AXISM32-LVENetworkCameraSeries
Thedeviceinterface
Whenusingacertificate,inAxis'implementation,thedeviceandtheauthenticationserverauthenticate
themselveswithdigitalcertificatesusingEAP-TLS(ExtensibleAuthenticationProtocol-Transport
LayerSecurity).
Toallowthedevicetoaccessanetworkprotectedthroughcertificates,asignedclientcertificatemust
beinstalledonthedevice.
Clientcertificate:SelectaclientcertificatetouseIEEE802.1x.Theauthenticationserverusesthe
certificatetovalidatetheclient’sidentity.
CAcertificate:SelectaCAcertificatetovalidatetheauthenticationserver’sidentity.Whenno
certificateisselected,thedevicetriestoauthenticateitselfregardlessofwhatnetworkitisconnectedto.
EAPidentity:Entertheuseridentityassociatedwiththeclientcertificate.
EAPOLversion:SelecttheEAPOLversionthatisusedinthenetworkswitch.
UseIEEE802.1x:SelecttousetheIEEE802.1xprotocol.
Preventbrute-forceattacks
Blocking:Turnontoblockbrute-forceattacks.Abrute-forceattackusestrial-and-errortoguess
logininfoorencryptionkeys.
Blockingperiod:Enterthenumberofsecondstoblockabrute-forceattack.
Blockingconditions:Enterthenumberofauthenticationfailuresallowedpersecondbeforetheblock
starts.Youcansetthenumberoffailuresallowedbothonpagelevelanddevicelevel.
IPaddressfilter
Usefilter:SelecttofilterwhichIPaddressesthatareallowedtoaccessthedevice.
Policy:ChoosewhethertoAllowaccessorDenyaccessforcertainIPaddresses.
Addresses:EntertheIPnumbersthatareeitherallowedordeniedaccesstothedevice.Youcanalso
usetheCIDRformat.
Custom-signedfirmwarecertificate
ToinstalltestfirmwareorothercustomfirmwarefromAxisonthedevice,youneedacustom-signed
firmwarecertificate.Thecertificateverifiesthatthefirmwareisapprovedbyboththedeviceowner
andAxis.Thefirmwarecanonlyrunonaspecificdevicewhichisidentifiedbyitsuniqueserial
numberandchipID.Custom-signedfirmwarecertificatescanonlybecreatedbyAxis,sinceAxis
holdsthekeytosignthem.
ClickInstalltoinstallthecertificate.Youneedtoinstallthecertificatebeforeyouinstallthefirmware.
41