
IPsec/Firewall Policy
(Full-featured HP Jetdirect print servers only) The Firewall and Internet Protocol security (IPsec) features provide
network-layer security on both IPv4 and IPv6 networks. The Firewall provides simple control of which IP
addresses are allowed access. IPsec (RFC 2401) provides the additional security benets of authentication and
encryption.
IPsec conguration is relatively complex. However, because IPsec provides security at the network layer and can
be relatively independent of the application layers, the opportunity for secure host-to-host communications
over a widespread network, such as the Internet, is greatly enhanced.
●
If IPsec is supported, you can control IP trac by using both Firewall and IPsec protection.
●
If IPsec is not supported, you can control IP trac by using only Firewall protection.
NOTE: In addition to Firewall and IPsec protection at the network layer, the HP Jetdirect print server also
supports the following:
●
An SNMPv3 agent at the application layer for management application security
●
Open Secure Sockets Layer (SSL) standards at the transport layer for secure client-server applications,
such as client/server authentication or HTTPS Web browsing
For IPsec/Firewall operation on the HP Jetdirect print server, use this option to congure an IPsec/Firewall policy
that is applied to specied IP trac. For more information about conguring IPsec/Firewall policies and the
specic settings, see the HP Jetdirect Print Servers Administrator’s Guide.
NOTE: To ensure communications with an HP Jetdirect print server that is congured with an IPsec policy,
computer systems that communicate with the print server must be properly congured. IPsec policies that are
congured on the print server and computer systems must be compatible. Otherwise, connections fail.
Use the following steps to modify a rule:
1. Select the rule, and then click the Add / Modify Rules button. The IPsec/Firewall Policy wizard starts.
2. On the Specify Address Template page, select the address template.
3. Use the following steps to modify the address template:
a. Click the Modify button.
b. On the Create Address Template window, make the appropriate changes, and then click the OK
button.
4. On the Specify Address Template page, click the Next button.
5. On the Specify Service Template page, select the service template.
6. Use the following steps to modify the service template:
a. Click the Modify button.
b. On the Create Service Template window, click the Manage Services button.
c. On the Manage Services window, make the appropriate changes, and then click the OK button.
d. On the Create Service Template window, click the OK button.
7. On the Specify Service Template page, click the Next button.
8. On the Specify Action page, select the appropriate option, and then click the Next button.
9. If the Require trac to be protected with an IPsec/Firewall policy option is selected, the Specify IPsec/
Firewall Template page appears. Use the following steps to modify the IPsec template:
426 Chapter 6 Device Conguration Options ENWW
Komentarze do niniejszej Instrukcji