Axis A1214 Network Door Controller Kit

User Manual - Page 17

For A1214.

PDF File Manual, 34 pages, Read Online | Download pdf file

A1214 photo
Loading ...
Loading ...
Loading ...
AXISA1214NetworkDoorControllerKit
Thewebinterface
Securekeystore:
Secureelement(CCEAL6+):Selecttousesecureelementforsecurekeystore.
TrustedPlatformModule2.0(CCEAL4+,FIPS140-2Level2):SelecttouseTPM2.0forsecurekeystore.
IEEE802.1x
IEEE802.1xisanIEEEstandardforport-basednetworkadmissioncontrolprovidingsecureauthenticationofwiredandwireless
networkdevices.IEEE802.1xisbasedonEAP(ExtensibleAuthenticationProtocol).
ToaccessanetworkprotectedbyIEEE802.1x,networkdevicesmustauthenticatethemselves.Theauthenticationisperformedby
anauthenticationserver,typicallyaRADIUSserver(forexample,FreeRADIUSandMicrosoftInternetAuthenticationServer).
Certicates
WhenconguredwithoutaCAcerticate,servercerticatevalidationisdisabledandthedevicetriestoauthenticateitself
regardlessofwhatnetworkitisconnectedto.
Whenusingacerticate,inAxis'implementation,thedeviceandtheauthenticationserverauthenticatethemselveswithdigital
certicatesusingEAP-TLS(ExtensibleAuthenticationProtocol-TransportLayerSecurity).
Toallowthedevicetoaccessanetworkprotectedthroughcerticates,youmustinstallasignedclientcerticateonthedevice.
Clientcerticate:SelectaclientcerticatetouseIEEE802.1x.Theauthenticationserverusesthecerticatetovalidatethe
client’sidentity.
CAcerticate:SelectCAcerticatestovalidatetheauthenticationserver’sidentity.Whennocerticateisselected,thedevice
triestoauthenticateitselfregardlessofwhatnetworkitisconnectedto.
EAPidentity:Entertheuseridentityassociatedwiththeclientcerticate.
EAPOLversion:SelecttheEAPOLversionthatisusedinthenetworkswitch.
UseIEEE802.1x:SelecttousetheIEEE802.1xprotocol.
Preventbrute-forceattacks
Blocking:Turnontoblockbrute-forceattacks.Abrute-forceattackusestrial-and-errortoguesslogininfoorencryptionkeys.
Blockingperiod:Enterthenumberofsecondstoblockabrute-forceattack.
Blockingconditions:Enterthenumberofauthenticationfailuresallowedpersecondbeforetheblockstarts.Youcansetthe
numberoffailuresallowedbothonpagelevelanddevicelevel.
IPaddresslter
Uselter:SelecttolterwhichIPaddressesareallowedtoaccessthedevice.
Policy:ChoosewhethertoAlloworDenyaccessforcertainIPaddresses.
Addresses:EntertheIPnumbersthatareeitherallowedordeniedaccesstothedevice.YoucanalsousetheCIDRformat.
Custom-signedrmwarecerticate
ToinstalltestrmwareorothercustomrmwarefromAxisonthedevice,youneedacustom-signedrmwarecerticate.The
certicateveriesthatthermwareisapprovedbyboththedeviceownerandAxis.Thermwarecanonlyrunonaspecic
devicewhichisidentiedbyitsuniqueserialnumberandchipID.OnlyAxiscancreatecustom-signedrmwarecerticates,
sinceAxisholdsthekeytosignthem.
Install:Clicktoinstallthecerticate.Youneedtoinstallthecerticatebeforeyouinstallthermware.
17
Loading ...
Loading ...
Loading ...