Jetdirect print server and the attached network device. (If the list is empty, then all hosts are allowed access.) ● Access is generally limited to host systems specified in the list. ● Host systems that use HTTP, such as the embedded Web server or IPP, are not checked against entries in the access list and are allowed access. However, you can disable HTTP host access using the embedded Web server. ● Configured on the HP Jetdirect print server using TFTP (IPv4), Telnet (IPv4), embedded Web server, or SNMP (IPv4) management software. Telnet Control ● Telnet (IPv4) access is not secure. You can disable Telnet using the embedded Web server (see Embedded Web server (V.38.xx) on page 61). Authentication and Encryption Certificate management for X.509v3 digital certificates is provided through the embedded Web server, for both client-based and server-based authentication. A self-signed HP Jetdirect certificate is pre-installed, which can be replaced. On full-featured print servers, a CA certificate can also be installed. IPv4/IPv6 SNMP v1/v2c Set Community Name (IP/IPX) (SNMP v1/v2c only) ● A password on the HP Jetdirect print server that allows incoming SNMP Set commands to write (or set) HP Jetdirect configuration parameters. ● SNMP Set commands must contain the user-assigned community name, which is authenticated by the print server before the command is performed. ● On IP networks, you can restrict authentication of SNMP Set commands to systems on the ACL. ● Configured on the HP Jetdirect print server using TFTP (IPv4), Telnet (IPv4), embedded Web server, or Management application services. ● SNMP v1/v2c uses plain text, which you can disable. IPv4/IPv6 SNMP v3 (For full-featured print servers only) ● SNMP v3 agent on the HP Jetdirect print server provides secure, encrypted communications with an SNMP v3 management application, such as HP Web Jetadmin. ● Supports creation of an SNMP v3 account when it is enabled through the embedded Web server. The account information can be integrated on SNMP v3 management applications. ● Supports seamless SNMP v3 account creation and management from HP Web Jetadmin. HP Web Jetadmin (IPv4) Password and Profiles ● Access control to HP Jetdirect configuration parameters through the HP Jetdirect IP administrator password, which you can configure from HP Web Jetadmin (IPv4), Telnet (IPv4), or the embedded Web server. ● HP Web Jetadmin provides access control through user profiles, which allow password protection for individual profiles and controlled access to HP Jetdirect and printer features. ● (For full-featured print servers only) You can use HP Web Jetadmin to enable the IPv4/IPv6 SNMP v3 agent on the print server, and create an SNMP v3 account for secure, encrypted management. Printer Control Panel Lock 114 Chapter 6 Security features (V.38.xx) ENWW

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202

IPv4 Access Control List
NOTE:
The
Firewall
feature provides improved security and can be used in place of the IPv4 ACL.
Specify up to 10 IPv4 host systems, or IPv4 networks of host systems, that are allowed access to the HP Jetdirect print
server and the attached network device. (If the list is empty, then all hosts are allowed access.)
Access is generally limited to host systems specified in the list.
Host systems that use HTTP, such as the embedded Web server or IPP, are not checked against entries in the access
list and are allowed access. However, you can disable HTTP host access using the embedded Web server.
Configured on the HP Jetdirect print server using TFTP (IPv4), Telnet (IPv4), embedded Web server, or SNMP (IPv4)
management software.
Telnet Control
Telnet (IPv4) access is not secure. You can disable Telnet using the embedded Web server (see
Embedded Web server
(V.38.xx)
on page
61
).
Authentication and Encryption
Certificate management for X.509v3 digital certificates is provided through the embedded Web server, for both client-based
and server-based authentication. A self-signed HP Jetdirect certificate is pre-installed, which can be replaced. On full-featured
print servers, a CA certificate can also be installed.
IPv4/IPv6 SNMP v1/v2c Set Community Name (IP/IPX)
(SNMP v1/v2c only)
A password on the HP Jetdirect print server that allows incoming SNMP Set commands to write (or set) HP Jetdirect
configuration parameters.
SNMP Set commands must contain the user-assigned community name, which is authenticated by the print server before
the command is performed.
On IP networks, you can restrict authentication of SNMP Set commands to systems on the ACL.
Configured on the HP Jetdirect print server using TFTP (IPv4), Telnet (IPv4), embedded Web server, or Management
application services.
SNMP v1/v2c uses plain text, which you can disable.
IPv4/IPv6 SNMP v3
(For full-featured print servers only)
SNMP v3 agent on the HP Jetdirect print server provides secure, encrypted communications with an SNMP v3
management application, such as HP Web Jetadmin.
Supports creation of an SNMP v3 account when it is enabled through the embedded Web server. The account information
can be integrated on SNMP v3 management applications.
Supports seamless SNMP v3 account creation and management from HP Web Jetadmin.
HP Web Jetadmin (IPv4) Password and Profiles
Access control to HP Jetdirect configuration parameters through the HP Jetdirect IP administrator password, which you
can configure from HP Web Jetadmin (IPv4), Telnet (IPv4), or the embedded Web server.
HP Web Jetadmin provides access control through user profiles, which allow password protection for individual profiles
and controlled access to HP Jetdirect and printer features.
(For full-featured print servers only) You can use HP Web Jetadmin to enable the IPv4/IPv6 SNMP v3 agent on the print
server, and create an SNMP v3 account for secure, encrypted management.
Printer Control Panel Lock
Table 6-1
Summary of HP Jetdirect security features (continued)
114
Chapter 6
Security features (V.38.xx)
ENWW