Security

 View Only
  • 1.  802.1x with bosch camera FLEXIDOME ip3000i

    Posted Mar 20, 2025 07:03 AM
      |   view attached

    hello, someone have experience to setup the 802.1x EAP-MD% in the bsch videocamera  FLEXIDOME ip3000i ?

    I have configured but at the clearpass arrive the EAP-TLS request and clearpass block access because he don't find the righe certificate.

    the target is to authenticate the Videocamera with username and password, not certificate.

    the configuration of the camera is simple but I didn't find how disable the EAP-TLS



    ------------------------------
    ACMP ACSP ACCP ACEP ACDP
    ------------------------------


  • 2.  RE: 802.1x with bosch camera FLEXIDOME ip3000i

    Posted Mar 20, 2025 09:58 AM

    I'm curious, if the camera is already attempting EAP-TLS, why would you intentionally go for something less secure?  Just setup the certificate trust for the camera and go with that.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: 802.1x with bosch camera FLEXIDOME ip3000i

    Posted Mar 20, 2025 11:24 AM

    it's a customer policy



    ------------------------------
    ACMP ACSP ACCP ACEP ACDP
    ------------------------------



  • 4.  RE: 802.1x with bosch camera FLEXIDOME ip3000i

    Posted Mar 20, 2025 11:30 AM

    Then your best bet is probably going to be Bosch support for how to configure that device.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: 802.1x with bosch camera FLEXIDOME ip3000i

    Posted Mar 20, 2025 11:40 AM

    agree



    ------------------------------
    ACMP ACSP ACCP ACEP ACDP
    ------------------------------



  • 6.  RE: 802.1x with bosch camera FLEXIDOME ip3000i

    Posted Mar 21, 2025 05:55 AM

    It's a bad and insecure policy in that case. EAP-MD5's security is broken.

    I'd check in the dropdown for 802.1X Authentication, where it now says 'On'; if there may be an option to select EAP-MD5 / EAP-TLS / or none to see if you can disable EAP-TLS; but in general it's the device (camera in this case) that determines which authentication method to use. ClearPass should support the one used in it's service.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------