Admin Guide
Admin Guide
Contents
Administrator's Guide................................................................................................................................. 7
Using Web Config Network Configuration Software ................................................................................ 8
About Web Config ................................................................................................................................ 8
Accessing Web Config ......................................................................................................................... 8
Restricting Features Available for Users .............................................................................................. 9
User Feature Restriction................................................................................................................ 10
Configuring User Feature Restrictions........................................................................................... 10
Changing the Administrator Password in Web Config ................................................................... 12
Using Your Product on a Secure Network .......................................................................................... 13
Configuring SSL/TLS Communication........................................................................................... 13
Configuring SSL/TLS Settings .................................................................................................. 13
Configuring a Server Certificate for the Product........................................................................ 14
Configuring IPsec/IP Filtering ........................................................................................................ 15
About IPsec/IP Filtering ............................................................................................................ 16
Configuring Default IPsec/IP Filtering Policy............................................................................. 16
Configuring Group IPsec/IP Filtering Policies ........................................................................... 17
IPsec/IP Filtering Policy Settings .............................................................................................. 18
IPsec/IP Filtering Configuration Examples................................................................................ 23
Configuring an IPsec/IP Filtering Certificate ............................................................................. 24
Configuring SNMPv3 Protocol Settings ......................................................................................... 25
SNMPv3 Settings...................................................................................................................... 26
Connecting the Product to an IEEE 802.1X Network ..................................................................... 27
Configuring an IEEE 802.1X Network ....................................................................................... 27
IEEE 802.1X Network Settings ................................................................................................. 28
Configuring a Certificate for an IEEE 802.1X Network .............................................................. 29
IEEE 802.1X Network Status .................................................................................................... 30
Using a Digital Certificate .............................................................................................................. 31
About Digital Certification.......................................................................................................... 31
Obtaining and Importing a CA-signed Certificate ...................................................................... 32
CSR Setup Settings .................................................................................................................. 34
3
CSR Import Settings ................................................................................................................. 34
Deleting a CA-signed Certificate ............................................................................................... 35
Updating a Self-signed Certificate............................................................................................. 35
Using an LDAP Server................................................................................................................... 36
Configuring the LDAP Server and Selecting Search Settings ................................................... 37
LDAP Server Settings ............................................................................................................... 38
LDAP Search Settings .............................................................................................................. 40
Checking the LDAP Server Connection .................................................................................... 40
LDAP Connection Report Messages ........................................................................................ 41
Configuring Protocols in Web Config ............................................................................................. 41
Protocol Settings....................................................................................................................... 42
Using an Email Server ................................................................................................................... 45
Configuring an Email Server ..................................................................................................... 46
Email Server Settings ............................................................................................................... 46
Checking the Email Server Connection .................................................................................... 47
Email Server Connection Report Messages ............................................................................. 48
Configuring Email Notification................................................................................................... 50
Using EpsonNet Config Network Configuration Software..................................................................... 51
Installing EpsonNet Config ................................................................................................................. 51
Configuring a Product IP Address Using EpsonNet Config ................................................................ 51
Using Epson Device Admin Configuration Software ............................................................................. 53
Solving Problems ...................................................................................................................................... 54
Scanning Error Messages .................................................................................................................. 54
Solving Network Software Usage Problems....................................................................................... 57
Cannot Access Web Config........................................................................................................... 57
The "Out of Date" Message Appears............................................................................................. 58
"The name of the security certificate does not match" Message Appears ..................................... 58
Model Name or IP Address Not Displayed in EpsonNet Config ..................................................... 58
Solving Network Security Problems ................................................................................................... 58
Pre-Shared Key was Forgotten ..................................................................................................... 59
Cannot Communicate with the Product Using IPsec Communication ........................................... 59
Communication was Working, but Stopped ................................................................................... 59
Cannot Create the Secure IPP Printing Port.................................................................................. 60
4
Cannot Connect After Configuring IPsec/IP Filtering..................................................................... 60
Cannot Access the Product After Configuring IEEE 802.1X .......................................................... 60
Solving Digital Certificate Problems ................................................................................................... 60
Digital Certificate Warning Messages............................................................................................ 60
Cannot Import a Digital Certificate ................................................................................................. 62
Cannot Update a Certificate or Create a CSR ............................................................................... 62
Deleted a CA-signed Certificate .................................................................................................... 63
Where to Get Help.............................................................................................................................. 63
Notices ....................................................................................................................................................... 64
Trademarks ........................................................................................................................................ 64
Copyright Notice................................................................................................................................. 64
Copyright Attribution ...................................................................................................................... 65
5
Administrator's Guide
Welcome to the Administrator's Guide.
For a printable PDF copy of this guide, click here.
Note: Not all features mentioned in this Administrator's Guide are available with every product model.
You can use two software utilities to configure your product's advanced network settings: Web Config
and EpsonNet Config. This guide covers Web Config in detail; for information on using EpsonNet Config,
see the EpsonNet Config help utility.
The available network functions vary by product. (Unavailable functions are not displayed on the
product’s control panel or software settings screen.) Epson products support the following system
administration functions:
• SSL/TLS communication: use Secure Sockets Layer/Transport Layer Security to encrypt traffic and
avoid spoofing between the product and a computer
• IPsec/IP filtering: control access and secure communications between the product and a network
gateway
• Individual protocol control: enable and disable single services
• Remote configuration of scan and fax destinations: use an LDAP server to look up fax and email
contacts
• User feature restriction: allow or deny access to printing, scanning, faxing, and copying on a per user
basis
• Import and export printer settings: migrate settings from product to product
7
Using Web Config Network Configuration Software
Follow the instructions in these sections to configure your product's administrator network settings using
the Web Config software.
Note: Before you can configure system administration settings, you must connect the product to a
network. See the product's User's Guide for instructions.
Note: Before you can configure system administration settings, you must connect the product to a
network. See the product's User's Guide for instructions.
You can lock the settings you select by setting up an administrator password for your product. See the
product's User's Guide for instructions.
Parent topic: Using Web Config Network Configuration Software
8
• IPv6: http://[product IP address]/
The Status page appears:
4. To use HTTPS, configure your browser to use HTTPS for the address.
A message warning about the self-signed certificate appears.
To access Web Config after configuring HTTPS, enter https:// before the product IP address, shown in
step 3.
Note: If the product name is registered with the DNS server, you can use the product name instead of
the product IP address to access Web Config.
9
Parent topic: Using Web Config Network Configuration Software
10
3. If you have configured the product for an LDAP server or IEEE 802.1x network, you can deselect the
Allows printing and scanning without authentication information checkbox to prevent the
product from receiving jobs sent from these sources:
• The default operating system driver
• A PCL or PostScript printer driver
• Web services such as Epson Connect or Google Cloud Print
• Smartphones and other mobile devices
4. Click OK.
5. Select User Settings.
6. Click Add.
You see a window like this:
7. Enter a name for a user in the User Name field following the guidelines on the screen. Use ASCII
(0x20-0x7E) characters.
8. Enter a password for the user in the Password field following the guidelines on the screen.
Note: If you need to reset a password, leave the password field blank.
9. Select the checkbox for each function you want the user to be able to perform, and deselect the
checkbox for each function you want to restrict access to.
11
10. Click Apply.
Note: When you edit a completed user account, you see a Delete option. Click it to delete a user, if
necessary.
Note: You can import and export a list of user features using EpsonNet Config. See the help utility in the
software for instructions.
Note: See your product's User's Guide for instructions on setting an administrator password using the
control panel. If you forget your administrator password, contact Epson for support, as described in the
product's User's Guide.
12
3. Enter a user name, if necessary.
4. Do one of the following:
• If you have set an administrator password before, enter the current password, then enter and
confirm the new password in the fields provided.
• If you have not set an administrator password before, enter a new password and confirm it in the
fields provided.
5. Click OK.
Parent topic: Restricting Features Available for Users
13
2. Under SSL/TLS, select Basic.
You see a window like this:
14
You see a window like this:
15
Configuring an IPsec/IP Filtering Certificate
Parent topic: Using Your Product on a Secure Network
About IPsec/IP Filtering
You can filter traffic to the product over the network based on IP address, service, and port by
configuring a default policy that applies to every user or group connecting to the product. For control of
individual users or user groups, you can configure group policies.
Note: IPsec is supported only by computers running Windows Vista or later, or Windows Server 2008 or
later.
16
5. Click Next.
You see a confirmation message.
6. Click OK.
Parent topic: Configuring IPsec/IP Filtering
Configuring Group IPsec/IP Filtering Policies
You can configure group policies for IPsec/IP traffic filtering using Web Config.
1. Access Web Config and select the Network Security tab.
2. Under IPsec/IP Filtering, select Basic.
3. Click a tab number for the policy number you want to configure.
You see a window like this:
17
Parent topic: Configuring IPsec/IP Filtering
IPsec/IP Filtering Policy Settings
Setting Options/Description
Access Control Permit Access to permit IP packets to pass through
Refuse Access to prevent IP packets from passing
through
IPsec to permit IPsec packets to pass through
IKE Version Select the version of the Internet Key Exchange (IKE)
protocol that matches your network environment
Authentication Method Select an authentication method, or select Certificate if
you have imported a CA-signed certificate
Pre-Shared Key If necessary, enter a pre-shared key between 1 and 127
characters long
Confirm Pre-Shared Key Confirm the pre-shared key you entered
ID Type If you selected Pre-Shared Key as the Authentication
Method, select the ID type from the list.
ID If you selected IKEv2 as the IKE Version setting, enter
the necessary ID information
Encapsulation If you selected IPsec as the Access Control option,
select one of these encapsulation modes:
Transport Mode: if you are using the product on the
same LAN; IP packets of layer 4 or later are encrypted
Tunnel Mode: if you are using the product on an Internet-
capable network, such as IPsec-VPN; the header and
data of IP packets are encrypted
Remote Gateway(Tunnel Mode) If you selected Tunnel Mode as the Encapsulation
option, enter a gateway address between 1 and 39
characters long
18
Setting Options/Description
Security Protocol If you selected IPsec as the Access Control option,
select one of these security protocols:
ESP: to ensure the integrity of authentication and data,
and encrypt data
AH: to ensure the integrity of authentication and data; if
data encryption is prohibited, you can use IPsec
Algorithm Settings Select the encryption algorithm settings for the security
protocol you selected
Setting Options/Description
Access Control Permit Access to permit IP packets to pass through
Refuse Access to prevent IP packets from passing
through
IPsec to permit IPsec packets to pass through
Local Address(Printer) Select an IPv4 or IPv6 address that matches your network
environment; if the IP address is assigned automatically,
select Use auto-obtained IPv4 address
Remote Address(Host) Enter the device's IP address (between 0 and 43
characters long) to control access, or leave blank to
control all addresses; if the IP address is assigned
automatically, such as by DHCP, the connection may be
unavailable, so configure a static address instead
Method of Choosing Port Select the method you want to used for specifying ports
Service Name If you selected Service Name as the Method of
Choosing Port option, select a service name option here;
see the next table for more information
19
Setting Options/Description
Transport Protocol If you selected Port Number as the Method of Choosing
Port option, select one of these encapsulation modes:
Any Protocol
TCP
UDP
ICMPv4
See the Group Policy Guidelines table for more
information.
Local Port If you selected Port Number as the Method of Choosing
Port option, and TCP or UDP for the Transport Protocol
option, enter the port numbers that control receiving
packets (up to 10 ports), separated by commas, for
example 25,80,143,5220; leave this setting blank to
control all ports; see the next table for more information
Remote Port If you selected Port Number as the Method of Choosing
Port option, and TCP or UDP for the Transport Protocol
option, enter the port numbers that control sending
packets (up to 10 ports), separated by commas, for
example 25,80,143,5220; leave this setting blank to
control all ports; see the next table for more information
IKE Version Select IKEv1 or IKEv2 depending on the device that the
product is connected to
Authentication Method If you selected IPsec as the Access Control option,
select an authentication method here
Pre-Shared Key If you selected Pre-Shared Key as the Authentication
Method option, enter a pre-shared key between 1 and
127 characters long here and in the Confirm Pre-Shared
Key field
ID Type If you selected Pre-Shared Key as the Authentication
Method, select the ID type from the list
ID If you selected IKEv2 as the IKE Version setting, enter
the necessary ID information
20
Setting Options/Description
Encapsulation If you selected IPsec as the Access Control option,
select one of these encapsulation modes:
Transport Mode: if you are using the product on the
same LAN; IP packets of layer 4 or later are encrypted
Tunnel Mode: if you are using the product on an Internet-
capable network, such as IPsec-VPN; the header and
data of IP packets are encrypted
Remote Gateway(Tunnel Mode) If you selected Tunnel Mode as the Encapsulation
option, enter a gateway address between 1 and 39
characters long
Security Protocol If you selected IPsec as the Access Control option,
select one of these security protocols:
ESP: to ensure the integrity of authentication and data,
and encrypt data
AH: to ensure the integrity of authentication and data; if
data encryption is prohibited, you can use IPsec
Algorithm Settings Select the encryption algorithm settings for the security
protocol you selected
21
Service name Protocol type Local/Remote port Controls these operations
number
WSD TCP Any port/5357 Controlling WSD
WS-Discovery UDP 3702/Any port Searching for a product from WSD
Network Scan TCP 1865/Any port Forwarding scan data from
Document Capture Pro
Network Push Scan TCP Any port/2968 Acquiring job information on push
scanning from Document Capture
Pro
Network Push Scan UDP 2968/Any port Searching for a computer during
Discovery push scanning from Document
Capture Pro
FTP Data (Local) TCP 20/Any port Forwarding FTP printing data to FTP
server
FTP Control (Local) TCP 21/Any port Controlling FTP printing to FTP
server
FTP Data (Remote) TCP Any port/20 Forwarding scan data and received
fax data to FTP client; controls only
an FTP server that uses remote port
20
FTP Control TCP Any port/21 Forwarding scan data and received
(Remote) fax data to FTP client
CIFS (Local)* TCP 445/Any port Sharing a network folder on CIFS
server
CIFS (Remote)* TCP Any port/445 Forwarding scan data and received
fax data to a folder on CIFS server
NetBIOS Name UDP 137/Any port Sharing a network folder on CIFS
Service (Local) server
NetBIOS Datagram UDP 138/Any port
Service (Local)
NetBIOS Session TCP 139/Any port
Service (Local)
22
Service name Protocol type Local/Remote port Controls these operations
number
NetBIOS Name UDP Any port/137 Forwarding scan data and received
Service (Remote) fax data to a folder on CIFS server
NetBIOS Datagram UDP Any port/138
(Remote)
NetBIOS Session TCP Any port/139
Service (Remote)
HTTP (Local) TCP 80/Any port Forwarding Web Config and WSD
data to a HTTP or HTTPS server
HTTPS (Local) TCP 443/Any port
HTTP (Remote) TCP Any port/80 Communicating with Epson Connect,
Google Cloud Print, firmware update,
HTTPS (Remote) TCP Any port/443
and root certificate update on a
HTTP or HTTPS client
* To control forwarding of scan and received fax data, share a network folder, or receive fax data from
PC-Fax, select Port Number as the Method of Choosing Port option and specify the port numbers for
CIFS and NetBIOS.
Parent topic: Configuring IPsec/IP Filtering
IPsec/IP Filtering Configuration Examples
You can configure IPsec and IP filtering in a variety of ways, as shown in the examples here.
23
Default policy:
• IPsec/IP Filtering: Enable
• Access Control: Refuse Access
Group policy:
• Access Control: Permit Access
• Remote Address(Host): Client IP address
• Method of Choosing Port: Service Name
• Service Name: Select ENPC, SNMP, HTTP (Local), HTTPS (Local), and RAW (Port9100)
24
You see a window like this:
3. Click Import to add a new client certificate and enter any necessary settings.
4. Click OK.
Parent topic: Configuring IPsec/IP Filtering
Related tasks
Obtaining and Importing a CA-signed Certificate
25
You see a window like this:
2. Scroll down and select the Enable SNMPv3 checkbox to enable SNMPv3 settings.
3. Select the settings you want in SNMPv3 Settings section.
4. Click Next.
You see a confirmation message.
5. Click OK.
SNMPv3 Settings
Parent topic: Using Your Product on a Secure Network
SNMPv3 Settings
You can configure these SNMPv3 settings in Web Config.
Setting Options/Description
User Name Enter a user name from 1 to 32 characters long in
ASCII
Authentication Settings
Algorithm Select the algorithm for authentication
26
Setting Options/Description
Password Enter a password from 8 to 32 characters long in
ASCII
Confirm Password Enter the authentication password again
Encryption Settings
Algorithm Select the algorithm for encryption
Password Enter a password from 8 to 32 characters long in
ASCII
Confirm Password Enter the encryption password again
Context Name Enter a context name from 1 to 32 characters long
in ASCII
27
You see a window like this:
Note: You can share the network settings for Ethernet and Wi-Fi networking.
Setting Options/Description
Connection Method Displays the current network connection method
28
Setting Options/Description
EAP Type Select one of these authentication methods for connections
between the product and a RADIUS server:
EAP-TLS or PEAP-TLS: You must obtain and import a CA-
signed certificate
PEAP/MSCHAPv2: You must configure a password
User ID Enter an ID between 1 and 128 ASCII characters for
authentication on a RADIUS server
Password Enter a password between 1 and 128 ASCII characters for
authentication of the product. If you are using Windows as a
RADIUS server, enter up to 127 ASCII characters.
Confirm Password Enter the authentication password again
Server ID Enter a server ID between 1 and 128 ASCII characters for
authentication on a specified RADIUS server; server ID is
verified in the subject/subjectAltName field of a server
certificate sent from the RADIUS server
Certificate Validation Select a valid certificate regardless of the authentication
method; import the certificate using the CA Certificate option
Anonymous Name If you selected PEAP-TLS or PEAP/MSCHAPv2 as the
Authentication Method setting, you can configure an
anonymous name between 1 and 128 ASCII characters
instead of a user ID for phase 1 of a PEAP authentication
Encryption Strength Select one of the following encryption strengths:
High for AES256/3DES
Middle for AES256/3DES/AES128/RC4
29
You see a window like this:
30
Status ID Status description
User ID Error Authentication failed because the product's user ID and/or certificate
protocol is incorrect
Server ID Error Authentication failed because the server ID on the server certificate and
the server's ID do not match
Server Certificate Error Authentication failed because the server certificate is out of date or the
chain of the server certificate is incorrect
CA Certificate Error Authentication failed because the CA certificate is incorrect, not imported,
or out of date
EAP Failure Authentication failed because the client certificate is incorrect (EAP-TLS
or PEAP-TLS), or the user ID or password is incorrect
(PEAP/MSCHAPv2)
31
Parent topic: Using a Digital Certificate
Obtaining and Importing a CA-signed Certificate
You can obtain a CA-signed certificate by creating a CSR (Certificate Signing Request) using Web
Config and submitting it to a certificate authority. The CSR created in Web Config is in PEM/DER format.
You can import one CSR created from Web Config at a time.
1. Access Web Config and select the Network Security tab.
2. Under one of the following network security options, select the corresponding certificate:
• SSL/TLS and Certificate
• IPsec/IP Filtering and Client Certificate
• IEEE802.1X and Client Certificate
3. In the CSR section, select Generate.
You see a window like this:
32
7. In the CSR section, click the Download option that matches the format specified by your certificate
authority to download the CSR.
Caution: Do not generate another CSR or you may not be able to import a CA-signed certificate.
8. Submit the CSR to the certificate authority following the format guidelines provided by that authority.
9. Save the issued CA-signed certificate to a computer connected to the product.
Before proceeding, make sure the time and date settings are correct on your product. See the
product's User's Guide for instructions.
10. Select the Network Security tab again, and select your network security option and the
corresponding certificate.
11. In the CA-signed Certificate section, click Import.
You see a window like this:
12. Select the format of the certificate as the Server Certificate setting.
13. Select the certificate import settings as necessary for the format and the source from which you
obtained it.
14. Click OK.
You see a confirmation message.
15. Click Confirm to verify the certificate information.
33
Parent topic: Using a Digital Certificate
CSR Setup Settings
You can select these settings when setting up a CSR in Web Config.
Note: The available key length and abbreviations vary by certificate authority, so follow the rules of that
authority when entering information in the CSR.
Setting Options/Description
Key Length Select a key length for the CSR
Common Name Enter a name or static IP address from 1 to 128
characters long; for example, Reception printer
or https://10.152.12.225
Organization, Organizational Unit, Locality, Enter information in each field as necessary, from
State/Province 0 to 64 characters long in ASCII; separate any
multiple names with commas
Country Enter a two-digit country code number as specified
by the ISO-3166 standard
Note: The import setting requirements vary by certificate format and how you obtained the certificate.
34
Certificate format Setting descriptions
PKCS#12 format obtained from a computer Private Key: Do not configure
Password: Optional
CA Certificate 1/CA Certificate 2: Do not
configure
Note: If you obtained a CA-signed certificate from Web Config, you cannot import a deleted certificate;
you must obtain and import a new certificate.
35
You see a window like this:
4. Enter an identifier for your product from 1 to 128 characters long in the Common Name field.
5. Select a validity period for the certificate as the Certificate Validity (year) setting.
6. Click Next.
You see a completion message.
7. Click OK.
8. Click Confirm to verify the certificate information.
Parent topic: Using a Digital Certificate
36
Configuring the LDAP Server and Selecting Search Settings
You can configure the LDAP server and select search settings for it using Web Config.
1. Access Web Config and select the Network tab.
2. Under LDAP Server, select Basic.
You see a window like this:
37
You see a window like this:
Setting Options/Description
LDAP Server Address Enter the address of the LDAP server as necessary,
depending on the format of the server:
• IPv4 or IPv6 format: Enter from 1 to 255 characters
• FQDN format: Enter from 1 to 255 alphanumeric characters
in ASCII; you can use "-", except at the beginning or end of
the address
LDAP server Port Number Enter an LDAP server port number between 1 and 65535
Secure Connection Select the encryption method for connecting to the LDAP
server
38
Setting Options/Description
Certificate Validation Select Enable to validate the certificate when connecting to
the LDAP server
Search Timeout (sec) Enter a search time interval before timeout from between 5
and 300 seconds
Authentication Method Select one of the available authentication methods listed
Kerberos Realm to be Used If you selected Kerberos Authentication as the
Authentication Method option, select the correct realm of
Kerberos authentication from the realms defined under the
Kerberos Settings menu entry.
User Name Leave this blank or enter a user name for the LDAP server
from 0 to 128 characters long in Unicode (UTF-8); do not use
control characters such as 0x00-0x1F or OX7F (not available
when you selected Anonymous Authentication as the
Authentication Method option)
Password Leave this blank or enter a password from 1 to 128 characters
long in Unicode (UTF-8) for LDAP server authentication; do
not use control characters such as 0x00-0x1F or OX7F (not
available when you selected Anonymous Authentication as
the Authentication Method option)
Kerberos Settings
Realm (Domain) If you selected Kerberos Authentication as the
Authentication Method option, enter the realm of Kerberos
authentication from 0 to 255 characters long in ASCII; you can
define up to 10 realms with associated addresses and port
numbers
KDC Address Leave this blank or, if you selected Kerberos Authentication
as the Authentication Method option, enter the Kerberos
server address from 0 to 255 characters long in IPv4, IPv6, or
FQDN format
Port Number (Kerberos) Leave this blank or, if you selected Kerberos Authentication
as the Authentication Method option, enter the Kerberos
server port number between 1 and 65535
39
LDAP Search Settings
You can configure these LDAP search settings in Web Config.
Setting Options/Description
Search Base (Distinguished Name) Leave blank or search for an arbitrary domain name on the
LDAP server using 1 to 128 characters Unicode (UTF-8)
Number of search entries Specify the maximum number of search entries before an
error message appears, from 1 to 500
User name Attribute Enter the attribute name to display when searching for users
names from 1 to 255 characters long in Unicode (UTF-8); the
first character must be a-z, or A-Z
User name Display Attribute Leave blank or enter the attribute name to display as the user
name from 1 to 255 characters long in Unicode (UTF-8); the
first character must be a-z, or A-Z
Fax Number Attribute Enter the attribute name to display when searching for fax
numbers from 1 to 255 characters long using A-Z, a-z, 0-9,
and "-" in Unicode (UTF-8); the first character must be a-z, or
A-Z
Email Address Attribute Leave blank or enter the attribute name to display when
searching for email addresses from 1 to 255 characters long in
Unicode (UTF-8); the first character must be a-z, or A-Z
Arbitrary Attribute 1 through Leave blank or specify other arbitrary attributes to search for
Arbitrary Attribute 4 from 1 to 255 characters long in Unicode (UTF-8); the first
character must be a-z, or A-Z
40
LDAP Connection Report Messages
You can review the connection report messages to diagnose LDAP connection problems in Web Config.
Message Description
Connection test was successful. Connection to the server is successful
Connection test failed. Check the One of the following occurred:
settings.
• The LDAP server address or port number is incorrect
• A timeout occurred
• You selected Do Not Use as the Use LDAP Server setting
• If you selected Kerberos Authentication as the
Authentication Method setting, the Kerberos server
settings are incorrect
Connection test failed. Check the Connection failed because the time settings for the product
date and time on your printer or and the LDAP server do not match
server.
Authentication failed. Check the Authentication failed because the User Name and Password
settings. settings are incorrect or, if you selected Kerberos
Authentication as the Authentication Method setting, the
time and date are not configured correctly
Cannot access the printer until The product is busy
processing is complete.
41
Protocol Settings
Parent topic: Using Your Product on a Secure Network
Protocol Settings
Protocols
Name Description
Bonjour Bonjour is used to search for devices and AirPrint
SLP SLP is used for push-scanning and network searching in
EpsonNet Config
WSD Add WSD devices, or print and scan from the WSD port
LLTD Displays the product on the Windows network map
LLMNR Use name resolution without NetBIOS even if you cannot use
DNS
LPR Print from to the LPR port
RAW(Port9100) Print from the RAW port (Port 9100)
IPP Print over the Internet, including AirPrint
FTP Print over FTP
SNMPv1/v2c Remotely set up and monitor your product
SNMPv3 Remotely set up and monitor your product with the SNMPv3
protocol
Bonjour Settings
Setting Options/Description
Use Bonjour Search for or use devices through Bonjour (you cannot use
AirPrint if disabled)
Bonjour Name Displays the Bonjour name
Bonjour Service Name Displays the Bonjour service name
Location Displays the Bonjour location name
Top Priority Protocol Selects the protocol that is the top priority for Bonjour printing
42
Setting Options/Description
Wide-Area Bonjour Enables the Wide-Area Bonjour protocol; register all products
on the DNS server to locate them over the segment
SLP Settings
Setting Options/Description
Enable SLP Enable the SLP function to use the Push Scan function and
network searching in EpsonNet Config
WSD Settings
Setting Options/Description
Enable WSD Enable adding devices using WSD, and printing and scanning
from the WSD port
Printing Timeout (sec) Enter the communication timeout value for WSD printing
between 3 and 3,600 seconds
Scanning Timeout (sec) Enter the communication timeout value for WSD scanning
between 3 and 3,600 seconds
Device Name Displays the WSD device name
Location Displays the WSD location name
LLTD Settings
Setting Options/Description
Enable LLTD Enable LLTD to display the product in the Windows network
map
Device Name Displays the LLTD device name
LLMNR Settings
Setting Options/Description
Enable LLMNR Enable LLMNR to use name resolution without NetBIOS, even
if you cannot use DNS
43
LPR Settings
Setting Options/Description
Allow LPR Port Printing Allow printing from the LPR port
Printing Timeout (sec) Enter the timeout value for LPR printing between 0 and 3,600
seconds
Setting Options/Description
Allow RAW (Port9100) Printing Allow printing from the RAW port (Port 9100)
Printing Timeout (sec) Enter the timeout value for RAW (Port 9100) printing between
0 and 3,600 seconds
IPP Settings
Setting Options/Description
Enable IPP Enable IPP communication for products that support IPP are
displayed (you cannot use AirPrint if disabled)
Allow Non-secure Communication Allow the printer to communicate without any security
measures (IPP)
Communication Timeout (sec) Enter the timeout value for IPP printing between 0 and 3,600
seconds
URL(Network) Displays IPP URLs (http and https) when the product is
connected using wired LAN or Wi-Fi (the URL is a combined
value of the product’s IP address, Port number, and IPP
printer name)
URL(Wi-Fi Direct) Displays IPP URLs (http and https) when the product is
connected using Wi-Fi Direct (the URL is a combined value of
the product’s IP address, Port number, and IPP printer name)
Printer Name Displays the IPP printer name
Location Displays the IPP location
44
FTP Settings
Setting Options/Description
Enable FTP Server Enable FTP printing for products that support FTP printing
Communication Timeout (sec) Enter the timeout value for FTP communication between 0
and 3,600 seconds
SNMPv1/v2c Settings
Setting Options/Description
Enable SNMPv1/v2c Enable SNMPv1/v2c for products that support SNMPv3
Access Authority Set the access authority when SNMPv1/v2c is enabled to
Read Only or Read/Write
Community Name (Read Only) Enter 0 to 32 ASCII characters
Community Name (Read/Write) Enter 0 to 32 ASCII characters
SNMPv3 Settings
Setting Options/Description
Enable SNMPv3 Enable SNMPv3 for products that support SNMPv3
User Name Enter 1 to 32 characters
Authentication Settings Select an algorithm and set a password for authentication
Encryption Settings Select an algorithm and set a password for encryption
Context Name Enter 1 to 32 characters
45
Configuring an Email Server
Email Server Settings
Checking the Email Server Connection
Email Server Connection Report Messages
Configuring Email Notification
Parent topic: Using Your Product on a Secure Network
Configuring an Email Server
You can configure an email server using Web Config.
1. Access Web Config and select the Network tab.
2. Under Email Server, select Basic.
You see a window like this:
46
Setting Options/Description
Authentication Method Select the authentication method that matches your email
server
Authenticated Account Enter the authenticated account name from 1 to 255
characters long in ASCII
Authenticated Password Enter the authenticated password from 1 to 20 characters long
in ASCII using A-Z, a-z, 0-9, and these characters:
!#$%'*+-./=?^_{!}~@
Sender's Email Address Enter the sender's email address from 1 to 255 characters
long in ASCII; do not use a period (.) as the first character or
use these characters: ( ) < > [ ] ;
SMTP Server Address Enter the SMTP server address from 1 to 255 characters long
using A-Z, a-z, 0-9, and "-" in IPv4 or FQDN format
SMTP Server Port Number Enter the SMTP server port number between 1 and 65535
Secure Connection Select the security method for the email server; available
choices depend on the Authentication Method setting
Certificate Validation Enable checking for a valid certificate; recommended value is
Enable
POP3 Server Address Enter the POP server address from 1 to 255 characters long
using A-Z, a-z, 0-9, and "-" in IPv4 or FQDN format
POP3 Server Port Number Enter the POP server port number between 1 and 65535
47
Email Server Connection Report Messages
You can review the connection report messages to diagnose email server connection problems in Web
Config.
Message Description
Connection test was successful. Connection to the server is successful
SMTP server communication error. One of the following has occurred:
Check the following - Network
• Product is not connected to a network
Settings
• SMTP server is down
• Network connection is disrupted while communicating
• Received incomplete data
POP3 server communication error. One of the following has occurred:
Check the following - Network
• Product is not connected to a network
Settings
• POP3 server is down
• Network connection is disrupted while communicating
• Received incomplete data
An error occurred while connecting One of the following has occurred:
to SMTP server. Check the following
• DNS resolution failed
- SMTP Server Address - DNS Server
• Name resolution for an SMTP server failed
An error occurred while connecting One of the following has occurred:
to POP3 server. Check the following
• DNS resolution failed
- POP3 Server Address - DNS Server
• Name resolution for a POP3 server failed
SMTP server authentication error. SMTP server authentication failed
Check the following - Authentication
Method - Authenticated Account -
Authenticated Password
POP3 server authentication error. POP3 server authentication failed
Check the following - Authentication
Method - Authenticated Account -
Authenticated Password
48
Message Description
Unsupported communication The communication protocol is unsupported
method. Check the following - SMTP
Server Address - SMTP Server Port
Number
Connection to SMTP server failed. There is an SMTP mismatch between a server and a client, or
Change Secure Connection to None. when the server does not support an SMTP secure connection
Connection to SMTP server failed. There is an SMTP mismatch between a server and a client, or
Change Secure Connection to the server requests an SSL/TLS connection for SMTP
SSL/TLS.
Connection to SMTP server failed. There is an SMTP mismatch between a server and a client, or
Change Secure Connection to when the server requests a STARTTLS connection for SMTP
STARTTLS.
The connection is untrusted. Check The product’s date and time setting is incorrect or the
the following - Date and Time certificate has expired
The connection is untrusted. Check The product has a root certificate mismatch or a CA Certificate
the following - CA Certificate has not been imported
The connection is not secured. The certificate is damaged
SMTP server authentication failed. Authentication method mismatch between a server and a
Change Authentication Method to client. The server does not support SMTP AUTH.
SMTP-AUTH.
SMTP server authentication failed. Authentication method mismatch between a server and a
Change Authentication Method to client. The server does not support SMTP AUTH.
POP before SMTP.
Sender's Email Address is incorrect. The specified sender’s Email address is wrong
Change to the email address for
your email service.
Cannot access the printer until The product is busy
processing is complete.
49
Configuring Email Notification
You can configure email notifications using Web Config so you can receive alerts by email when certain
events occur on the product, such as running out of paper. You can register up to 5 email addresses and
select the events for which you want to be notified.
1. Access Web Config and select the Device Management tab.
You see a window like this:
50
Using EpsonNet Config Network Configuration Software
Follow the instructions in these sections to configure your product's administrator network settings using
the EpsonNet Config software.
With Windows, you can configure network settings in a batch operation. See the EpsonNet Config help
utility for instructions.
Note: Before you can configure system administration settings, connect the product to a network. See
the product's Start Here sheet and User's Guide for instructions.
• Windows (other versions): Click or Start and select All Programs or Programs. Select
EpsonNet > EpsonNet Config.
• Mac: Open the Applications folder, open the Epson Software folder, and select EpsonNet >
EpsonNet Config > EpsonNet Config.
After a few moments, the program displays the connected products.
51
4. Double-click the product you are configuring.
Note: If several products of the same model are connected, you can identify them by their MAC
address.
6. Select Manual.
7. Enter the product's IP address, Subnet Mask, and Default Gateway settings in the fields provided.
Note: To connect the product to a secure network, enter a static IP address. You can also configure
the DNS settings by selecting DNS, and enter proxy settings by selecting Internet from the TCP/IP
menu.
8. Select Send.
9. Enter the current administrator password if necessary, and click OK.
Parent topic: Using EpsonNet Config Network Configuration Software
52
Using Epson Device Admin Configuration Software
With Windows, you can discover and monitor remote devices, and configure network settings in a batch
operation. See the Epson Device Admin help for instructions.
To install Epson Device Admin, download the software from the support page at epson.com/support
(U.S.), epson.ca/support (Canada), or epson.com.jm/support (Caribbean) and follow the on-screen
instructions.
53
Solving Problems
Check these sections for solutions to problems you may have with the network configuration software.
Scanning Error Messages
Solving Network Software Usage Problems
Solving Network Security Problems
Solving Digital Certificate Problems
Where to Get Help
54
Message Solution
DNS error. Check DNS settings. Try the following:
• Make sure the address in the contacts list on the
printer and the address of the shared folder are
the same.
• If the computer's IP address is static or set
manually, change the computer name in the
network path to the IP address. For example,
change \\EPSON02\SCAN to
\\192.168.xxx.xxx\SCAN.
• Make sure your computer is turned on and not
running in a power-saving mode, such as sleep
or standby. If your computer is in sleep mode,
you cannot save scanned images to the shared
folder.
• Temporarily disable your computer's firewall and
security software. If this clears the error, check
the settings in the security software.
• If you are using a laptop computer and the IP
address is set as DHCP, the IP address may
change when reconnecting to the network.
Obtain the IP address again.
• Check the printer's DNS settings using the
product's control panel.
• Check the DNS settings for the server,
computer, or access point.
• The computer name and the IP address may
differ when the management table of the DNS
server is not updated. Check the computer
name and the IP address.
55
Message Solution
Authentication error. Check the authentication Try the following:
method, authenticated account, and authenticated
• If user restrictions have been enabled, make
password
sure you enter in the correct user name and
password. Also, make sure that the password
has not expired.
• Check the Location settings.
Communication error. Check the Wi-Fi/network Try the following:
connection.
• Make sure MS Network is enabled.
• Make sure the address in the contacts list on the
printer and the address of the shared folder are
the same.
• Access rights for the user in the contacts list
should be added to the Sharing and Security
tabs of the shared folder's properties. Access
permissions should also be enabled for the user.
• Check the Location settings.
• Print a network connection report to check if the
printer is connected to the network.
The file name is already in use. Rename the file Check if there is a file with the same name as the
and scan again. file you want to save in the shared folder. Delete
the saved file or select a different file name.
Scanned file(s) are too large. Only XX page(s) Try the following:
have been sent. Check if the destination has
• Increase the storage space in the specified
enough space.
folder.
• Reduce the number of documents.
• Lower the scanning resolution or increase the
compression ratio to reduce the size of the
scanned image.
56
Solving Network Software Usage Problems
Check these sections if you have problems using the network software.
Cannot Access Web Config
The "Out of Date" Message Appears
"The name of the security certificate does not match" Message Appears
Model Name or IP Address Not Displayed in EpsonNet Config
Parent topic: Solving Problems
• Windows (other versions): Click or Start and select Control Panel > Network and Internet >
Internet Options > Connections > LAN settings > Proxy server > Bypass proxy server for
local addresses.
• Mac: Select System Preferences > Network > Advanced > Proxies. Register the local address
under Bypass proxy settings for these Hosts & Domains. For example, 192.168.1.*: Local
address 192.168.1.XXX, subnet mask 255.255.255.0.
Parent topic: Solving Network Software Usage Problems
57
The "Out of Date" Message Appears
If the "Out of Date" message appears when you access Web Config using SSL communication (HTTPS),
the certificate is out of date. Make sure that the product date and time are configured correctly, and
obtain a new certificate.
Parent topic: Solving Network Software Usage Problems
"The name of the security certificate does not match" Message Appears
If a message beginning with "The name of the security certificate does not match . . ." appears when you
access Web Config using SSL communication (HTTPS), the product's IP address on the CSR or self-
signed certificate does not match what you entered in the browser. Change the IP address you entered
for the Common Name setting, and obtain and import a certificate again, or change the product name.
Parent topic: Solving Network Software Usage Problems
58
Pre-Shared Key was Forgotten
If you forget a pre-shared key, change the key using Web Config for the default or group policy.
Parent topic: Solving Network Security Problems
59
• If that does not solve the problem, enter a static IP address using Web Config.
Parent topic: Solving Network Security Problems
60
Message Solution
Enter a Server Certificate. Select a certificate file and click Import.
CA Certificate 1 is not entered. Import CA certificate 1 before importing additional
certificates.
Invalid value below. Remove any unsupported characters in the file
path and password.
Invalid date and time. Set the date and time on the product using Web
Config, EpsonNet Config, or the product control
panel.
Invalid password Enter the password that matches the password set
for the CA certificate.
Invalid file Try the following:
• Import only certificate files in X509 format sent
by a trusted certificate authority.
• Make sure the file size is 5KB or less and is not
corrupted or fabricated.
• Make sure the chain in the certificate is valid;
check the certificate authority's website.
Cannot use the Server Certificates that include Import certificate files in PKCS#12 format that
more than three CA certificates. contains one or two CA certificates, or convert
each certificate to PRM format and import them
again.
The certificate has expired. Check if the certificate Make sure the product time and date are set
is valid, or check the date and time on your printer. correctly and, if the certificate is out of date, obtain
and import a new certificate.
61
Message Solution
Private key is required. Do one of the following to pair a private key with
the certificate:
• For PEM/DER format certificates obtained from
a CSR using a computer, specify the private key
file.
• For PKCS#12 format certificates obtained from
a CSR using a computer, create a file containing
the private key.
If you re-imported a PEM/DER format certificate
obtained from a CSR using Web Config, you can
only import it once. You must obtain and import a
new certificate.
Setup failed. Make sure the computer and product are
connected, and the certificate file is not corrupted,
then import the certificate file again.
62
Parent topic: Solving Digital Certificate Problems
Internet Support
Visit Epson's support website at epson.com/support (U.S.), epson.ca/support (Canada), or
epson.com.jm/support (Caribbean) and select your product for solutions to common problems. You can
download drivers and documentation, get FAQs and troubleshooting advice, or e-mail Epson with your
questions.
63
Notices
Check these sections for important notices.
Trademarks
Copyright Notice
Trademarks
EPSON® is a registered trademark and EPSON Exceed Your Vision is a registered logomark of Seiko
Epson Corporation.
Mac is a trademark of Apple Inc., registered in the U.S. and other countries.
Google Cloud Print TM is a trademark of Google LLC.
General Notice: Other product names used herein are for identification purposes only and may be
trademarks of their respective owners. Epson disclaims any and all rights in those marks.
Copyright Notice
All rights reserved. No part of this publication may be reproduced, stored in a retrieval system, or
transmitted in any form or by any means, electronic, mechanical, photocopying, recording, or otherwise,
without the prior written permission of Seiko Epson Corporation. The information contained herein is
designed only for use with this Epson product. Epson is not responsible for any use of this information as
applied to other products.
Neither Seiko Epson Corporation nor its affiliates shall be liable to the purchaser of this product or third
parties for damages, losses, costs, or expenses incurred by purchaser or third parties as a result of:
accident, misuse, or abuse of this product or unauthorized modifications, repairs, or alterations to this
product, or (excluding the U.S.) failure to strictly comply with Seiko Epson Corporation's operating and
maintenance instructions.
Seiko Epson Corporation shall not be liable for any damages or problems arising from the use of any
options or any consumable products other than those designated as Original Epson Products or Epson
Approved Products by Seiko Epson Corporation.
64
Seiko Epson Corporation shall not be held liable for any damage resulting from electromagnetic
interference that occurs from the use of any interface cables other than those designated as Epson
approved Products by Seiko Epson Corporation.
This information is subject to change without notice.
Copyright Attribution
Parent topic: Notices
Copyright Attribution
© 2018 Epson America, Inc.
10/18
CPD-55258R1
Parent topic: Copyright Notice
65