How to Secure Network Printers?



Similar documents
technical brief browsing to an installation of HP Web Jetadmin. Internal Access HTTP Port Access List User Profiles HTTP Port

HREP Series DVR DDNS Configuration Application Note

This document explains how to use your Web Browser to configure the 100BaseT Print Server models

This document explains how to use your Web Browser to configure the 100BaseT IOPRINT+ Print Server models. Connecting to the IOPRINT+ Print Server

SX-3000EDM Integration Guide

Print Servers. HP JetDirect. HP JetDirect Print Servers. 600N/400N/500X/300X Administrator's Guide

Before deploying SiteAudit it is recommended to review the information below. This will ensure efficient installation and operation of SiteAudit.

TDP43ME NetPS. Network Printer Server. Control Center. for Ethernet Module

Operating Instructions Software Guide

BIT COMMANDER. Serial RS232 / RS485 to Ethernet Converter

AP6511 First Time Configuration Procedure

APC by Schneider Electric Release Notes AP9537 Network Management Card. APC part number: Released: 26 October 2012

Two kinds of size notation are employed in this manual. With this machine refer to the metric version.

Configuring System Message Logging

Network Guide. Using a Printer Server Monitoring and Configuring the Printer Special Operations under Windows Appendix

XPrint UNIX System Printer Driver Installation SOLARIS 1.X (SUN OS) / SOLARIS 2.X

F-SECURE MESSAGING SECURITY GATEWAY

Print Audit Facilities Manager Technical Overview

KYOCERA COMMAND CENTER. Operation Guide

How To Manage A Printer On Windows (Windows 7) (Windows 8) (Powerbook) (For Windows 7) And Windows 7 (Windows) (Netware) (Amd64) (Operations) (A

Chapter 3 Management. Remote Management

Chapter 4 Management. Viewing the Activity Log

PREFACE iss.01 -

Follow these steps to prepare the module and evaluation board for testing.

enetworks TM Using the Syslog Feature C.1 Configuring the Syslog Feature

TABLE OF CONTENTS COPYRIGHT INTRODUCTION...4 PRODUCT OVERVIEW...4 COMPONENTS AND FEATURES...4 HARDWARE INSTALLATION...

HP LaserJet 4345 MFP Security Checklist 3/29/2006

CYAN SECURE WEB APPLIANCE. User interface manual

L2/L3 Switches. System. Configuration Guide

Administrator's Guide

Enabling Remote Access to the ACE

TCP/IP Network Connectivity and ION Meters

NETWORK SETUP INSTRUCTIONS

bizhub C3850/C3350 USER S GUIDE Applied Functions

IP Power Stone 4000 User Manual

INTELLIscribe Installation and Setup for Windows 2000, XP, Server 2003, and Vista

It should be noted that the installer will delete any existing partitions on your disk in order to install the software required to use BLËSK.

ReadyNAS Remote Troubleshooting Guide NETGEAR

ETHERNET USER GUIDE DTC1000-DTC4000-DTC4500

Internet Access to a DVR365

Setting Up Scan to SMB on TaskALFA series MFP s.

Configuring a Backup Path Test Using Network Monitoring

RUNNING A HELPDESK CONTENTS. using HP Web Jetadmin

Ithaca itherm, POSjet & BANKjet Printers Ethernet Adapters Setup Guide

Configuration Guide. How to Configure SSL VPN Features in DSR Series. Overview

3.5 Mobile LAN Disk. User Guide

Configuring Class Maps and Policy Maps

Ethernet Interface Manual Thermal / Label Printer. Rev Metapace T-1. Metapace T-2 Metapace L-1 Metapace L-2

NAM CLI Commands: - logout

Chapter 1 Configuring Internet Connectivity

LevelOne WAP User s Manual. 108 Mbps Wireless Access Point

HP Printing Security Best Practices for HP LaserJet Enterprise Printers and HP Web Jetadmin

Setup Manual and Programming Reference. RGA Ethernet Adapter. Stanford Research Systems. Revision 1.05 (11/2010)

Network Interface Table of Contents

DN USB 2.0 Hi-Speed Ports/MFP Server User`s Manual. Version 1.17

Chapter 8 Router and Network Management

QNAP SYSTEMS INC. QNAP Digital Signage Player Web Console Manual

NETWORK SETUP GLOSSARY

Print Server User s Manual Version: 2.0 (January, 2006)

Securely manage data center and network equipment from anywhere in the world.

Chapter 8 How to Configure TCP/IP Printing for Unix

CentreWare Internet Services Setup and User Guide. Version 2.0

DSL-G604T Install Guides

VMware vcenter Log Insight Getting Started Guide

Unified Access Point Administrator's Guide

How To Configure A Network Monitor Probe On A Network Wire On A Microsoft Ipv6 (Networking) Device (Netware) On A Pc Or Ipv4 (Network) On An Ipv2 (Netnet) Or Ip

Chapter 1 Configuring Basic Connectivity

This document explains how to configure and use the IOPRINT+ Print Server in the Unix TCP/IP environment.

Table Of Contents. 2. Index iii

NNAS-D5 Quick Installation Guide

Print Server. Quick Installation Guide

DMH remote access. Table of Contents. Project : remote_access_dmh Date: 29/05/12 pg. 1

Half Bridge mode }These options are all found under Misc Configuration

System Administration Guide Xerox WorkCentre 4250/4260 Series

Chapter 6 Configuring the SSL VPN Tunnel Client and Port Forwarding

Manual. IP Sensor and Watchdog IPSW2210. I P S W M a n u a l P a g e 1. Relay Output. Power input. 12VDC adapter LED Indicators. 2 Dry.

I N S T A L L A T I O N M A N U A L

Protecting the Home Network (Firewall)

WorkCentre System Administrator Guide Guide de l administrateur système Español Português. Xerox WorkCentre 7120 Multifunction Printer

VELOCITY. Quick Start Guide. Citrix XenServer Hypervisor. Server Mode (Single-Interface Deployment) Before You Begin SUMMARY OF TASKS

TotalCloud Phone System

Legal Notes. Regarding Trademarks KYOCERA Document Solutions Inc.

Network Load Balancing

3.1 RS-232/422/485 Pinout:PORT1-4(RJ-45) RJ-45 RS-232 RS-422 RS-485 PIN1 TXD PIN2 RXD PIN3 GND PIN4 PIN5 T PIN6 T PIN7 R+ PIN8 R-

PePWave Surf Series PePWave Surf Indoor Series: Surf 200, AP 200, AP 400

PrintFleet Enterprise Security Overview

6.0. Getting Started Guide

PRINT FLEET MANAGER USER MANUAL

Common Services Platform Collector 2.5 Quick Start Guide

NETWORK PRINT MONITOR User Guide

Tool for Automated Provisioning System (TAPS) Version 1.2 (1027)

To configure TCP/IP parameters from the control panel, use the following instructions:

Network Guide. Windows Configuration Using a Printer Server Monitoring and Configuring the Printer Appendix

Command Line Interface User s Guide

PRILINK PRI Management System

LifeSize ClearSea Administrator Guide

Prestige 310. Cable/xDSL Modem Sharing Router. User's Guide Supplement

Management, Logging and Troubleshooting

Configuring RADIUS Server Support for Switch Services

3.5 EXTERNAL NETWORK HDD. User s Manual

Transcription:

How to Secure Network Printers? IT Security Office June 7, 2006

Agenda Printer History & Statistics The problem with Network Printers Tools for managing network printers How to secure your printers What can the Security Office do to help you secure your printers? Questions?

Printer History & Statistics What are printers suppose to do? Dumb printers Serial/Parallel Printer Locally attached printers Local printer sharing Printer Programming Languages (PostScript, Printer Command Line and Printer Job Language)

Printer History & Statistics Network Printers Printing through Print Servers Direct Printing Network Printers @ UI 1484 Network Printers 1184 HP Printers 71 low toner cartridge 20 order new cartridge 10 empty tray 3 paper jams Longest Uptime: 285 days, 06:46:36.60 112 printers with ACLs 33 printers with syslog servers

The Problem with Network Printers Physical Security Embedded Devices Unauthenticated Remote Access Print Job Forwarding Print Job Notification & Printer Logs RAM Disks and Filesystems

Tools for managing Network Printers Front Panel Web browser CLI SNMP HP Jet Direct HP Web Admin HP DownLoad Manager

How to Secure your printers HPs Recommendation for securing network printers http://h20000.www2.hp.com/bizsupport/techsupport/document.jsp?objectid=bpj05999 Security Step 1 - Upgrade the HP Jetdirect firmware Security Step 2 - Specify a telnet password Security Step 3 - Disable all unused protocols Security Step 4 - Disable all unused print and management services Security Step 5 - Specify an SNMP set community name Security Step 6 - Specify an access control list

How to Secure your printers Obtain information about your printer >telnet 128.255.x.x or http://128.255.x.x HP JetDirect Please type "?" for HELP, or "/" for current settings > ===JetDirect Telnet Configuration=== Firmware Rev. : G.08.49 MAC Address : 00:10:83:xx:xx:xx Config By : USER SPECIFIED IP Address : 128.255.x.x Subnet Mask : 255.255.255.0 Default Gateway : 128.255.x.x Syslog Server : Not Specified Idle Timeout : 90 Seconds Set Cmnty Name : public Host Name : Printer1 Default Get Cmnty : Enabled DHCP Config : Disabled Passwd : Disabled IPX/SPX : Enabled DLC/LLC : Enabled Ethertalk : Enabled Banner page : Enabled

How to Secure your printers Set a password >passwd Enter Password [16 character max.; 0 to disable]: > Set a static IP address >dhcp-config: 0 >ip: 128.255.x.x >subnet-mask: 255.255.255.0 >default-gw: 128.255.x.x Set hostname >host-name: PRINTER1

How to Secure your printers Disable unused protocols IPX, DLC/LLC, LPR, AppleTalk, JetDirect, etc. >ipp-printing: 0 to disable, 1 to enable (TCP port 631) >ftp-printing: 0 to disable, 1 to enable (TCP port 20, 21) >ftp-config: 0 to disable, 1 to enable (TCP port 20, 21) >lpd-printing: 0 to disable, 1 to enable (TCP port 515) >9100-printing: 0 to disable, 1 to enable (TCP port 9100) >slp-config: 0 to disable, 1 to enable (UDP port 427) >ipx/spx: 0 to disable, 1 to enable >dlc/llc: 0 to disable, 1 to enable >ethertalk: 0 to disable, 1 to enable

How to Secure your printers Disable unused services HTTP management >ews-config:0 to disable, 1 to enable Enable SSL State for Web Management >ssl-state: 1 to enable redirection, 2 to disable redirection

How to Secure your printers Change the default community string >set-cmnty-name: secure-string (32 characters max) >default-get-cmnty: 0 to disable, 1 to enable Disable SNMP >snmp-config: 0 to disable, 1 to enable Note: JetDirect will not respond to any remote access via the network requiring community strings for communication (ex. JetAdmin, WebJet, HP DownLoad Manager)

How to Secure your printers Configure Syslog Enable Syslog Server >syslog-svr: 128.255.x.x Configure Maximum messages per min. >syslog-max: integer 1..1000, 0 to disable Configure Syslog Priority >syslog-priority: integer (0.. 7), 8 to disable

How to Secure your printers Configure Access Control List (ACL) Restricts access to telnet/www/ftp/printing Single host or maskable network range Maximum of 10 ACLs Examples >allow: list (displays current ACLs) >allow: 128.255.1.1 >allow: 128.255.1.0 255.255.255.0 >allow: 0 (clears all ACLs)

How to Secure your printers HP JetDirect Please type "?" for HELP, or "/" for current settings > To Change/Configure Parameters Enter: Parameter-name: value <Carriage Return> Parameter-name Type of value ip: IP-address in dotted notation subnet-mask: address in dotted notation (enter 0 for default) default-gw: address in dotted notation (enter 0 for default) syslog-svr: address in dotted notation (enter 0 for default) idle-timeout: seconds in integers set-cmnty-name: alpha-numeric string (32 chars max) default-get-cmnty: 0 to disable, 1 to enable host-name: alpha-numeric string (upper case only, 32 chars max) dhcp-config: 0 to disable, 1 to enable allow: <ip> [mask] (0 to clear, list to display, 10 max) addrawport: <TCP port num> (<TCP port num> 3000-9000) deleterawport: <TCP port num> listrawport: (No parameter required) addstring: <name> <contents> contents - For non-printable characters use \xx for two digit hex number deletestring: <name> liststring: (No parameter required) addq: <name> [prepend] [append] [processing] prepend - The prepend string name append - The append string name Use NULL for no string processing - RAW, TEXT, or AUTO deleteq: <name> listq: (No parameter required) defaultq: <name> ipx/spx: 0 to disable, 1 to enable dlc/llc: 0 to disable, 1 to enable ethertalk: 0 to disable, 1 to enable banner: 0 to disable, 1 to enable Type passwd to change the password. Type "?" for HELP, "/" for current settings or "quit" to save-and-exit. Or type "exit" to exit without saving configuration parameter entries >

What can the Security Office do to help you secure your printers? Scan for printers in your domain Test the security of the printers Help with ACL configuration

Questions?

Thank You!