Loading

Configure IPsec

This topic contains the following instructions:

  1. Check if the Identity certificate is valid for IPsec

  2. Configure IPsec

PRISMAsync Print Server IPsec protocols

PRISMAsync Print Server can use IPsec to secure the host communication via the following protocols.

  • HTTPS

  • DHCP

  • ICMP

  • NDP

Check if the Identity certificate is valid for IPsec

To use IPsec, the PRISMAsync Print Server Identity certificate must be valid for IPsec, and also HTTPS.

HTTPS can be used in case problems occur with the IPsec connection.

  1. Go to: [Configuration]  → [Security].

    [Security] tab
  2. Go to the [Identity certificate] options.

  3. Read the [Valid for IPsec] option to check if the certificate is valid for IPsec and HTTPS.

    Certificate for IPsec

Configure IPsec

  1. Go to: [Configuration]  → [IPsec communication].

    [IPsec communication] tab
  2. Click [Configure].

  3. Click the [IPsec enabled] check box.

  4. Use the [Minimum strength of encryption algorithm] option to define the minimum algorithm strength level.

    [Minimum strength of encryption algorithm] option
    • [Compatible with legacy algorithm techniques]

    • [Compatible with common algorithm techniques]

    • [Compatible with strong algorithm techniques]

  5. Use the [Use of NAT-T] option when NAT-T (Network Address Translation Traversal) must be used.

    [Use of NAT-T] option
    • [Never]

    • [When remote endpoint is behind NAT router]

    • [When both local and remote endpoints are behind NAT router]

  6. Use the exemption options to indicate what TCP/IP protocols are not secured by IPsec.

    Exemption options
    • [Exempt DHCP traffic from IPsec security]

    • [Exempt ICMP traffic from IPsec security]

    • [Exempt NDP traffic from IPsec security]

    • [Exempt HTTPS traffic from IPsec security]

    IMPORTANT

    During the initial configuration of IPsec, you are advised to keep the possibility to connect via HTTPS in case IPsec is not able to set up a connection. Therefore, exempt HTTPS from IPsec security and ensure HTTPS is configured correctly.

  7. Click [OK].

  8. Define one or more IPsec rules.

    NOTE

    IPsec is active when at least one rule has been defined.