HP 635n Practical IPsec Deployment for Printing and Imaging Devices - Page 68

Microsoft IPsec Configuration Wizard for Pre-Shared Key

Page 68 highlights

for the configuration to be changed without constantly bringing down the IP stack and bringing it back up. • Always use the failsafe option when testing various IPsec policies to avoid being locked out remotely. Be sure to disable it once everything has be tested and verified to work properly. Okay, we are done covering IPsec policy configuration on Jetdirect for Pre-Shared Key. Configuring one endpoint for IPsec and not the other endpoint isn't exactly useful. What we need to do next is step through a Microsoft configuration. Before doing that, we need to review what we are trying to accomplish. • (1) We want to protect printing, imaging, and management protocols on Jetdirect using IPsec. • (2) We want to protect printing protocols across all desktops and laptops, with an emphasis on ease of management and deployment • (3) We want to protect our specialty servers, such as WJA with IPsec. Using the HP recommended printing and imaging configuration, we have accomplished (1): The Jetdirect recommended configuration - IPsec exemptions followed by IPsec protection of all services. Now we want to focus on (2) - protecting desktop and laptop printing using IPsec policy in a way that is very manageable and scalable. Microsoft IPsec Configuration Wizard for Pre-Shared Key HP Recommend IPsec Policy to Protect Printing for Desktops/Laptops Here we are going to cover an easy to deploy and manage IPsec policy to protect printing on Desktop/Laptops in the enterprise. 68

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193

68
for the configuration to be changed without constantly bringing down the IP stack and
bringing it back up.
Always use the failsafe option when testing various IPsec policies to avoid being locked out
remotely.
Be sure to disable it once everything has be tested and verified to work properly.
Okay, we are done covering IPsec policy configuration on Jetdirect for Pre-Shared Key.
Configuring
one endpoint for IPsec and not the other endpoint isn’t exactly useful.
What we need to do next is
step through a Microsoft configuration.
Before doing that, we need to review what we are trying to accomplish.
(1) We want to protect printing, imaging, and management protocols on Jetdirect using
IPsec.
(2) We want to protect printing protocols across all desktops and laptops, with an emphasis
on ease of management and deployment
(3) We want to protect our specialty servers, such as WJA with IPsec.
Using the HP recommended printing and imaging configuration, we have accomplished (1):
The Jetdirect
recommended
configuration –
IPsec
exemptions
followed by
IPsec
protection of
all services.
Now we want to focus on (2) – protecting desktop and laptop printing using IPsec policy in a way
that is very manageable and scalable.
Microsoft IPsec Configuration Wizard for Pre-Shared Key
HP Recommend IPsec Policy to Protect Printing for Desktops/Laptops
Here we are going to cover an easy to deploy and manage IPsec policy to protect printing on
Desktop/Laptops in the enterprise.