Руководство По Обслуживанию для Cisco Cisco TelePresence MX700

Скачать
Страница из 141
D15119.02 MX700 and MX800 Administrator Guide TC7.2, AUGUST 2014.  
www.cisco.com — Copyright © 2014 Cisco Systems, Inc. All rights reserved. 
83
Cisco TelePresence MX700 and MX800 
Administrator Guide
Network [1..1] IEEE8021X TlsVerify
Verification of the server-side certificate of an IEEE802.1x connection against the certificates in 
the local CA-list when TLS is used. The CA-list must be uploaded to the video system. This can 
be done from the web interface.
This setting takes effect only when Network [1..1] IEEE8021X Eap Tls is enabled (On).
Requires user role: ADMIN
Value space: <Off/On>
Off: When set to Off, TLS connections are allowed without verifying the server-side X.509 
certificate against the local CA-list. This should typically be selected if no CA-list has been 
uploaded to the codec.
On: When set to On, the server-side X.509 certificate will be validated against the local CA-
list for all TLS connections. Only servers with a valid certificate will be allowed.
Example:
 Network 1 IEEE8021X TlsVerify: Off
Network [1..1] IEEE8021X UseClientCertificate
Authentication using a private key/certificate pair during an IEEE802.1x connection. The 
authentication X.509 certificate must be uploaded to the video system. This can be done from 
the web interface.
Requires user role: ADMIN
Value space: <Off/On>
Off: When set to Off client-side authentication is not used (only server-side).
On: When set to On the client (video system) will perform a mutual authentication TLS 
handshake with the server.
Example:
 Network 1 IEEE8021X UseClientCertificate: Off
Network [1..1] IEEE8021X Identity
The 802.1X Identity is the user name needed for 802.1X authentication.
Requires user role: ADMIN
Value space: <S: 0, 64>
Format: String with a maximum of 64 characters. 
Example:
 Network 1 IEEE8021X Identity: ""
Network [1..1] IEEE8021X Password
The 802.1X Password is the password needed for 802.1X authentication.
Requires user role: ADMIN
Value space: <S: 0, 32>
Format: String with a maximum of 32 characters.
Example:
 Network 1 IEEE8021X Password: ""
Network [1..1] IEEE8021X AnonymousIdentity
The 802.1X Anonymous ID string is to be used as unencrypted identity with EAP (Extensible 
Authentication Protocol) types that support different tunneled identity, like EAP-PEAP and EAP-
TTLS. If set, the anonymous ID will be used for the initial (unencrypted) EAP Identity Request.
Requires user role: ADMIN
Value space: <S: 0, 64>
Format: String with a maximum of 64 characters.
Example:
 Network 1 IEEE8021X AnonymousIdentity: ""
Network [1..1] IEEE8021X Eap Md5
Set the Md5 (Message-Digest Algorithm 5) mode. This is a Challenge Handshake 
Authentication Protocol that relies on a shared secret. Md5 is a Weak security.
Requires user role: ADMIN
Value space: <Off/On>
Off: The EAP-MD5 protocol is disabled.
On: The EAP-MD5 protocol is enabled (default).
Example:
 Network 1 IEEE8021X Eap Md5: On
Contents
Introduction
Web interface
System settings
Setting passwords
Appendices
System settings