Securing your store network
If your receipt printer is a network printer (reached through a print agent rather than plugged into one computer — see Receipt printers & devices), it talks to Swann Retail over a printer port that has no password. That’s normal for thermal printers — but it means any device on the same network can send the printer commands, including popping the cash drawer. So the printer can’t protect itself; the network has to, by keeping the printer reachable only from the one machine that runs your print agent.
This page is for whoever sets up your store network — you, your IT person, or your installer. It’s the checklist for a store that already has a network (you’re keeping your existing router and Wi-Fi). A brand-new store gets a router pre-configured by Swann instead, so these steps are already done for you — ask us about the setup kit. New to how the pieces fit together? Start with Setting up your store network, then come back here to lock it down.
You only need this if you run a network printer. A USB printer plugged straight into the register isn’t on the network at all, so there’s nothing here to do.
The five-point checklist
Section titled “The five-point checklist”Work through these once, on-site, when you set the store up. They reinforce each other — do all five.
-
Put the POS gear on its own network. Your register tablets, the print agent’s computer, and the printers go on a dedicated segment (a POS VLAN), separate from back-office computers and anything guests use. Keep traffic between devices on that segment limited to what the register actually needs.
-
Lock the printer port to the print agent only. On the router/firewall, allow the printer’s port 9100 to be reached only from the computer running the print agent — that machine is the single device that’s allowed to print. Block every other source. This is the step that stops a random phone or laptop on the network from popping your drawer.
-
Keep guest Wi-Fi separate. If you offer customer Wi-Fi, put it on its own network/SSID with client isolation so guest devices can’t see your printers, tablets, or back office at all. (This is also what card networks expect of a store that takes cards.)
-
Harden each printer. On every network printer: change the default admin password, require a login on the printer’s web/admin page, turn off services you don’t use, and restrict or disable SNMP. A printer left on factory defaults is the easy way back in even after the steps above.
-
Verify it. From a device that is not the print agent’s computer — a phone on the POS Wi-Fi, a back-office PC — confirm you cannot reach the printer on port 9100. If that device can still reach it, step 1 or 2 isn’t doing its job yet. The only thing that should be able to print is the print agent.
Future hardening
Section titled “Future hardening”Some newer printers support printing over an encrypted, authenticated connection (IPP over TLS). Where a printer offers it, prefer it — it adds a password and encryption on top of the network segmentation above. Not all thermal printers support it, so the five-point checklist is the baseline either way.
Why this matters
Section titled “Why this matters”The printer port is unauthenticated by design — that’s how every network thermal printer works, not a Swann limitation. We can’t put a password on it without breaking standard printers, so the protection lives in the network. Done right, only your register can talk to your printer and cash drawer; done loosely, anyone within reach of the same network can. The checklist above is the difference.