Service
or Application |
Protocol
Port |
Shorewall
Example |
Ping the
printer |
ICMP 8 |
ACCEPT net
loc icmp 8 |
HTTP (RUI) |
TCP 80 |
ACCEPT net
loc tcp 80 |
Non Canon
driver printing (HP Laserjet ...) |
TCP 515 |
ACCEPT net loc tcp 515 |
Canon
Driver printing (CPCA) |
TCP 515 UDP 47545 |
ACCEPT
net loc tcp 515 ACCEPT net loc udp 47545 |
Canon
Printer Driver Get Device Status |
UDP 47545 |
ACCEPT net loc udp 47545 |
Canon
ScanGear Tool and Scanning |
UDP 47545 TCP 9011 TCP 9014 |
ACCEPT
net loc udp 47545 ACCEPT net loc tcp 9011 ACCEPT net loc tcp 9014 |
NetSpot
Job Monitor |
UDP 47545 | ACCEPT net loc udp 47545 |
Standard
TCP/IP Printer Port Wizard |
UDP 161 |
ACCEPT net
loc udp 161 |
Standard
TCP/IP Printing (LPR) (Need UDP 161 if SNMP status enabled is required)* |
UDP 161* TCP 515 |
ACCEPT
net loc udp 161 ACCEPT net loc tcp 515 |
Standard
TCP/IP Printing (9100) (Need UDP 161 if SNMP status enabled is required)* |
UDP 161* TCP 9100 |
ACCEPT
net loc udp 161 ACCEPT net loc tcp 9100 |
IPP
Printing If using HTTP proxy on host, add printer's IP to local proxy bypass |
UDP 161 TCP 80 |
ACCEPT
net loc udp 161 ACCEPT net loc tcp 80 |
NetSport
Resource Downloader |
UDP 161 UDP 47545 |
ACCEPT
net loc udp 161 ACCEPT net loc udp 47545 |
JBig
Viewer |
UDP 161 TCP 80 |
ACCEPT
net loc udp 161 ACCEPT net loc tcp 80 |
Security
Agent for Single Signon |
TCP 5678 |
ACCEPT
net loc tcp 5678 |
If you find any errors, ommisions or have a better way, please contact me