Multifunction Peripheral (MFP) Security for Enterprise Environments
MFP Security White Paper
6
Protocol/Service Configuration
Improperly configured systems are a common target for attack. Systems may have security settings improperly
configured, or unused, unneeded, and unmonitored services installed. Oftentimes, services that are left unused
are not secured, providing backdoors for exploitation. The following services and protocols may be
selectively disabled:
• Management: Embedded Web Server (EWS), SNMPv2 and SNMPv3 protocols, Telnet, FTP, and
RCFG.
• Network Protocols: IPX/SPX, AppleTalk, DLC/LLC.
• Print Services: Port 9100, LPD, IPP, and FTP
• Device Discovery: SLP, mDNS, and Multicast IPv4
MFP Copy/Scan/Print Security
HP MFP’s provide a range of capabilities. The HP 4100 and 9000 series MFPs allow the capability to copy,
scan, and print network documents. Scanned documents may be stored for subsequent reprinting, transferred
to network folders, FTP sites, or remote printers, as well as transmitted electronically as email and LAN faxes.
Secured access to the MFP is provided by HP Digital Sending Software (DSS) components. Using HP DSS,
access to the MFP as well as network and email functionality may be limited to authenticated NT and Novell
users.
Private printing allows a personal identification number (PIN) to be associated with the print job. The print job
will be released only after that PIN has been entered at the MFP’s control panel.
Scan-to--email allows a document to be transmitted electronically. To ensure the integrity of scanned-to-email
documents, as well as compliance to intellectual property policies, the administrator may configure the MFP
email gateway to the trusted gateway (Figure 2).
Figure 2: The HP MFP Subsystems
Encrypted Scan to E-Mail and Network is provided by Authentica’s content securing software. Additional
information may be found in the reference section for Secure Document Delivery.
Director
y
Folder
,
FTP
Digital Sending
Software
(
DSS
)
Printer
Multifunction Peripheral (MFP)
Email, Fax
User
1
42
3










