HP 630n HP Jetdirect Print Servers - Administrator's Guide - Page 126

Limit access to security features

Page 126 highlights

Limit access to security features You can control access to HP Jetdirect configuration parameters using the available security features. Examples of various settings and associated levels of access control are provided in Table 6-2 Settings for Access Control on page 116. Table 6-2 Settings for Access Control Settings Level of Access Control ● Accessible using HTTP (embedded Web server), SNMP Low v1/v2c applications, or Telnet ● Administrator password not set Best suited for trusted environments. ● Default SNMP v1/v2c community names Any system can access the HP Jetdirect configuration parameters through the embedded Web server, Telnet, or ● No authentication or encryption SNMP management software. Passwords are not required. ● Access control list empty or Firewall disabled. ● Administrator password set Medium ● User-specified SNMP v1/v2 Set Community Name set Limited security for non-trusted environment. ● Access control list contains host entries and checks HTTP connections If the Administrator password and SNMP v1/v2c Set Community Name are known, access is limited to: ● Telnet and other non-secure protocols disabled. ● Systems listed in the access control list ● SNMP v1/v2c management applications ● Unused protocols disabled High ● HTTPS access enabled using certificates issued by trusted sources High security for non-trusted, professionally managed environments. ● Full-featured HP Jetdirect print servers configured for Access is controlled by IPsec. Encryption provides data EAP/802.1X server-based authentication and encryption privacy; network communication in plain text is not used. ● Full-featured HP Jetdirect print servers with SNMP v3 enabled, SNMP v1/v2c disabled ● Telnet disabled ● Passwords set CAUTION: Configuration settings from a BootP/TFTP or DHCP/TFTP server can change when the print server is turned off and then on. Verify any settings that might change when the print server is turned off and then on. ● Access control list contains specified entries and checks HTTP connections ● Printer control panel locked ● IPsec/Firewall policy is enabled and configured 116 Chapter 6 Security features (V.38.xx) ENWW

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202

Limit access to security features
You can control access to HP Jetdirect configuration parameters using the available security features.
Examples of various settings and associated levels of access control are provided in
Table
6
-
2
Settings
for Access Control
on page
116
.
Table 6-2
Settings for Access Control
Settings
Level of Access Control
Accessible using HTTP (embedded Web server), SNMP
v1/v2c applications, or Telnet
Administrator password not set
Default SNMP v1/v2c community names
No authentication or encryption
Access control list empty or Firewall disabled.
Low
Best suited for trusted environments.
Any system can access the HP Jetdirect configuration
parameters through the embedded Web server, Telnet, or
SNMP management software. Passwords are not required.
Administrator password set
User-specified SNMP v1/v2 Set Community Name set
Access control list contains host entries and checks
HTTP connections
Telnet and other non-secure protocols disabled.
Medium
Limited security for non-trusted environment.
If the Administrator password and SNMP v1/v2c Set
Community Name are known, access is limited to:
Systems listed in the access control list
SNMP v1/v2c management applications
Unused protocols disabled
HTTPS access enabled using certificates issued by
trusted sources
Full-featured HP Jetdirect print servers configured for
EAP/802.1X server-based authentication and encryption
Full-featured HP Jetdirect print servers with SNMP v3
enabled, SNMP v1/v2c disabled
Telnet disabled
Passwords set
Access control list contains specified entries and checks
HTTP connections
Printer control panel locked
IPsec/Firewall policy is enabled and configured
High
High security for non-trusted, professionally managed
environments.
Access is controlled by IPsec. Encryption provides data
privacy; network communication in plain text is not used.
CAUTION:
Configuration settings from a BootP/TFTP or
DHCP/TFTP server can change when the print server is turned
off and then on. Verify any settings that might change when
the print server is turned off and then on.
116
Chapter 6
Security features (V.38.xx)
ENWW