Previous Page Go Index Next Page

IEEE802.1X Authentication


This page explains how to configure the settings to use IEEE802.1X authentication.


1. Supported 802.1X Authentication Methods

2. Standard and Saving Format for Certificate

3. IEEE 802.1X Settings


1. Supported 802.1X Authentication Methods

DS-600 supports the following IEEE802.1X authentication methods.

PEAP(PEAPv0)
EAP-TLS
EAP-TTLS


2. Standard and Saving Format for Certificate

Standard for Certificate

DS-600 supports the standard of certificate as follows:

Key exchange method RSA
Key size 512bit, 1024bit, 2048bit
Signature algorithm SHA1withRSA
MD5withRSA

Saving Format for Certificate

DS-600 supports the saving format of certificate as follows:

Client certificate PKCS#12
PFX
CA certificate for server authentication DER (Binary encoded X509)
PEM (BASE64-encoded text format of DER)


3. IEEE 802.1X Settings

Access the Web page of DS-600.


The login page is displayed.
Enter the password for DS-600 and click Login.

  • By default, no password is configured to DS-600.

The Web page of DS-600 is displayed.
From the left menu on the Web page, click Security - IEEE 802.1X.


The IEEE 802.1X Configuration page is displayed.
Configure each setting and click Submit.

IEEE 802.1X Enable/Disable the IEEE 802.1X authentication. DISABLE
Authentication Method Set the IEEE 802.1X authentication method (EAP-TLS / EAP-TTLS / PEAP). EAP-TLS
EAP User Name Set an EAP user name for the IEEE 802.1X authentication. This name is used by the server to identify a client. NONE
EAP Password Set an EAP password for the IEEE 802.1X authentication.
This password is used to check client reliability when EAP-TTLS or PEAP is used as authentication method.
NONE
Inner Authentication Method Set the inner authentication method (PAP/CHAP/MSCHAP/MSCHAPv2) to perform in TLS tunneling of the IEEE 802.1X authentication.
When PEAP is used as authentication method, this is fixed to MS-CHAPv2.
MSCHAPv2
Client Certification Select a client certificate to use for client authentication on the IEEE 802.1X authentication.
This is used when EAP-TLS is used as authentication method.
NONE
Client Certificate Password Set a client certificate password to use for client authentication on the IEEE 802.1X authentication.
This setting is necessary when a password is set to the client certificate.
EAP-TLS
Server Authentication Specify whether to check reliability of the server on IEEE 802.1X authentication.
When ON is selected, CA certificate for server authentication is required.
OFF
CA Certification Select a CA certificate to use for server authentication on the IEEE 802.1X authentication.
This setting is necessary when ON is selected for server authentication.
NONE

EAP User Name Necessary Necessary Necessary
EAP Password Necessary -- Necessary
Inner Authentication Method -- -- Necessary
Client Certification -- Necessary --
Client Certificate Password -- Optional --
Server Authentication Optional Optional Optional
CA Certification Optional Optional Optional

The Restart page is displayed. Click Restart to restart DS-600.
The changes will take effect after restart.

When the login page is displayed, the reboot is completed.
Finish the Web browser.


Go PageTop Previous Page Go Index Next Page