AXISP3265-VDomeCamera
Thewebinterface
Authenticationmethod:SelectanEAPtypeusedforauthentication.ThedefaultoptionisEAP-TLS.EAP-PEAP/MSCHAPv2isa
moresecureoption.
Clientcerticate:SelectaclientcerticatetouseIEEE802.1x.Theauthenticationserverusesthecerticatetovalidatethe
client’sidentity.
CAcerticate:SelectCAcerticatestovalidatetheauthenticationserver’sidentity.Whennocerticateisselected,thedevice
triestoauthenticateitselfregardlessofwhatnetworkitisconnectedto.
EAPidentity:Entertheuseridentityassociatedwiththeclientcerticate.
EAPOLversion:SelecttheEAPOLversionthatisusedinthenetworkswitch.
UseIEEE802.1x:SelecttousetheIEEE802.1xprotocol.
IEEE802.1AEMACsec
IEEE802.1AEMACsecisanIEEEstandardformediaaccesscontrol(MAC)securitythatdenesconnectionlessdatacondentiality
andintegrityformediaaccessindependentprotocols.
ThesettingsareonlyavailableifyouuseEAP-TLSastheauthenticationmethod:
Mode
•DynamicCAK/EAP-TLS:Thedefaultoption.Afterasecuredconnection,thedevicechecksforMACseconthenetwork.
•StaticCAK/pre-sharedkey(PSK):Selecttosetthekeynameandvaluetoconnecttothenetwork.
ThesettingsareonlyavailableifyouuseEAP-PEAP/MSCHAPv2astheauthenticationmethod:
•Password:Enterthepasswordforyouruseridentity.
•Peapversion:SelectthePeapversionthatisusedinthenetworkswitch.
•Label:Select1touseclientEAPencryption;select2touseclientPEAPencryption.SelecttheLabelthatthenetwork
switchuseswhenusingPeapversion1.
Preventbrute-forceattacks
Blocking:Turnontoblockbrute-forceattacks.Abrute-forceattackusestrial-and-errortoguesslogininfoorencryptionkeys.
Blockingperiod:Enterthenumberofsecondstoblockabrute-forceattack.
Blockingconditions:Enterthenumberofauthenticationfailuresallowedpersecondbeforetheblockstarts.Youcansetthe
numberoffailuresallowedbothonpagelevelanddevicelevel.
Firewall
Activate:Turnontherewall.
DefaultPolicy:Selectthedefaultstatefortherewall.
•Allow:Allowsallconnectionstothedevice.Thisoptionissetbydefault.
•Deny:Deniesallconnectionstothedevice.
Tomakeexceptionstothedefaultpolicy,youcancreaterulesthatallowsordeniesconnectionstothedevicefromspecic
addresses,protocols,andports.
•Address:EnteranaddressinIPv4/IPv6orCIDRformatthatyouwanttoallowordenyaccessto.
•Protocol:Selectaprotocolthatyouwanttoallowordenyaccessto.
•Port:Enteraportnumberthatyouwanttoallowordenyaccessto.Youcanaddaportnumberbetween1and65535.
•Policy:Selectthepolicyoftherule.
:Clicktocreateanotherrule.
Addrules:Clicktoaddtherulesthatyouhavedened.
37