HP J2550B Čistý list

Procházejte online nebo si stáhněte Čistý list pro Tiskové servery HP J2550B. HP J2550B White Paper Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 33
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 0
HP Jetdirect Security Guidelines
white
p
a
p
er
Table of Contents:
Introduction ..................................................................................................................................... 1
HP Jetdirect Overview ...................................................................................................................... 2
What is an HP Jetdirect?................................................................................................................... 3
How old is Your HP Jetdirect?............................................................................................................ 4
Upgrading ...................................................................................................................................... 5
HP Jetdirect Administrative Guidelines ................................................................................................ 6
HP Jetdirect Hacks: TCP Port 9100..................................................................................................... 7
HP Jetdirect Hacks: Password and SNMP Community Names................................................................ 9
HP Jetdirect Hacks: Firmware Upgrade............................................................................................... 9
HP Jetdirect Hacks: Sniffing Print Jobs and Replaying Them................................................................. 10
HP Jetdirect Hacks: Printer/MFP access ............................................................................................ 10
Recommended Security Deployments: SET 1...................................................................................... 11
Recommended Security Deployments: SET 2...................................................................................... 12
Recommended Security Deployments: SET 3...................................................................................... 18
Recommended Security Deployments: SET 4...................................................................................... 28
Further Reading ............................................................................................................................. 33
Introduction
The availability of public information on the Internet for hacking HP Jetdirect products has prompted
customers to ask HP about how they can protect their printing and imaging devices against such
attacks and what is HP doing about preventing those attacks. In all fairness, some of this public
information is of rather poor quality and inflammatory; however, some websites detailing the attacks
and the vulnerabilities on HP Jetdirect are informative and raise valid concerns that need to be
addressed. It is the purpose of this whitepaper to address customer concerns about these attacks and
vulnerabilities and to recommend proper security configurations to help customers protect their
printing and imaging devices. This whitepaper is only a small part of a broad initiative within HP to
educate our customer base about printing and imaging security. Resources such as The Secure
Printing website (http://www.hp.com/go/secureprinting
) provide a great deal of information for
customers about products, solutions, as well as configuration recommendations. In general, a lot of
this information can be put to use on existing HP Jetdirect products, mainly because HP Jetdirect was
1
Zobrazit stránku 0
1 2 3 4 5 6 ... 32 33

Shrnutí obsahu

Strany 1 - white

HP Jetdirect Security Guidelines whitepaper Table of Contents: Introduction ...

Strany 2 - HP Jetdirect Overview

10 firmware upgrades; if telnet has been disabled to avoid plain-text transmission of the password, FTP upgrades are also disabled. The ability to u

Strany 3 - What is an HP Jetdirect?

11 Recommended Security Deployments: SET 1 The HP Jetdirect products denoted by SET 1 do not have any cryptographic security capability. As a result,

Strany 4

The TFTP configuration file points to a parameter file called “pjlprotection”. This file is sent to the printer on power-up. Here is a sample conten

Strany 5 - Upgrading

First and foremost, set a password. 13

Strany 6

Change the Encryption Strength to “Medium” and check the “Encrypt All Web Communication” checkbox. This checkbox forces HTTPS to be used for all we

Strany 7

Uncheck “Enable SNMPv1/v2” and check Enable “SNMPv3”. Provide SNMPv3 parameters. 15

Strany 8

Based upon the customer’s environment, read only SNMPv1/v2c access may need to be granted. Some tools such as the HP Standard Port Monitor use SNMPv

Strany 9

Disable unused print protocols and services. Allowing device discovery helps in device management, but may not be required in all environments. 8

Strany 10

Configuration Review Configuration review. Click “Finish” to set the configuration. Recommended Security Deployments: SET 3 First and foremost

Strany 11

Be sure that you are using HTTPS before navigating to this page. Select the drop down box for the Default Rule to be “Allow” and then click “Add Rule

Strany 12

one of the first print servers to widely implement security protocols such as SSL/TLS, SNMPv3, 802.1X, and IPsec. If you are new to security and se

Strany 13 - First and

We’ll define the IPv4 address range first. Select “All IPv4 Addresses” for Local Address and then we specified the 192.168.0/24 subnet for the Remote

Strany 14

Select the appropriate IPv6 addresses and name the address template. Now that we have the address templates, let’s create a rule. Rules a

Strany 15

We are concerned with management services, so select the service template “All Jetdirect Management Services”. Click “Next”. Select “Allow Traf

Strany 16

Select “Create another rule”. Select the IPv6 address template you created and then click “Next”. 23

Strany 17

Select the “All Jetdirect Management Services” service template. Click “Next”. Select “Allow Traffic”. Click Next. 24

Strany 18

We have allowed management traffic from our IPv4/IPv6 administrative subnet. Now we must create a rule to throw away all other management traffic.

Strany 19

Again, select “All Jetdirect Management Services” for the service template and then click “Next”. Select “Drop”. Click “Next”.

Strany 20

We can now see our policy. Rules are processed from 1 to 10. If a packet comes from or is going to our defined IPv4/IPv6 subnet, the rule will mat

Strany 21

Recommended Security Deployments: SET 4 First and foremost, SET 4 configuration needs to have the Security Wizard for SET 2 executed. Once the Secur

Strany 22

29 ll Click “Next”. Select “AJetdirect Management Services”. Select “Requtraffic to be protan IPsec/Firewall Policy”. Cire ected with lick “

Strany 23

What is an HP Jetdirect? When printers were directly connected to network spoolers, often a simple hardware protocol was used to send data from the P

Strany 24

30 Click “New”. Name the IPTemplate. Some Jetdirecmodels may require you to configure IKE parameters. However, thismodel has a quick set of IK

Strany 25

31 n P d r Click “Next”. For example purposes only, Pre-Shared Key Authenticatiois used. Hdoes not recommenusing Pre-Shared Key Authentication.C

Strany 26

32 f c is default rule. Click “Finish”. Here is our IPsec policy. Ia management protocol is to be used, it must use IPsec. All other traffi

Strany 27

33 Further Reading 802.1X: http://h20000.www2.hp.com/bc/docs/support/SupportManual/c00731218/c00731218.pdf IPsec: http://h20000.www2.hp.com/bc/docs/s

Strany 28

4 How old is Your HP Jetdirect? Once in a while, when doing an inventory of a network, an administrator may discover some network connected devices t

Strany 29

5 Upgrading Upgrading your HP Jetdirect devices is by no means a requirement, but is highly recommended. Should a customer choose to do so, HP can p

Strany 30

6 As you can see, replacing a discontinued 400n MIO model with a new external parallel port print server like the 300X will not upgrade the security

Strany 31

7 • A guideline to popular HP Jetdirect devices and the firmware they should be running as of August of 2007 is shown in Table 4: HP Jetdirect Prod

Strany 32

8 Which hosts need to print? Options Only computers on the same subnet as HP Jetdirect Option 1) For SET 1/2/3/4. Eliminate the default gateway (se

Strany 33 - Further Reading

9 they are trusted to establish a print connection, they are trusted to print. Some additional protections can be provided, in the form of Color Acce

Komentáře k této Příručce

Žádné komentáře