
Set up Instant On Security
HP Enterprise printers running the latest rmware version use the Instant-On Security and the HP Device
Announcement Agent features to automatically discover and congure devices when they are rst connected to
the network.
NOTE: Automatic assessment/ remediation of newly discovered devices requires a device license and a valid
initial assessment policy.
NOTE: To implement Instant-On Security, the device must support HP Device Announcement Agent, which is
found in rmware version 11.3 (released December 2011) or later.
For a list of devices that include HP Device Announcement Agent, go to www.hp.com/go/SecurityManager.
Automatic discovery requires that the Accept Device Announcements feature is enabled (disabled by default) and
the device's HP Device Announcement Agent feature is enabled (enabled by default). In addition, the corporate
DNS server must be congured with an entry that points the hostname hp-print-mgmt to the IP address of the
Security Manager server.
When the device announcement agent is activated on a compatible printer, the HP device announcement agent
looks for a host with the DNS hostname of hp-print-mgmt. If found, the device announces itself directly to
Security Manager. If Accept Device Announcements is enabled and the device passes the minimum
authentication requirements, the device is automatically added to Security Manager. If Allow Automatic
Remediation is enabled, an automatic assessment/ remediation of the device occurs.
NOTE: A device is not added to Security Manager if it fails the minimum authentication required for the
assessment.
When the device announcement agent is enabled, it announces itself to the Security Manager server in the
following situations:
●
When the device is turned on.
●
When a cold reset is performed on the device.
●
When the IP stack comes up (for example, after a network conguration change).
●
When the conguration server IP address changes (use this if a DNS entry cannot be used).
●
When the HP Device Announcement Agent feature is enabled using the check box in the device
HP Embedded Web Server or the device control panel.
When Accept Device Announcements is enabled, each device that passes the authentication is assigned a device
license from the license pool.
Follow these steps to set up Instant-On Security:
NOTE: The Instant-On Security feature might fail, if IPsec, Windows rewall, or other rewalls does not allow
communication with Security Manager using port 3329.
1. To activate Instant-On Security and automatic remediation, request the site administrator to add an entry in
the corporate DNS server that points hp-print-mgmt to the IP address of the Security Manager server.
2. Click the Settings, icon, and then select the Settings option.
3. In the left navigation pane, select Instant-On Security.
ENWW Set up Instant On Security 13
Comentarios a estos manuales