Xerox WorkCentre 5845 Installation And Operation Manual Download Page 5

 

 

4

10.

 

IP  Filtering

:  Enable  and  configure  IP  Filtering  to  create  IP  Filter  rules  by  following  the  instructions  under  “IP 

Filtering” in Section 4 of the SAG. 

Note  that  IP  Filtering  is  not  available  for  either  the  AppleTalk  protocol  or  the  Novell  protocol  with  the  ‘IPX’  filing 
transport. Also, IP Filtering will not work if IPv6 is used instead of IPv4.

 

11.

 

Audit Log

: Enable the audit log, download the audit log .csv file and then store it in a compressed file on an external 

IT product using the Web UI by following the appropriate instructions for “Enabling Audit Log” and “Saving an Audit 
Log”, respectively, under “Audit Log” in Section 4 of the SAG.  

Save audit log entries on a USB drive attached to the device via one of the Host USB ports using the Control Panel 
by following the appropriate instructions for “Saving an Audit Log to a USB Drive” under “Audit Log” in Section 4 of 
the  SAG. 

In  downloading  the  Audit  Log  the  System  Administrator  should  ensure  that  Audit  Log  records  are 

protected after they have been exported to an external trusted IT product and that the exported records are only 
accessible by authorized individuals.

 

The  System  Administrator  should  download  and  review  the  Audit  Log  on  a  daily  basis.    The  machine  will  send  a 
warning email when the audit log is filled to 90% (i.e., 13,500) of the 15,000 maximum allowable number of entries, 
and repeated thereafter at 15,000 entries until the Audit Log is downloaded. 

 

12.

 

IPSec

:  Enable and configure IPSec by following the instructions under  “IPsec” in Section 4 of the SAG.  Note that 

IPSec should be used to secure printing jobs; HTTPS (SSL) should be used to secure scanning jobs.  Use the default 
values for IPSec parameters whenever possible for secure IPSec setup.  

Note that IPSec can be disabled at the Control Panel by following the instructions for “Disabling IPSec at the Control 
Panel”  under  “IPSec”  in  Section  4  of  the  SAG.  However,  if  IPSec  is  disabled  the  device  will  no  longer  be  in  the 
evaluated configuration. 

13.

 

Session Inactivity Timeout

: Enable the session inactivity timers (termination of an inactive session) from the Web 

UI  by  following  the  instructions  for  “Setting  System  Timeout  Values”  or  from  the  Control  Panel  by  following  the 
instructions for “Setting the System Timeout Values at the Control Panel” in Section 4 of the SAG. 

14.

 

Secure  Print

:  Set  the  Secure  Print  security  function  to  require  the  User  ID  for  identification  purposes  to  release  a 

secure  print  job.  Access  and  configure  the  Secure  Print  security  function  by  following  the  instructions  under 
“Configuring Secure Print Settings” in Section 5 of the SAG.  

Make sure the ‘Release Policies for Secure Print Jobs Requiring Passcode When the User is Already Logged In’ option 
is set to 

Prompt for Passcode Before Releasing Jobs

For  best  security  print  jobs  (other  than  LANFax  jobs)  submitted  to  the  device  from  a  client  or  from  the  Web  UI 
should be submitted as a secure print job. To ensure that print jobs can only be submitted as secure print jobs, for 
logged  in  users  (since  non-logged  in  users  are  denied  permission  to  print  any  job  in  the  evaluated  configuration) 
follow the instructions for “Setting Job Type Print Permissions under “Editing Print Permissions for the Non-Logged 
In Users Role” under “Configuring Authorization Settings” in Section 4 of the SAG, select 

Custom

 and then set the 

permission to be 

Allowed

 for Secure Print and 

Not Allowed

 for all other print types. 

Once  a  secure  print  job  has  been  submitted  the  authenticated  user  can  either  release  the  job  for  printing  at  the 
Control Panel by following the instructions under ”Releasing a Secure Print” or delete the job at the Control Panel by 
following  the  directions  under  “Deleting  a  Secure  Print”,  both  under  “Printing  Special  Job  Types”  under  “Printing 
Features” in Section 5 of the applicable User Guide

7

Note that only the submitter of a secure print job can release the job, and in the evaluated configuration only the 
System Administrator can delete any job, including a secure print job. To ensure that only the System Administrator 
can  delete  jobs,  from  the  WebUI  follow  the  instructions  for  “Editing  Services  and  Tools  Permissions  for  the  Non-
Logged  In  Users  Role”  under  “Configuring  Authorization  Settings”  in  Section  4  of  the  SAG  and  set  the  entry  for 
‘Delete  Jobs’  under  ‘Job  Status  Pathway’  to 

Not  Allowed

  for  all  defined  logged  in  user  roles  except  the  System 

Administrator  and  Accounting  Administrator  roles,  which  are  set  to 

Allowed

  for  this  entry  (non-logged  in  users 

should be denied permission to access any device services or features as discussed in I.b.3.ii above).  

Set job deletion to ‘System Administrator Only’ at the Control Panel by following the instructions for “Setting Job 
Deletion Options at the Control Panel” in Section 10 of the SAG. 

15.

 

Hold All Jobs

: The 

Hold All Jobs

 function is used in the evaluated configuration. Set the Enablement option to 

Hold 

All  Jobs  in  a  Private  Queue

  and  the  Unidentified  Jobs  Policies  option  to 

Hold  Jobs;  Only  Administrators  can 

                     

7

Xerox

 WorkCentre

 5845 / 5855 / 5865 / 5875 / 5890  User Guide, Version 1.0: January 2013;  Xerox

 WorkCentre

 7220 / 7225  User Guide, 

Version 1.0: April 2013;  Xerox

 WorkCentre

 7800 Series  User Guide, Version 1.0: February 2013;  Xerox

 ColorQube

 9301 / 9302 / 9303 

Xerox ConnectKey Controller User Guide, Version 1.0: February 2013. 

Summary of Contents for WorkCentre 5845

Page 1: ...Version 1 3 May 6 2013 Secure Installation and Operation of Your WorkCentre 5845 5855 5865 5875 5890 WorkCentre 7220 7225 WorkCentre 7830 7835 7845 7855 and ColorQube 9301 9302 9303...

Page 2: ...he information provided here is consistent with the security functional claims made in the Security Target 3 Upon completion of the evaluation the Security Target will be available from the Common Cri...

Page 3: ...assword Reset security feature so it is not used To disable this feature perform the following At the Web UI select the Properties tab Select the following entries from the Properties Content menu Sec...

Page 4: ...self signed certificate is installed by default on the device If a CA certificate is desired a Certificate Signing Request CSR will have to be sent to a Certificate Authority to obtain the CA Certific...

Page 5: ...ure Print Settings in Section 5 of the SAG Make sure the Release Policies for Secure Print Jobs Requiring Passcode When the User is Already Logged In option is set to Prompt for Passcode Before Releas...

Page 6: ...nd SFTP Filing Settings under FTP SFTP Filing in Section 3 of the SAG c The following protocols services and functions are considered part of the evaluated configuration and should be enabled when nee...

Page 7: ...ction 8 of the SAG Makes sure the Delete on Print option is selected for Received Documents The Local Polling option and embedded fax mailboxes should not be set up or used at any time Remote Polling...

Page 8: ...disable when complete Software upgrades can be enabled disabled by following the instructions for Enabling Upgrades under Updating the Printer Software in Section 10 of the SAG II Secure Acceptance Se...

Page 9: ...nd Image Overwrite should be run This error message will persist until an On Demand Image overwrite is initiated by the System Administrator In the case that the copy controller is reset at the same t...

Page 10: ...can job will be deleted and not transferred to the remote SSL repository In this case the job status reported in the Completed Job Log for this job will read Job could not be sent as a connection to t...

Page 11: ...nter to report the suspected problem and initiate the SPAR Software Problem Action Request 10 process for addressing problems found by Xerox customers d Depending upon the configuration of the device...

Page 12: ...can to email LAN Fax or Embedded Fax job fails The error message informs the user to notify the System Administrator that an On Demand Overwrite should be run and persists on the Control Panel screen...

Page 13: ...ler LDAP server and other kerberized services as they are developed Is accessible by typing http IP Address diagnostics kerberosSettings php Download DLM PCL Forms Allows the System Administrator to d...

Page 14: ...nters to each Web User Interface screen organized by Web UI tab Is accessible by selecting the Site Map button in the upper right hand corner of every Web User Interface page Exit from Sleep Mode Auto...

Reviews: