
4. Select the Accept Device Announcements check box, and then click OK in the conrmation dialog box to
enable communication with port 3329.
5. Select a setting to specify the minimum authentication required for the assessment. The default setting is
the No Authentication (Out of the Box) option.
Mutual Authentication
a. Select this option for the highest authentication level and then click Select Certicate.
This authentication method is most secure and requires certicates to be congured on the device
and in Security Manager. This enables the Security Manager server and the device to verify that the
certicate for the other is valid. When the device announces itself or other events occur, such as an IP
address change or cold reset, the device and the Security Manager server communicate using the
secure socket layer (SSL) to validate certicates before automatic remediation occurs. The certicates
must be valid identity certicates signed by a trusted certicate authority and installed on the Security
Manager server and each device. Each device must be set to require mutual authentication using
certicates during a pre-staging process. Because certicates remain after a cold reset, this method
of Instant-On Security provides protection even if a cold reset is performed on the device.
b. On the Select Certicate window, select a certicate from the list of certicates found on the Security
Manager server, and then click Select.
NOTE: Optionally, you can use Security Manager to manage the identity certicates on the Security
Manager server and the devices.
No Authentication (Out of the Box)
a. Select this option to not use any authentication.
This is the simplest authentication method because no pre-staging is required. Security Manager
automatically congures devices to be compliant with the security policy when they are taken out of
the box and connected to the network. This method also works on devices when a cold reset is
performed because no authentication is required for auto discovery, assessment, and remediation.
b. To restrict and control the devices entering Security Manager, select the Use Device Serial Number
List check box, and then click Add Device Serial Number(s).
c. Select one of the following methods to add serial numbers on the Add Device Serial Number(s)
window:
●
Type the printer’s serial number in the Device Serial Number text box , and then click Add to list.
●
Click Add from le, locate the xml or text le from your le browser, open the le in Security
Manager, and then click Add.
Security Manager uses the list of serial numbers to accept a device the rst time, and then
automatically removes the serial number from the list. It recognizes all future announcements
by that device as a valid device.
6. Create a valid policy from the Policies page.
For instructions, see Create a policy
NOTE: You must create a valid initial policy to use with Automatic Remediation.
7. Select the Allow Automatic Remediation check box to activate automatic remediation.
14 Chapter 3 Set up Security Manager ENWW
Comentarios a estos manuales