background image

 

 

5

external users (specified by subnet mask) is dropped and so that following ports for web services are closed: tcp ports 53202, 
53303, 53404 and tcp/udp port 3702. 

IP  Filtering  is  not  available  for  either  the  AppleTalk  protocol  or  the  Novell  protocol  with  the  ‘IPX’  filing  transport.  Also,  IP 
Filtering will not work if IPv6 is used instead of IPv4.

 

x).

 

To enable disk encryption follow the instructions under “Enabling Encryption of Stored Data” on page 78 of the SAG. 

Before enabling  disk  encryption the  System Administrator should make sure that the  machine is not in diagnostics mode 
and that there are no active or pending scan jobs. 

y).

 

The System Administrator should ensure that the Embedded Fax Card and fax software is properly installed.  The System 
Administrator can then set Embedded Fax parameters and options via the Local User Interface on the machine by following 
the instructions on pages 152 through 160 in the SAG. 

z).

 

To  enable  and  configure  IPSec,  follow  the  instructions  starting  on  page  83  of  the  SAG.  IPSec  should  be  used  to  secure 
printing jobs; HTTPS (SSL) should be used to secure scanning jobs.   

Use the default values for IPSec parameters listed in the IPSec discussion starting on page 83 in the SAG

 

whenever possible 

for secure IPSec setup.  

aa).

 

To enable the session inactivity timers (termination of an inactive session) from the Web UI follow the instructions on page 
96 of the SAG. 

bb).

 

There is a software verification test feature that checks the integrity of the executable code by comparing a calculated hash 
value against a pre-stored value to ensure the value has not changed. To initiate this feature follow the instructions on page 
105 of the SAG. 

cc).

 

To  enable  the  Scan  to  Mailbox  feature  from  the  Web  UI  follow  the  instructions  under  ‘Enabling  or  Disabling  Scan  to 
Mailbox’ on page 126 of the SAG.  

For the purposes of the evaluation, the Scan to Mailbox feature was set to store scanned documents only in private folders.  

To set the scan policies for the Scan to Mailbox feature follow the instructions under ‘Setting Scan Policies’ starting on page 
126 of the SAG

.

 Public folders are not allowed in the evaluated configuration. The scan policies should therefore be set as 

follows: 

 

Deselect [

Allow Scanning to Default Public Folder

].

 

 

Deselect [

Require per Job password to public folders

].

 

 

Select [

Allow additional folders to be created

 

 

Select [

Require password when creating additional folders

].

 

 

 

 

Select [

Prompt for password when scanning to private folder

]. 

 

 

Deselect [

Allow access to job log data

].  

Passcodes  for  Scan-to-Mailbox  mailboxes  should  be  selected  to  be  as  random  as  possible  and  should  be  changed  on  a 
regular basis, consistent with applicable internal policies and procedures. Xerox recommends that the minimum length of a 
password assigned to a private Scan to Mailbox folder be 8 alphanumeric characters. 

dd).

 

To enable the Print from USB feature from the Web UI follow the instructions on page 119 of the SAG. 

ee).

 

To enable the Print from Mailbox feature from the Web UI follow the instructions on page 120 of the SAG. 

ff).

 

In  the  evaluated  configuration  the  Embedded  Fax  Secure  Receive  option  should  be  enabled

5

  and  the  fax  forwarding  on 

receive feature should be enabled. The Local Polling option and embedded fax mailboxes should not be set up or used at 
any time.  

To enable Secure Receive from the Local UI follow the instructions under ‘Enabling or Disabling the Secure Fax Feature’ on 
page 154 of the SAG. The System Administrator should ensure that the secure receive passcode, which is fixed at 4-digits, is 
changed every three days. 

To enable Fax Forwarding on Receive and establish up to five fax forward rules from the WebUI follow the instructions for 
Fax Forwarding starting on page 158 of the SAG.  

 

The evaluation assumes that after normal business hours Fax Forwarding on Receive is enabled and  secure receive is 
disabled.  

                     

5

 This will apply to any received fax, including faxes that are remotely polled to the device from another remote fax machine or remote device.

  

Summary of Contents for ColorQube 8700

Page 1: ...Version 1 1 Sep 21 2012 Secure Installation and Operation of Your ColorQube 8700 8900 ...

Page 2: ...on page 19 in the System Administration Guide SAG 3 To log in to the Local User Interface Local UI as an authenticated System Administrator follow the System Administrator Access at the Control Panel instructions located on page 18 in the SAG Follow the instructions located in the SAG in Chapter 4 Security to set up these security functions except as noted in the items below Note that whenever the...

Page 3: ...le h In the evaluated configuration only the System Administrator should have the ability to delete a job From the Local UI follow the instructions for Setting Job Deletion Options at the Control Panel on page 198 of the SAG to set job deletion to System Administrator Only From the WebUI set the permission for Delete Jobs under the Job Status Pathway to Not Allowed for all roles defined other than...

Page 4: ...emand Image Overwrite request the confirmation sheet must have printed The Embedded Fax card must have the correct software version and must be properly configured When invoked from the Web UI the status of the completed On Demand Image Overwrite will not appear on the Local UI but can be ascertained from the On Demand Overwrite Confirmation Report that is printed after the Network Controller rebo...

Page 5: ...trator should ensure that SSL is enabled as discussed in Step 3 under Configuring LDAP Server Optional Information on page 47 in the SAG Make sure that Enable SSL under SSL is selected s To be consistent with the evaluated configuration the device should be set for local authorization Remote authorization was not evaluated since that function is performed external to the system Choose the authoriz...

Page 6: ...ore scanned documents only in private folders To set the scan policies for the Scan to Mailbox feature follow the instructions under Setting Scan Policies starting on page 126 of the SAG Public folders are not allowed in the evaluated configuration The scan policies should therefore be set as follows Deselect Allow Scanning to Default Public Folder Deselect Require per Job password to public folde...

Page 7: ...ion mm The following features and protocols are not included in the evaluation Reprint from Saved Job SMart eSolutions Custom Services Extensible Interface Platform or EIP Network Accounting and Auxiliary Access Internet Fax Use of Embedded Fax mailboxes NTP Direct USB Printing AppleTalk and Novell protocols SFTP Web Services 2 The System Administrator should change the SNMPv1 v2c public private c...

Page 8: ...unts to access the device 15 The following windows are available to any authenticated and authorized user from the Local User Interface These windows provide standard machine services or job management capability Embedded Fax Batch Send Confirmation Allows a user to either send an Embedded Fax job to a remote destination immediately or include the job as part of a batch of Embedded Fax jobs sent t...

Page 9: ...typing http IP Address diagnostics hideotherqueuesbutton php Secure Print Alphanumeric PIN Allows the System Administrator to set the secure print PIN to be alphanumeric characters instead of just digits Is accessible by typing either http IP Address diagnostics index dhtml and then selecting Secure Print Alphanumeric PIN from the Diagnostics Content Menu or by typing http IP Address diagnostics s...

Page 10: ...M NTLM versions Is accessible by typing http IP Address diagnostics NTLMSecurity php Custom Size Allowed Allows the System Administrator to allow custom size paper to be used for print jobs Is accessible by typing http IP Address diagnostics customSizeAllowed php Copies Per Page Print Setting Allows the System Administrator to permit the use of the copies per page setting for print jobs Is accessi...

Page 11: ...n general enabling a specialized customer specific feature will take the system out of the evaluated configuration Contact For additional information or clarification on any of the product information given here contact Xerox support Disclaimer The information provided in this Xerox Product Response is provided as is without warranty of any kind Xerox Corporation disclaims all warranties either ex...

Reviews: