-
Notifications
You must be signed in to change notification settings - Fork 467
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Iptables (question) #5192
Comments
@Kalle72 IPP typically uses port 631, although some printers will use port 443 for encrypted IPP. AppSocket/JetDirect almost always uses port 9100; old multi-port print servers also use port 9101 and 9102. LPD (lpr) uses port 515. SNMP (used for some kinds of discovery as well as supply levels) uses port 161. Bonjour uses port 53 for regular DNS and 5353 for Multicast DNS. I'll use this bug to track adding a firewall help document to the next CUPS release... |
@Kalle72 |
@michaelrsweet I think information is missing if on the CUPS server machine a port E.g. port 9100 does not need to open on the CUPS server FYI see also |
@jsmeix Can you file a new issue asking for the port direction information? I actually had it in one local iteration of the document but ended up dropping it since you can look at the sharing ports as "in" and the network printing ports as "out" - a server absolutely needs to have outgoing tcp port 9100 if you have a legacy network printer that uses that port, for example. |
Thanks a lot for the informations -- exactly what I was searching for! Regards |
@michaelrsweet I have a question regarding your I do not understand this because server TCP port 9100 <----> printer TCP port 9100 but as far as I know network printers accept incoming server TCP port 1234 <----> printer TCP port 9100 |
For someone who is interested: Assume that all outgoing and ingoing traffic will be dropped by iptables (only loopback communication is allowed): Assume furthermore that you wish to print to an JetDirect-Device with the ip 192.168.50.80 Then one can allow outgoing connections to the JetDirect via To accept also the incomming traffic related to the outgoing, one has to use the well-known Because the rule * applies to the cupsd daemon, all users can print now on the JetDirect device Regards |
@jsmeix When I say “outgoing tcp port 9100” I mean destination port 9100. |
Hello,
I use iptables in a strict configuration -- only root can reach some update-relevant ip's.
Now, I will additionally allow the users to print to some network-printers in the local network.
Therefore: Which ports do I have to open for that?
Thanks in advance and regards
Kalle
The text was updated successfully, but these errors were encountered: