Netgard Secure Scanning for US DOD and Federal Agencies Before

Transcription

Netgard Secure Scanning for US DOD and Federal Agencies Before
12/16/2011
SYS211 e-Le@rning:
Netgard Secure Scanning
for U.S. DOD and Federal Agencies
Presenter: Henry Gold
Business Area Manager
API Technologies
Before we begin…
ƒ Please silence your cell phones
ƒ Keep background noise to a minimum
ƒ Do not put your phone on HOLD
ƒ Please let instructor know if anyone else
is sitting in with you
ƒ The phone audio will be muted - Please
save questions until the end or submit
text based questions as we move
through presentation
Toshiba Academy Systems e-Le@rning Program
1
12/16/2011
Have questions?
Submit text based
questions
via the Q&A pod
Toshiba Academy Systems e-Le@rning Program
Your Status
ƒ Throughout the program, we will ask
you to respond by indicating your
“Status.”
ƒ When asked please use the “Status
Options” drop-down button, located
at the top of your screen.
ƒ Set your status now by indicating:
“Agree”
9
Toshiba Academy Systems e-Le@rning Program
2
12/16/2011
e-Le@rning Goals
The goals of today’s e-Le@rning session are…
ƒ Introduce the new Netgard MFD security solution that will
help facilitate sales to U.S. DOD (and soon civilian
agencies)
ƒ How does Netgard relate to GSA?
ƒ Reduce your sales cycle
ƒ Provide you with product training to get you started with
Netgard
N
d MFD
Toshiba Academy Systems e-Le@rning Program
e-Le@rning Objectives
Upon completion of this course, you will be able to:
¾ Build your knowledge of a key Security requirement to deploy
systems to the U.S. DOD and Civilian Agencies
¾ Give you the tools needed to close business with the U.S. Gov.
¾ Provide the necessary skills to install this solution
Toshiba Academy Systems e-Le@rning Program
3
12/16/2011
Agenda
1. API Technologies Introduction
2 Netgard™ Overview
2.
3. Physical Installation and Technical Overview
4. Live Q&A Discussion
Toshiba Academy Systems e-Le@rning Program
API Technologies Introduction
ƒ
ƒ
ƒ
Who is API Technologies?
Featured Customers
The Customer Need
Toshiba Academy MPS Certification Program
4
12/16/2011
Company Snapshot
ƒ Prime contractor in sophisticated
electronics, highly engineered systems,
secure communications and electronic
components and subsystems to the global
defense and aerospace industries
ƒ
ƒ
ƒ
ƒ
Publicly traded (ATNY.OB)
Revenues of over $380M
2000 Employees
Key product focus
¾ Defense & Aerospace Products & Services
¾ Systems
S t
& Engineering
E i
i S
Services
i
¾ Secure Communications Products &
Services
¾ Components & Subsystems
Toshiba Academy Systems e-Le@rning Program
Featured Customers
US & International Government Agencies
Leading Government & Defense Contractors
Toshiba Academy Systems e-Le@rning Program
5
12/16/2011
The Customer Need
DOD Requirement:
¾ All multi-function devices (MFDs) that can
transmit scan jobs over the LAN must be
secured by a Common Access Card (CAC)
that will verify and authorize the user before
a scan-to-network function is permitted
(STIG)
¾ Expanding security to “Copy” function &
“Print Release”
¾ Seeing
g requirement
q
at Civilian Agencies
g
(PIV card)
HSPD‐12
HSPD
12
Toshiba Academy Systems e-Le@rning Program
CAC & SMARTCARD Deployments
ƒ 17 million cards issued to date
ƒ 5.5
5 5 million active cards are in use
today
ƒ Today CACs are:
¾ The standard at more than 1,000 sites
¾ Used in over 25 countries
ƒ To date the DoD has deployed
p y over 1
million card readers and associated
middleware around the world
Toshiba Academy Systems e-Le@rning Program
6
12/16/2011
Netgard Overview
ƒ
ƒ
ƒ
How it works
Authentication Options
Value Proposition
Toshiba Academy MPS Certification Program
Netgard: How it Works
ƒ End Users Brings their CAC
Card to our Device
ƒ They insert their CAC Card in
the reader
ƒ They enter their Pin Number
ƒ The Server Verifies
Status/ Job
Cancel
Copy
Program
Send
Application
Document Box
Credentials(OCSP/LDAP/AD)
ƒ Operation Panel Access
Granted
OCSP/LDAP/AD
OR
ƒ Operation Panel Access Denied
Toshiba Academy Systems e-Le@rning Program
7
12/16/2011
Connectivity
•
•
•
•
Simple, in‐line Ethernet connection
Web‐based remote admin
Integrates with Active Directory and/or PKI
Supports CAC PIN, X.509 certificate, LDAP, PKI and OCSP
Toshiba Academy Systems e-Le@rning Program
Live Video Demonstration
Toshiba Academy Systems e-Le@rning Program
8
12/16/2011
Important Facts
ƒ Conforms to DoD requirements
ƒ Works with all major copier models
ƒ Support for CAC/PIV V1 & V2
ƒ Special security features:
¾ FIPS 140-2 & 201
¾ Email encryption & signing
¾ Confirms identity of sender
ƒ Added security on Scan-to-Email feature replaces the “From”
“Reply-to” and “Sender” fields with CAC user’s email address
(obtained from CAC or LDAP)
Toshiba Academy Systems e-Le@rning Program
Netgard Customers / Deployments
Over 3000 Netgard™ devices are currently deployed in all
branches of armed services:
ƒ Air Force (Andrews, Ramstein, Bolling & Hill AFB)
ƒ Army (Aberdeen, Fort Collins)
ƒ Army National Guard
ƒ Army Reserves
ƒ Navy (Jabuti Naval Base)
ƒ DAPS/DLA
Toshiba Academy Systems e-Le@rning Program
9
12/16/2011
Configurable Authentication Options
ƒ
PIN (Default, Always ON)
¾
ƒ
ƒ
ƒ
ƒ
User’s PIN is used to unlock the CAC.
X509 validation (requires issuer certificate)
¾
CAC certificate Challenge/response
¾
Requires issuer certificate
OCSP
¾
User’s certificate is sent to OCSP server for revocation check.
¾
Requires issuer certificate
LDAP/LDAPS (anonymous and non-anonymous)
¾
LDAP lookup is performed to ensure the user is valid
¾
LDAPS requires server certificate
¾
Non-anonymous lookup requires username and password
Kerberos
¾
Network PKI authentication
Toshiba Academy Systems e-Le@rning Program
How Does the Netgard Affect the Printer/MFP?
ƒ No adjustment to the Copier/MFP is required – the
Netgard MFD connects the MFP to the LAN and
handles all network traffic control.
ƒ Windows users see no difference when they print to
the Copier/MFP or add a printer.
ƒ Administrators may connect to Copier/MFP and
manage it using the browser interface as normal.
ƒ Other Copier/MFP communication, like the Printer
Monitor Utility (SNMP based), is unaffected as well.
Toshiba Academy Systems e-Le@rning Program
10
12/16/2011
Value Proposition
ƒ Quick to market CAC/PIV – Secures Scan to Network.
¾ No custom development needed on MFD
ƒ MFD agnostic
ƒ Easy to deploy
ƒ With over 3000 devices deployed…field tested
ƒ Significant investment – core competency
ƒ Priced right
Toshiba Academy Systems e-Le@rning Program
Additional Points
ƒ Next release will support GSA PIV (1st half 2012)
ƒ Secure Print Release - Print to cloud with NSI
ƒ Scan to home – Utilizes NSI Autostore
Toshiba Academy Systems e-Le@rning Program
11
12/16/2011
Physical Installation
ƒ
ƒ
ƒ
ƒ
ƒ
ƒ
ƒ
ƒ
ƒ
Let’s Install Netgard
Connectivity and Physical Connections
Local Access Via IP Connection
Basic Configuration
Setup of MFP
Advanced Authentication Options
Netgard Maintenance
Pre-Installation Checklist
Troubleshooting
Toshiba Academy MPS Certification Program
Connectivity
Toshiba Academy Systems e-Le@rning Program
12
12/16/2011
Physical Connection
ƒ Make connections
¾ Connect CAC Reader to USB port
¾ Connect base network to LAN port
¾ Connect copier to DEV port
¾ Connect computer to MGMT port (no crossover needed)
¾ Connect Vend cable via USB port (optional)
ƒ Power up
p unit (~60
(
seconds to boot))
Toshiba Academy Systems e-Le@rning Program
Initial Install Requires Local Access
Via IP Connection
Toshiba Academy Systems e-Le@rning Program
13
12/16/2011
Administering Netgard MFD
ƒ Administer Netgard by plugging directly into the Ethernet
Management (MGMT) port.
¾ Set computer IP to:
IP: 192
192.168.20.20
168 20 20
Subnet: 255.255.255.0
Gateway: 192.168.20.1
ƒ Use FireFox web browser to administer Netgard
ƒ https://192.168.20.1:8080
ƒ Login
g information
¾ ID: admin
¾ Password: password
ƒ For additional details see the quick install guide.
Toshiba Academy Systems e-Le@rning Program
GUI
Toshiba Academy Systems e-Le@rning Program
14
12/16/2011
Netgard Homepage
ƒ Tour of UI
Toshiba Academy Systems e-Le@rning Program
Basic Configuration
Toshiba Academy Systems e-Le@rning Program
15
12/16/2011
Network configuration (Step #1)
ƒ Click on the “Network” Tab
ƒ Set IP addresses
¾ Set the Netgard’s Lan
Address If DHCP write
Address.
down the IP address.
¾ Tell the Netgard the IP
address of the Printer
¾ Click the “Apply” button
ƒ Set Copier IP:
IP: 192.168.10.30
Subnet:255.255.255.0
GW: 192.168.10.1
ƒ Additional configuration
optional
Toshiba Academy Systems e-Le@rning Program
Scan Setup (Step #2)
ƒ Click on the “Scan Setup”
button
ƒ Enable Required
f
functionality
ti
lit
¾ Email
ƒ Set SMTP server IP
ƒ Scan to self?
ƒ Encryption & Signing
¾ FTP
ƒ Append file header name?
¾ Click the “Apply” button
Toshiba Academy Systems e-Le@rning Program
16
12/16/2011
Scan Setup (Step #2 cont.)
ƒ Enable SMB
ƒ Open F/W when CAC
authenticated?
ƒ Set NSI/Autostore
information
ƒ Click the “Apply”
button
Toshiba Academy Systems e-Le@rning Program
Netgard Admin (Optional)
ƒ Click on the “Admin”
tab
ƒ Turn on Management
port on LAN Port so
Administer Netgard
remotely
ƒ Define an ACL
Toshiba Academy Systems e-Le@rning Program
17
12/16/2011
User Administration
ƒ Click on the
Admin->Users
t b
tab.
ƒ Add a new
“Admin” level
user
ƒ Delete the
default admin
user.
Toshiba Academy Systems e-Le@rning Program
Initial Netgard Configuration Complete….
Now Setup MFP
Toshiba Academy Systems e-Le@rning Program
18
12/16/2011
MFP Configuration
ƒ Set Copier IP address to address configured in the first
p (default
(
= 192.168.10.30))
step
ƒ Setup Scan to Network functionality
¾ Same configuration as if copier was sitting on customer network.
¾ If Email set to “Send to Self” add one “Destination”
Toshiba Academy Systems e-Le@rning Program
IP Configuration on e-STUDIO MFP
ƒ IP address =
192 168 10 30
192.168.10.30
ƒ Subnet Mask=
255.255.255.0
ƒ Gateway =
192.168.10.1
Toshiba Academy Systems e-Le@rning Program
19
12/16/2011
Test Basic Functionality
ƒ Authenticate with a CAC and test
¾ Scan to email,
email Scan to SMB
SMB, Scan to FTP
¾ Perform same test without CAC
ƒ Browse to Copier
¾ Use “LAN” IP address of Netgard (http://10.10.3.153)
ƒ Test Print functionality
¾ Use “LAN”
LAN” IP address of Netgard
Toshiba Academy Systems e-Le@rning Program
Advanced Authentication Options
Toshiba Academy Systems e-Le@rning Program
20
12/16/2011
Authentication Screen
• Authentication Options
•
•
•
•
X.509 – Local certificate authentication
OCSP – Revocation List
LDAP – Active Directory Lookup
Kerberos – Authentication Toshiba Academy Systems e-Le@rning Program
Additional Configuration for X.509
ƒ Click on Scan Setup-> Certificates button
ƒ Upload Certificates (chain of trust)
¾ “Upload Trusted Certificates” button on the right hand side
¾ Certificates must be in Base-64 encoded format (pem file extension)
ƒ Point the Netgard to a NTP server to ensure the Date/Time is properly
set (Admin->Time Zone)
Toshiba Academy Systems e-Le@rning Program
21
12/16/2011
Netgard Maintenance
Toshiba Academy Systems e-Le@rning Program
Configuration Management
ƒ
ƒ
ƒ
ƒ
Go to the Admin->Utilities
Backup and restore a device configuration
Perform a Netgard Upgrade
Reboot the device
Toshiba Academy Systems e-Le@rning Program
22
12/16/2011
Pre-Installation Check List
Toshiba Academy Systems e-Le@rning Program
Pre-Installation Checklist
ƒ Netgard IP address (Subnet & Mask)
¾ May need to provide MAC address
¾ DNS IP
ƒ SMTP IP address
ƒ NTP IP
ƒ Root & intermediate certificates
ƒ OCSP URL
ƒ LDAP iinformation
f
ti
¾ IP, Login, Search details
ƒ CAC card available for testing
Toshiba Academy Systems e-Le@rning Program
23
12/16/2011
Troubleshooting
Toshiba Academy Systems e-Le@rning Program
Can’t Get to Management Port?
1) Check Computer’s IP address
IP: 192.168.20.20
Subnet: 255.255.255.0
Gateway: 192.168.20.1
2) Confirm that your computer IP address changed:
Open Command Window (run>CMD)
At the prompt type IPCONFIG
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix
. :
IP Address. . . . . . . . . . . . : 192.168.20.20
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.20.1
3) Start a New web browser session (Firefox)
Ensure that the URL is correct https://192.168.20.1:8080
Toshiba Academy Systems e-Le@rning Program
24
12/16/2011
Diagnostics & Logs
Toshiba Academy Systems e-Le@rning Program
Troubleshooting Scan to Email
ƒ Confirm that the Netgard configuration is correct:
¾ Email configuration
ƒ Scan Setup->Scan to Network->Enable Email
ƒ Scan Setup
Setup->Scan
>Scan to Network
Network->Server
>Server IP address correct
¾ Copier device (Network->Configuration->Copier IP Address)
ƒ Confirm that the Netgard can ping the copier & SMTP server
ƒ Take Netgard out of loop to ensure copier setup
ƒ Confirm that the user successfully completed the CAC
authentication.
¾ Reader displays “Ready to Scan”
ƒ Capture email session to determine root cause
¾ Monitoring->Diagnostics->Packet Trace->Network Select (LAN and
MFD)
Toshiba Academy Systems e-Le@rning Program
25
12/16/2011
Troubleshooting
CAC authentication failure
ƒ Start off simple - Add layers of authentication to
ensure configuration
g
is correct
ƒ Confirm that the Netgard can ping the OCSP, LDAP
server
ƒ Take Netgard out of loop to ensure copier setup
ƒ Capture failed authentication session to determine
root cause
¾ Monitoring->Diagnostics->Packet Trace->Network Select (LAN
and MFD)
Toshiba Academy Systems e-Le@rning Program
Wrap-up
ƒ Additional Materials from API Technologies
¾ User Guide
¾ Quick Install Guide
¾ Installation & Configuration Videos
¾ Product Catalog
ƒ Negard MFD Community on
Toshiba eXCHANGE
Software & Services > Security > Netgard MFD
Toshiba Academy Systems e-Le@rning Program
26
12/16/2011
API Technologies Netgard
Technical Training Certification Process
1. There are no prerequisites for the course
2. A Tech ID is REQUIRED to access API Technologies
Netgard CBT/Certification Test
¾ If you do not have a Tech ID, please see you local FYI SIS Admin to
add you to the Service Group and request a Tech ID at:
¾ FYI > Training > Service > Dealer Administration > New Tech Application
3. Once you have a Tech ID have your Service Manager enroll
you in:
¾
CBT course 12199: API Technologies Netgard
4. A dealer technical representative must pass the technical
CBT to be eligible to purchase Netgard solution
Toshiba Academy Systems e-Le@rning Program
API Technologies Netgard
Sales Training Certification Process
Pass the “73. API Technologies Netgard Certification Final
Exam” on FYI
FYI > Training > Sales > Testing > Product Knowledge Testing
¾
Must score of 80% or better to pass
Toshiba Academy Systems e-Le@rning Program
27
12/16/2011
Questions
Toshiba Academy Systems e-Le@rning Program
Thank you for attending!
Product Support
[email protected]
+1 (908) 546-3900 option 8
Henry Gold
+1 (908) 546-3907
[email protected]
Toshiba Academy Systems e-Le@rning Program
28
12/16/2011
Eric Roskelly
Digital Training Manager
973-316-2700 Ext #42730
[email protected]
Please advise us if you have not registered!
Toshiba Academy Systems e-Le@rning Program
Rob Troxel
Digital Training Manager
888-343-6245 Ext #5602
[email protected]
Please advise us if you have not registered!
Toshiba Academy Systems e-Le@rning Program
29
12/16/2011
Dean Tamashiro
Digital Training Manager
949-462-6927
[email protected]
Please advise us if you have not registered!
Toshiba Academy Systems e-Le@rning Program
30