User`s manual
VIVOTEK
User's Manual - 39
IEEE802.1x
Advanced Mode
Enable thisfunction ifyournetwork environment uses IEEE802.1x, which isa portbased network
access control. The network devices, intermediary switch/access point/hub, and RADIUS server must
supportandenable802.1xsettings.
The 802.1x standard is designedtoenhancethe security oflocalarea networks, which provides
authenticationtonetworkdevices(clients)attachedtoanetworkport(wiredorwireless).Ifallcerticates
betweenclientandserverareveried,apointtopointconnectionwillbeenabledifauthenticationfails,
accessonthatportwillbeprohibited.802.1xutilizesanexistingprotocol,theExtensibleAuthentication
Protocol (EAP), to facilitate communication.
■
Thecomponentsofaprotectednetworkwith802.1xauthentication:
1.
Supplicant: A client end user (camera), which requests authentication.
2.
Authenticator (an access point or a switch): A “go between” which restricts unauthorized end users
from communicating with the authentication server.
3.
Authenticationserver(usuallyaRADIUSserver):Checkstheclientcerticateanddecideswhetherto
accept the end user’s access request.
■
VIVOTEK Network Cameras support two types of EAP methods to perform authentication: EAP-PEAP
and EAP-TLS.
Pleasefollowthestepsbelowtoenable802.1xsettings:
1.BeforeconnectingtheNetworkCameratotheprotectednetworkwith802.1x,pleaseapplyadigital
certicatefromaCerticateAuthority(ie.MISofyourcompany)whichcanbevalidatedbyaRADIUS
server.
2. Connect the Network Camera to a PC or notebook outside of the protected LAN. Open the
congurationpageoftheNetworkCameraasshownbelow.SelectEAP-PEAP or EAP-TLS as the
EAP method. In the following blanks, enter your ID and password issued by the CA, then upload
relatedcerticate(s).
Authenticator
(Network Switch)
Authentication Server
(RADIUS Server)
Supplicant
(Network Camera)










