AXISM32-LVENetworkCameraSeries
Thedeviceinterface
Thecontextmenucontains:
•Certicate Certicate
Certicate
information information
information
:Viewaninstalledcerticateʼsproperties.
•Delete Delete
Delete
certicate certicate
certicate
:Deletethecerticate.
•Create Create
Create
certicate certicate
certicate
signing signing
signing
request request
request
:Createacerticatesigningrequesttosendtoaregistrationauthority
toapplyforadigitalidentitycerticate.
IEEE IEEE
IEEE
802.1x 802.1x
802.1x
IEEE802.1xisanIEEEstandardforport-basednetworkadmissioncontrolprovidingsecureauthenticationofwired
andwirelessnetworkdevices.IEEE802.1xisbasedonEAP(ExtensibleAuthenticationProtocol).
ToaccessanetworkprotectedbyIEEE802.1x,networkdevicesmustauthenticatethemselves.Theauthenticationis
performedbyanauthenticationserver,typicallyaRADIUSserver(forexampleFreeRADIUSandMicrosoftInternet
AuthenticationServer).
Certicates Certicates
Certicates
WhenconguredwithoutaCAcerticate,servercerticatevalidationisdisabledandthedevicetriesto
authenticateitselfregardlessofwhatnetworkitisconnectedto.
Whenusingacerticate,inAxis'implementation,thedeviceandtheauthenticationserverauthenticatethemselves
withdigitalcerticatesusingEAP-TLS(ExtensibleAuthenticationProtocol-TransportLayerSecurity).
Toallowthedevicetoaccessanetworkprotectedthroughcerticates,asignedclientcerticatemustbeinstalled
onthedevice.
Client Client
Client
certicate certicate
certicate
:SelectaclientcerticatetouseIEEE802.1x.Theauthenticationserverusesthecerticate
tovalidatetheclientʼsidentity.
CA CA
CA
certicate certicate
certicate
:SelectaCAcerticatetovalidatetheauthenticationserverʼsidentity.Whennocerticateisselected,
thedevicetriestoauthenticateitselfregardlessofwhatnetworkitisconnectedto.
EAP EAP
EAP
identity identity
identity
:Entertheuseridentityassociatedwiththeclientcerticate.
EAPOL EAPOL
EAPOL
version version
version
:SelecttheEAPOLversionthatisusedinthenetworkswitch.
Use Use
Use
IEEE IEEE
IEEE
802.1x 802.1x
802.1x
:SelecttousetheIEEE802.1xprotocol.
Prevent Prevent
Prevent
brute brute
brute
- -
-
force force
force
attacks attacks
attacks
Blocking Blocking
Blocking
:Turnontoblockbrute-forceattacks.Abrute-forceattackusestrial-and-errortoguesslogininfo
orencryptionkeys.
Blocking Blocking
Blocking
period period
period
:Enterthenumberofsecondstoblockabrute-forceattack.
Blocking Blocking
Blocking
conditions conditions
conditions
:Enterthenumberofauthenticationfailuresallowedpersecondbeforetheblockstarts.You
cansetthenumberoffailuresallowedbothonpagelevelanddevicelevel.
IP IP
IP
address address
address
lter lter
lter
41