<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Network Inkjets from the Inside : networking printing</title><link>http://www.communities.hp.com/online/blogs/networkinkjet/archive/tags/networking+printing/default.aspx</link><description>Tags: networking printing</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Personal Firewalls and Trusted Programs</title><link>http://www.communities.hp.com/online/blogs/networkinkjet/archive/2008/09/19/personal-firewalls-and-trusted-programs.aspx</link><pubDate>Fri, 19 Sep 2008 23:00:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84831</guid><dc:creator>david.o.hamilton</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/networkinkjet/rsscomments.aspx?PostID=84831</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/networkinkjet/commentapi.aspx?PostID=84831</wfw:comment><comments>http://www.communities.hp.com/online/blogs/networkinkjet/archive/2008/09/19/personal-firewalls-and-trusted-programs.aspx#comments</comments><description>&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;In the last posting, I talked about changing security level to fix problems created by personal firewalls. In this posting I talk about the next thing to try, if the first two options either are not available, don&amp;#39;t resolve the problem or there is a reason to not&amp;nbsp;select a lower security level.&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;The next thing to try is to trust a particular program. This helps when&amp;nbsp;custom software has been installed, as is generally the case with a network printer. &lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;The easiest way to trust a program is to ensure that the firewall is configured to prompt whenever a program first attempts to make a network connection. This setting needs to be made before installing the printer software. Fortunately, firewalls often have this as their default setting, but not always. &lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;For these prompts to occur, the firewall needs to be running. Don&amp;#39;t disable the firewall before installing the printer software, or the prompts will not occur; while it may be tempting to turn off the firewall before installation to avoid problems, this only postpones problems to a later time. The best thing to do is to leave the firewall enabled and then look for, carefully read, and select to Always-Allow connections when prompted by the firewall software. &lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;When the firewall is set to prompt, then as soon as a program first tries to make a network connection, the firewall should pop up a dialog asking whether to allow or block this program from what it is trying to do. There are several common problems with these popup dialogs:&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt 0.5in;TEXT-INDENT:-0.25in;mso-list:l0 level1 lfo1;tab-stops:list .5in;"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="mso-fareast-font-family:&amp;#39;Times New Roman&amp;#39;;mso-bidi-font-family:&amp;#39;Times New Roman&amp;#39;;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;font size="3"&gt;1)&lt;/font&gt;&lt;span style="FONT:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font size="3"&gt;They can happen frequently, leading to a temptation to click quickly on something to make the dialog go away. &lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt 0.5in;TEXT-INDENT:-0.25in;mso-list:l0 level1 lfo1;tab-stops:list .5in;"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="mso-fareast-font-family:&amp;#39;Times New Roman&amp;#39;;mso-bidi-font-family:&amp;#39;Times New Roman&amp;#39;;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;font size="3"&gt;2)&lt;/font&gt;&lt;span style="FONT:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font size="3"&gt;They can be told to “go away and not come back”. To reduce how often these popup dialogs happen, they often have an option not to show them again. Although one might think this means to take the current selection (e.g., Allow Communication) and always apply this choice without prompting again, this is not always what this option means. Sometimes the firewall simply blocks without prompting. It often surprises people when they find this out.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt 0.5in;TEXT-INDENT:-0.25in;mso-list:l0 level1 lfo1;tab-stops:list .5in;"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="mso-fareast-font-family:&amp;#39;Times New Roman&amp;#39;;mso-bidi-font-family:&amp;#39;Times New Roman&amp;#39;;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;font size="3"&gt;3)&lt;/font&gt;&lt;span style="FONT:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font size="3"&gt;Popup dialogs are not always worded using the most clear language,&amp;nbsp;so be sure to read them carefully to make the right selection.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt 0.5in;TEXT-INDENT:-0.25in;mso-list:l0 level1 lfo1;tab-stops:list .5in;"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="mso-fareast-font-family:&amp;#39;Times New Roman&amp;#39;;mso-bidi-font-family:&amp;#39;Times New Roman&amp;#39;;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;font size="3"&gt;4)&lt;/font&gt;&lt;span style="FONT:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font size="3"&gt;They sometimes incorrectly report that a program is attempting to make a connection to the “Internet” when the program is actually just connecting to the private local network, not the public Internet.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;This surprises people and sometimes causes them to select to block the connection because they don’t know why a program needs to access the “Internet” and don’t want it to send information on the Internet. This inadvertently causes local network connections to be blocked. &lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Any of the above problems can lead to a necessary program not being trusted. So if problems happen after installation, it may be a good idea to check to be sure that all necessary pieces of software are trusted. So how does one find out what software should be in the firewall’s list of trusted programs?&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;You need to check the available documentation on the specific printer. Take the HP Photosmart C4380 wireless All-in-One as an example. The following document lists the programs that need to be trusted to ensure that scanning will work. &lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;a href="http://h10025.www1.hp.com/ewfrf/wc/document?docname=c01460919&amp;amp;cc=us&amp;amp;lc=en&amp;amp;dlc=en&amp;amp;product=3221646"&gt;&lt;font face="Times New Roman" size="3"&gt;http://h10025.www1.hp.com/ewfrf/wc/document?docname=c01460919&amp;amp;cc=us&amp;amp;lc=en&amp;amp;dlc=en&amp;amp;product=3221646&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;You can find documents like this using the method described in the first posting, repeated here:&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;Go to the main hp web site: &lt;u&gt;&lt;a href="http://www.hp.com/"&gt;http://www.hp.com/&lt;/a&gt;&lt;/u&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Move the mouse over the “Support &amp;amp; Drivers” tab near the top of the page.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Enter the product name, such as Photosmart C8180.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Here is the key part: near the top of the page is a field called “Questions or keywords”. In this field, enter the word “networking” (or other keywords if you have problems outside of networking)&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;The search results will list several documents on the right side of the page, including a variety of documents with tips and solutions. There may be multiple pages of results; you can get to additional pages by clicking on the “Next” button or clicking on one of the page numbers. &lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Once you find the list of programs that need to be trusted, you will need to navigate the user interface of your particular firewall in order to find out how to add them to the trusted programs list. &lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;If you uninstall the software that you have trusted, you should go back into the firewall settings to remove the trust as well.&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;It is probably clear that this method of trusting a program is a bit more complex and error-prone than the previously discussed methods. One thing that Hewlett-Packard does to avoid customers from having to deal with the hassle of trusting programs is to work with various firewall manufacturers to pre-configure the firewall to trust programs associated with HP printers. This only works when you have an active subscription for your&amp;nbsp;firewall and you accept updates for it. Not all&amp;nbsp;firewall makers have a method of pre-configuring trusted programs. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84831" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/networkinkjet/archive/tags/printing/default.aspx">printing</category><category domain="http://www.communities.hp.com/online/blogs/networkinkjet/archive/tags/networking/default.aspx">networking</category><category domain="http://www.communities.hp.com/online/blogs/networkinkjet/archive/tags/networking+printing/default.aspx">networking printing</category></item><item><title>MAC Address Filtering</title><link>http://www.communities.hp.com/online/blogs/networkinkjet/archive/2008/07/11/mac-address-filtering.aspx</link><pubDate>Fri, 11 Jul 2008 22:57:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83740</guid><dc:creator>david.o.hamilton</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/networkinkjet/rsscomments.aspx?PostID=83740</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/networkinkjet/commentapi.aspx?PostID=83740</wfw:comment><comments>http://www.communities.hp.com/online/blogs/networkinkjet/archive/2008/07/11/mac-address-filtering.aspx#comments</comments><description>&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Imagine the following scenario: a small startup business (“Acme Networking”) wants to increase their security by posting a guard at their front door who only admits authorized employees. Because they don’t have a lot of money, and because they want to keep things simple, they tell the guard to block people who do not tell the guard that they work for “Acme Networking”.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;The guard stands beside a door that has “Acme Networking” posted on it, and asks each person “Who do you work for?”&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Pretty dumb security, isn’t it?&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;It would prevent someone from accidentally going through the Acme Networking door, but it wouldn’t stop someone who is trying to sneak in; they would just look at the door and say “Oh yes, well um, I work for Acme Networking of course.”&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;MAC address filtering is like the Acme Networking security guard because with it the router only allows communication with devices having a MAC address that the router has been told about, and because those MAC addresses are easy to see for anyone trying to sneak into the network.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;The MAC address is included in communication with the router and the MAC address portion of the communication is unencrypted so anyone can see it even if they have not joined the wireless network. An &amp;quot;intruder&amp;quot; simply needs to change the MAC address on their computer to match one that they see being used on the network. &lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;So although MAC address filtering prevents people from accidentally joining a network, it does little to prevent anyone from sneaking onto the network. &lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;MAC address filtering causes problems because it obviously needs to be kept current. As each new device is added to the network, the new device’s MAC address needs to be added to the MAC address filter list. Any mistake in entering it prevents the new device from working correctly. And because MAC address filtering is not a standard WiFi feature, there is no mechanism to tell a device that it really hasn&amp;#39;t joined the network because it was &amp;quot;filtered out&amp;quot;. So the new device will think it is on the network but the router will be ignoring anything the new device sends to it, and the router won’t route any data to the new device. &lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Most people don’t manage their router settings on a daily basis, so it is easy to forget that MAC address filtering is being used, and others using the network may not be aware it is being used. If someone forgets or is unaware that MAC address filtering is being used and they try to add a new printer to the network, they will generally be confused and frustrated. They did everything right but the darn thing just won’t work. &lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;This is why MAC address filtering is often deemed much more trouble than it is worth. In fact, it has been listed as one of “the six dumbest ways to secure a wireless LAN” by George Ou. (http://blogs.zdnet.com/Ou/index.php?p=43)&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;By the way, many recent HP inkjet printers include a Wireless Network Test that can be run from the printer front panel, with the results printed as a report. It includes many different checks of error conditions. If there are no indications of an error but the printer does not sense any network communication, it warns that MAC address filtering may be blocking communication.&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0in 0in 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Everyone needs to make their own choice when the balance security and convenience, but pros and cons of MAC address filtering should be carefully considered when setting up a wireless network for a friend or relative.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;Are you really going to be doing them a favor by setting this up so that they have to deal with it later?&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83740" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/networkinkjet/archive/tags/networking+printing/default.aspx">networking printing</category></item></channel></rss>