background image

Xerox

® 

VersaLink

® 

C405/B405 Multifunction Printer 

Security Function Supplementary Guide 

 

6

 

 

If you have such inquiries as the following, please contact us (www.xerox.com/support): 

-

 

Inquiries about the machine's functions 

-

 

All other inquiries. 

 

You can check whether your model has the security functions by checking whether icons for the functions appear 

on the control panel or by checking Configuration Report. 

 

You can identify the product codes for the models in the List of Product Codes in "Appendix". 

 
Security Features 

 

The machine has the following security features: 

 

Flash Memory Encryption 

 

User Authentication 

 

System Administrator’s Security Management 

 

Customer Engineer Operation Restriction 

 

Security Audit Log 

 

Internal Network data protection 

 

Self Test 

 

Fax Flow Security 

 

Settings for the Secure Operation 

 

For the effective use of the security features, the System Administrator (Machine Administrator) 

must configure settings by referring to the following sections. 

 

Settings for the Secure Operation (Initial Settings Procedures Using Embedded Web Server)  

 

Settings for the Secure Operation (Initial Settings Procedures Using Control Panel)  

 

Regular Review by Audit Log 

 

Self Testing  

 

Authentication for the secure operation 

 

Operation using Control Panel 

 

Operation using Embedded Web Server 

 
 

 

Summary of Contents for VersaLink C405

Page 1: ...Xerox VersaLink C405 B405 Multifunction Printer Security Function Supplementary Guide Document Version 1 0 March 2018...

Page 2: ...e Configuration Report 10 Check the System Clock 11 Initial Settings ProceduresUsing Embedded Web Server 12 Preparationsfor Settings on the Embedded Web Server 12 Change the System Administrator s Pas...

Page 3: ...ar Review by Audit Log 25 Import the Audit Log File 25 Self Testing 27 Authenticationfor the secure operation 28 Users Controlled by Authentication 28 Roles 28 Login Method 29 FunctionsControlledby Ac...

Page 4: ...Xerox VersaLink C405 B405Multifunction Printer Security Function Supplementary Guide 4 Problem Solving 38 Fault ClearanceProcedure 38 Fault Codes 39 Security Xerox 47 Appendix 48...

Page 5: ...ity common criteria certified enus html andJISEC http www ipa go jp security jisec jisec_e website Pleasecheckthatthehashvaluesofyourmanualsarecorrect TheManualversionmightbechangedwhenthemanualconten...

Page 6: ...curity features FlashMemoryEncryption User Authentication System Administrator sSecurityManagement Customer EngineerOperationRestriction Security Audit Log InternalNetwork data protection SelfTest Fax...

Page 7: ...for Basic user Restricted Maximum Login Attempts 5 User Password Minimum Length 9 TLS Enabled Certificate Validation Google Cloud Print Disabled Bonjour IPP Enabled SOAP Disabled SNMP SMB WSD Scan CSR...

Page 8: ...ceoperationispermittedtoacustomer engineer TheFaxFlowSecurityfeaturerequiresnospecialsettingbytheSystemAdministrator Service Representative Restricted Operation Specifies whether the Service Represent...

Page 9: ...recharacters Setaccountlockoutpolicyto5times Administratorsneedtoremovetheuseraccounts whenusersleavetheirorganization Users and administratorsneed to manageandoperate the machine so that their user I...

Page 10: ...nicatedirectlywithoutproxyserver NTP server connection is outsidethescopeofevaluation Confirm the Machine ROM Version and the System Clock Before making initial settings the System Administrator needs...

Page 11: ...n Report shows SSD Total Size in Device Configuration section Check the System Clock 1 Select General On the Device screen Check the time and the date of the system clock If you need to change the tim...

Page 12: ...r enter the TCP IP address of the machine to the URL bar and press the Enter key 2 Select Log In on the Embedded Web Server 3 Select admin 4 Enter the password 5 Select Log In Change the System Admini...

Page 13: ...re below to delete GoogleDrive application 1 Select Apps 2 Select Print and Scan for GoogleDrive 3 Select Delete App 4 Select Delete Set OneDrive For the secure operation of the machine follow the pro...

Page 14: ...ation settings 1 Select Permissions 2 Select Login Logout Settings Configure the Local Authentication or Network Authentication Settings in the following procedures To use Local Authentication 3 Selec...

Page 15: ...lect Edit for Guest Access 14 Select Printing User Role 15 Select Custom Permissions for Printing Permissions 16 Disable all services for Allowed Job Types 17 Select OK 18 On the Permission screen sel...

Page 16: ...to specify maximum login attempts 1 Select Permissions 2 Select Login Logout Settings 3 Select Edit for Advanced Settings 4 Select Limit Login Attempts of System Administrator 5 Enable Limit Login At...

Page 17: ...lect Security 3 Select Security Certificates 4 Select Import 5 Select Select 6 Select a certificate 7 Enter Password and enter Retype Password if necessary 8 Select Import 9 Select Close Set Certifica...

Page 18: ...rt 4 Select OK 5 Select Restart Later if prompted Set SOAP For the secure operation of the machine follow the procedure below to set SOAP to Disabled 1 Select Connectivity 2 Select SOAP 3 Disable Port...

Page 19: ...lect HTTP 3 Enable CSRF Protection 4 Select OK 5 Select Restart Later if prompted Set LDAP Server Configure the LDAP server settings for directory service 1 Select Connectivity 2 Select LDAP 3 Select...

Page 20: ...ou need to import an S MIME certificate according to the same procedure as Import Machine Certificates To use E mail with this machine the E mail function needs to be enabled and configured 1 Select C...

Page 21: ...service 5 Set a passcode 6 Select OK 7 Select Restart Now if prompted Set Service Representative Restricted Operation Follow the procedure below to restrict the operation of service representatives 1...

Page 22: ...ettings 1 Select System 2 Select Defaults and Policies 3 Select Allowed Print Job Types for Printer Settings 4 Select Personal Secure and Saved Only 5 Select OK 6 Select Restart Later if prompted 7 Se...

Page 23: ...Sec 4 Select Preshared Key or Digital Signature for IKE Authentication Method 5 When you select Preshared Key enter a preshared key of 9 or more characters in Preshared Key and Retype Preshared Key Wh...

Page 24: ...panel Login as System Administrator Before configuring settings auser must be authenticated with an administrator s ID and a password 1 Select Log In on the control panel 2 Select admin 3 Enter the p...

Page 25: ...ime stamps into the internal storage device Up to 15 000 events can be stored When the number of recorded events exceeds 15 000 the oldest audit log file is overwritten and a new audit event is stored...

Page 26: ...following audit log is recorded when someone tried to login under ID User1 and the login failed due to an invalid password Item Description Log ID 1 Date 01 01 2018 Time 10 00 00 Logged Events Login...

Page 27: ...es the area of NVRAM and SEEPROM including setting data at initiation and displays an error on the control panel at error occurrence However an error is not detected for the data on audit logs and tim...

Page 28: ...that are restricted To enter the system administration mode enter the Machine Administrator ID into the user ID entry field on the authentication screen Authenticated Users with System Administrator...

Page 29: ...he user information that is registered on the machine to manage authentication Remote Authentication Login to Network Accounts Remote authentication uses a network authentication server LDAP or Kerber...

Page 30: ...t Scan Copy Device Email Fax IDCardCopy Jobs MyFolder RemoteScanning ScanTo ScantoDesktop USB Remote Access Device Website Permissions Operation of the machine through a network using Embedded Web Ser...

Page 31: ...ingtothesettingsdescribedpreviously ThemachinehasasingleSecureFaxReceivefoldertoholdreceivedfaxjobs Maximum Login Attempts by System Administrator This feature protects the settings from being changed...

Page 32: ...vailable NOTE WhenusingLocalAuthentication onlytheSystemAdministrator sIDispre registeredonthemachine Otheruser IDsarenotregistered FordetailsonhowtoregisterUserIDs refertothe OperationUsingEmbeddedWe...

Page 33: ...Jobs 4 Select Secure Fax Receive folder 5 Select a job to be printed or Print All NOTE ThemachinehasasingleSecureFaxReceivefoldertoholdreceivedfaxjobs OnlySystemAdministratorscanprintasecurefaxreceive...

Page 34: ...dministrator for further assistance Accessing Embedded Web Server Follow the steps below to access Embedded Web Server On a client computer on the network launch an internet browser In the URL field e...

Page 35: ...elect the user account from the list or enter the user name 3 Enter the password 4 Select Log In NOTE EntertheusernamefortheNetworkauthentication FortheLocalauthentication theuseridentificationvaries...

Page 36: ...tication to change the registered password This feature is only applicable to Local Authentication mode 1 Select the user icon on upper right corner on the Embedded Web Server 2 Select My Profile 3 Se...

Page 37: ...Xerox VersaLink C405 B405Multifunction Printer Security Function Supplementary Guide 37 4 Select Delete NOTE Only System Administrators are allowed this operation...

Page 38: ...identified specify the probable cause and then apply the appropriate solution Ifafaultoccurs firstrefertothescreenmessagestoclearthefaultaccordingtothespecifiedorder Alsorefertothefaultcodesdisplayedo...

Page 39: ...n themachinepower If theerror still is not resolved contact our CustomerSupport Center 016 402 Cause The authenticationconnectiontimed out Remedy Confirmthenetwork connectionandswitch setting of the a...

Page 40: ...for LDAP SSL TLS Communication under SSL TLSSettings on the machine however note that selectingthis option does not ensure thevalidityof the LDAP server 016 525 CauseLDAPserverSSLauthenticationerror...

Page 41: ...ause it could not connect to the FTP server Remedy Ensure that both thedestinationFTP server and themachine are availablefor network communications bycheckingthe following The IP address of the server...

Page 42: ...be used in the save location Check if the same folder name exists in the save location Check ifenough space isavailablein the save location 016 585 Cause The machinefailed totransfer data using FTP o...

Page 43: ...esolution Reducethe magnificationwith Reduce Enlarge Ask your system administratorto increase the value set for MaximumTotal Data Size For color scanning set MRC High Compression toOn under File Forma...

Page 44: ...ain When AuthenticationMethodis set toPreshared Key set the password When AuthenticationMethodis set toDigital Signature set an IPSec certificate 018 405 Cause An error occurred during LDAP authentica...

Page 45: ...etwork cable connection has noproblem confirmthe active status of the targetserver Check whether the server name has been correctly set for LDAP Server DirectoryService Settings under Remote Authentic...

Page 46: ...ificatehas expired or isan unreliable certificate Remedy Ask the sender tosend the e mail with a valid S MIME certificate 027 713 Cause The received e mail has been discarded becauseitmight be altered...

Page 47: ...on Printer Security Function Supplementary Guide 47 Security Xerox For the latest information on security and operation concerning your device see the Xerox Security Information website located at htt...

Page 48: ...r Permissions Guest Access Device User Role or Printing User Role Set Access Control Basic user Permissions Roles Device User Role or Printing User Role Set Maximum Login Attempts Permissions Login Lo...

Page 49: ...ive Apps Fax General Settings and Policies Secure Fax Receive Off Set Service Representative Restricted Operation System Security Customer Service Engineer Access Restriction Off Set Self Test System...

Page 50: ...er Security Function Supplementary Guide 50 List of Product Codes Model Product Code Xerox VersaLink C405 TL500481 TL500482 TL500483 TL500484 TL500485 TL500486 TL500487 Xerox VersaLink B405 TL300981 T...

Reviews: