Secure Installation and Operation of Your VersaLink
®
Multifunction
and Single Function Printer
Purpose and Audience
This
docum
ent provides information on the secure installation, setup and operation. All customers, but particularly those
concerned with secure installation and operation of these devices, should follow these guidelines.
Overview
This document lists some important customer information and guidelines
1
that will ensure that your device is operated and
maintained in a secure manner.
I.
Secure Installation and Set-up
To set up the machines in a secure manner, follow the guidelines below:
a.
Set up and configure the following security protocols and functions in the evaluated configuration:
Immediate Image Overwrite
On Demand Image Overwrite
Data Encryption
FIPS 140-2 Mode
IP Filtering
Audit Log
Security Certificates, Transport Layer Security (TLS)/Secure Sockets Layer (SSL)
and HTTPS
IPsec
Local, Remote or Smart Card Authentication
Local or Remote Authorization
User Permissions
Personalization
802.1x Device Authentication
Session Inactivity Timeout
USB Port Security
Embedded Fax Secure Receive
Secure Print
S/MIME
System Administrator authentication is required when accessing the security features and administrative functions of the
device or when implementing the guidelines and recommendations specified in this document. To log in as an
authenticated System Administrator via the Embedded Web Server Interface ( denoted hereafter as the Web UI), follow
the instructions under “Accessing the Embedded Web Server as a System Administrator” under “Accessing Administration
and Configuration Settings” in Section 2 of the applicable System Administration Guide (SAG)
2
.
To log in as an authenticated System Administrator via the Local User Interface (denoted hereafter in this document as
the Control Panel), follow “Accessing the Control Panel as a System Administrator” under “Accessing Administration and
Configuration Settings” in Section 2 of the SAG.
To log in as an authenticated user who is not the System Administrator ‘admin’ user, follow the instructions for “Accessing
the Embedded Web Server as a System Administrator” under “Accessing Administration and Configuration Settings” in
Section 2 of the applicable System Administration Guide (SAG), except that instead of entering ‘admin’ for the User ID
and the system administrator password the user should enter his/her User ID and his/her authentication password.
For secure operation do not use the ‘Simple Login’ method.
b.
Follow the instructions located in Chapter 4, Security, in the SAG to set up the security functions listed in Item a above.
Note that whenever the SAG
requires that the System Administrator provide an IPv4 address, IPv6 address or port number
the values should be those that pertain to the particular device being configured.
1
All guidelines in this document apply to the System Administrator unless explicitly stated otherwise.
2
Xerox
®
VersaLink
®
Series Multifunction and Single Function Printers System Administrator Guide, Version 1.1, April 2017