Download Print this page
Xerox WorkCentre 3655 Secure Installation And Operation

Xerox WorkCentre 3655 Secure Installation And Operation

Hide thumbs Also See for WorkCentre 3655:

Advertisement

Quick Links

Secure Installation and Operation of Your
WorkCentre™ 3655/3655i
WorkCentre™ 5845/5855/5865/5865i/5875/5875i/5890/5890i
WorkCentre™ 5945/5945i/5955/5955i
WorkCentre™ 6655/6655i
WorkCentre™ 7220/7220i/7225/7225i
WorkCentre™ 7830/7830i/7835/7835i/7845/7845i/7855/7855i
WorkCentre™ 7970/7970i
®
®
2016 Xerox
ConnectKey
Technology
Version 1.0
July 15, 2016

Advertisement

loading

Summary of Contents for Xerox WorkCentre 3655

  • Page 1 Secure Installation and Operation of Your WorkCentre™ 3655/3655i WorkCentre™ 5845/5855/5865/5865i/5875/5875i/5890/5890i WorkCentre™ 5945/5945i/5955/5955i WorkCentre™ 6655/6655i WorkCentre™ 7220/7220i/7225/7225i WorkCentre™ 7830/7830i/7835/7835i/7845/7845i/7855/7855i WorkCentre™ 7970/7970i ® ® 2016 Xerox ConnectKey Technology Version 1.0 July 15, 2016...
  • Page 2 . After careful review of this document, customers should document settings to be applied to devices in their environment establishing a unique benchmark configuration to support processes such as installation, change management and audit. Xerox Professional Services, which can be contacted via http://www.xerox.com/about-xerox/customer-training/tab1-ab-enus.html, can assist in evaluating and configuring these devices.
  • Page 3 Technology System Administrator Guide, Version 1.3, February 2016; Xerox WorkCentre 7220/7220i/7225/7225i Multifunction Printer 2016 Xerox ® ® ® ConnectKey ® Technology System Administrator Guide, Version 1.3, February 2016; Xerox ® WorkCentre ® 7800/7800i Multifunction Printer 2016 Xerox ® ConnectKey ®...
  • Page 4 c. Follow the instructions located in Chapter 4, Security, in the SAG to set up the security functions listed in Item a above. Note that whenever the SAG requires that the System Administrator provide an IPv4 address, IPv6 address or port number the values should be those that pertain to the particular device being configured. In setting up the device to be in the evaluated configuration, perform the following 1.
  • Page 5 (Device Certificate, CA Certificate or Trusted Certificate) the device supports. Note that a Xerox self-signed certificate is installed by default on the device. If a CA certificate is desired a Certificate Signing Request (CSR) will have to be sent to a Certificate Authority to obtain the CA Certificate before it can be installed on the device.
  • Page 6 WorkCentre 7220/7225 or WorkCentre 7830/7835/7845/7855 is not in diagnostics mode and that there are no active or pending scan jobs. 10. IP Filtering: Enable and configure IP Filtering to create IP Filter rules by following the instructions under “IP Filtering” in Section 4 of the SAG. Note that IP Filtering is not available for either the AppleTalk protocol or the Novell protocol with the ‘IPX’...
  • Page 7 Disable McAfee Secure Device ‘Security Level’ option. Xerox ® WorkCentre ® 3655/3655i Multifunction Printer 2016 Xerox ® ConnectKey ® Technology User Guide, Version 1.2, February 2016; Xerox ® WorkCentre ® 5800/5800i Multifunction Printer 2016 Xerox ® ConnectKey ® Technology User Guide, Version 4.0, February 2016; Xerox ®...
  • Page 8 Touch Device Settings > General.  Touch Feature Installation.  Enter the installation key for the Integrity Control option provided by Xerox when the option is purchased in the ‘Enter Feature Installation Key’ text box.  Touch OK. 21. Erase Customer Data: Initiate the feature to erase all customer date from the device at the Control Panel by performing the following: ...
  • Page 9  Ensure that Embedded Fax is properly installed.  Set Embedded Fax parameters and options via the Local User Interface on the machine by following the instructions for “Embedded Fax” in Section 8 of the SAG.  Set the minimum length of the (Embedded Fax) secure receive passcode from the Control Panel by performing the following: ...
  • Page 10  Deselect Allow Scanning to Default Public Folder  Deselect Require per Job password to public folders  Select Allow additional folders to be created  Select Require password when creating additional folders  Select Prompt for password when scanning to private folder ...
  • Page 11 6. Workflow Scanning:  When configuring workflow scanning file repositories (see “Configuring File Repository Settings” under “Workflow Scanning’ in Section 7 of the SAG) or template pool repositories (see “Configuring Template Pool Repository Settings” under “Workflow Scanning’ in Section 7 of the SAG) set the transfer protocol to be either HTTPS or SFTP.
  • Page 12 There are no active processes that access the hard disk drive(s).  No user is logged into a session via network accounting, Xerox Standard Accounting, or the internal auditron, or into a session accessing a directory on the hard disk drive(s).
  • Page 13 13. If Embedded Fax is enabled and then subsequently disabled before there is a power failure or system crash and Embedded Fax is then re-enabled after the device is restored to operational mode, the first ODIO that is subsequently initiated may fail. If that situation occurs, reinitiate the ODIO. Note: When an ODIO fails under this scenario no Fax ODIO report may be printed, the WebUI may indicate that the ODIO was successful, the Confirmation Report may indicate that the ODIO was ‘Not Completed’...
  • Page 14  Once Embedded Device Security is enabled on the device, any attempts to read from read-protected files and directories or to change write-protected files and directories will result in a Security Alert being recorded in the Audit Log. If configured, an email alert will also be sent. h.
  • Page 15 If IPv6 is disabled and then a software upgrade is performed by a Xerox Service Technician using an AltBoot, IPv6 will be disabled even though both the Control Panel and Web UI show that IPv6 is enabled. IPv6 can be enabled again via the Web UI by first disabling and then re-enabling it.
  • Page 16  Application Domain/Content Query - Allows the configuration of the system to perform an LDAP query for the logged-in user’s authentication domain prior to authenticating the server. Is accessible by typing http://{IP /diagnostics/index.dhtml and then selecting ‘Authentication Domain/Context Query’ from the Address} Diagnostics Content Menu or by typing http://{IP Address}/diagnostics/authenticationQuery.php.
  • Page 17  Show Web UI Configuration Page - Allows the System Administrator to enable users who are not authenticated administrators to view the Web UI Configuration Page. Is accessible by typing http://{IP Address}/diagnostics/ShowConfigSheet.php.  NTLM v2 Response - Allows the System Administrator to enable the device to send only the NT Lan Manager (NTLM) Version 2 protocol (and refuse the LM &...
  • Page 18 VII. Customers who required specialized changes to support unique workflows in their environment may request specific changes to normal behavior. Xerox will supply these SPAR releases to the specific customers requesting the change. Please note that in general enabling a specialized customer-specific feature will take the system out of the evaluated...
  • Page 19 For additional information or clarification on any of the product information given here, contact Xerox support. Disclaimer The information provided in this Xerox Product Response is provided "as is" without warranty of any kind. Xerox Corporation disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose.