HP 635n HP Jetdirect Print Server Administrator's Guide (Firmware V.36) - Page 110

Default Rule Example, IPsec Security Associations (SA

Page 110 highlights

Table 5-1 IPsec/Firewall Policy page (continued) Item Description Add Rules Delete Rules The rules are configured through an IPsec wizard, which is run when you press Add Rules. To remove one or more rule from the policy, click Delete Rules. Advanced This button allows configuration of a Failsafe feature to prevent being locked out of the print server over HTTPS (secure Web browser access) during IPsec/Firewall policy set up. In addition, you can allow selected multicast and broadcast traffic to bypass your IPsec/ Firewall policy. This may be important, for example, for device discovery by system installation utilities. Default Rule Example The following example illustrates the print server behavior depending on whether the default rule is set to Allow or Drop (default). IPsec Policy Configuration Example: IPsec is enabled on the print server with the following rule: ● All IPv4 Addresses ● All Jetdirect Print Services ● A simple IPsec template for these addresses and services has been configured. If the Default Rule is set to Allow, then: ● An IP packet that is not IPsec-protected, but with an IPv4 address directed to printing port 9100 would not be processed (dropped) because it violates the configured rule. ● An IP packet that is not IPsec-protected, but with an IPv4 address to a service port other than port 9100 (such as Telnet), would be allowed and processed. If the Default Rule is set to Drop, then: ● An IP packet that is not IPsec-protected, but with an IPv4 address directed to printing port 9100 would not be processed (dropped) because it violates the configured rule. ● An IPsec packet with IPv4 address directed to printing port 9100 would be allowed and processed because it matches the rule. ● A non-IPsec packet with IPv4 address to the Telnet port would be dropped because it violates the default rule. IPsec Security Associations (SA) If a packet is IPsec-protected, there must be an IPsec Security Association (SA) for it. A Security Association defines how an IP packet from one host to another is IPsec-protected. Among many things, it defines the IPsec protocol to use, the authentication and encryption keys, and duration of key use. An IPsec SA is unidirectional; a host may have an inbound SA and an outbound SA associated with particular IP packet protocols and services, and the IPsec protocol used to protect them. When properly configured, the IPsec rules define the Security Associations for IP traffic to and from the Jetdirect print server and can ensure all traffic is secure. 100 Chapter 5 IPsec/Firewall Configuration (V.36.xx) ENWW

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202

Item
Description
Add Rules
Delete Rules
The rules are configured through an IPsec wizard, which is run when you press
Add
Rules
.
To remove one or more rule from the policy, click
Delete Rules
.
Advanced
This button allows configuration of a
Failsafe
feature to prevent being locked out of the
print server over HTTPS (secure Web browser access) during IPsec/Firewall policy set
up.
In addition, you can allow selected multicast and broadcast traffic to bypass your IPsec/
Firewall policy. This may be important, for example, for device discovery by system
installation utilities.
Default Rule Example
The following example illustrates the print server behavior depending on whether the default rule is set
to
Allow
or
Drop
(default).
IPsec Policy Configuration Example
: IPsec is enabled on the print server with the following rule:
All IPv4 Addresses
All Jetdirect Print Services
A simple IPsec template for these addresses and services has been configured.
If the
Default Rule
is set to
Allow
, then:
An IP packet that is not IPsec-protected, but with an IPv4 address directed to printing port 9100 would
not
be processed
(dropped) because it violates the configured rule.
An IP packet that is not IPsec-protected, but with an IPv4 address to a service port other than port 9100 (such as Telnet),
would be allowed and processed.
If the
Default Rule
is set to
Drop
, then:
An IP packet that is not IPsec-protected, but with an IPv4 address directed to printing port 9100 would
not
be processed
(dropped) because it violates the configured rule.
An IPsec packet with IPv4 address directed to printing port 9100 would be allowed and processed because it matches the
rule.
A non-IPsec packet with IPv4 address to the Telnet port would be dropped because it violates the default rule.
IPsec Security Associations (SA)
If a packet is IPsec-protected, there must be an IPsec Security Association (SA) for it. A Security
Association defines how an IP packet from one host to another is IPsec-protected. Among many things,
it defines the IPsec protocol to use, the authentication and encryption keys, and duration of key use.
An IPsec SA is unidirectional; a host may have an inbound SA and an outbound SA associated with
particular IP packet protocols and services, and the IPsec protocol used to protect them.
When properly configured, the IPsec rules define the Security Associations for IP traffic to and from the
Jetdirect print server and can ensure all traffic is secure.
Table 5-1
IPsec/Firewall Policy page (continued)
100
Chapter 5
IPsec/Firewall Configuration (V.36.xx)
ENWW