Configuring the Cisco VC 220 Network Camera Software
Network Setting > 802.1X
VC 220 Dome WDR Day/Night PoE Network Camera Administration Guide
55
6
Protected EAP (EAP-PEAP)
Like EAP-TTLS uses an encrypted TLS-tunnel. Supplicant certificates for both
EAP-TTLS and EAP-PEAP are optional, but server (AS) certificates are required.
Developed by Microsoft, Cisco, and RSA Security, it is currently an IETF draft.
EAP-MSCHAPv2
Requires a username and password, and is an EAP encapsulation of MS-CHAP-v2,
RFC2759. Usually used inside of a PEAP-encrypted tunnel. Developed by
Microsoft, and is currently an IETF draft.
The following table provides a summary of the authentication methods:
EAP-MD5
EAP-TLS
EAP-TTLS
EAP-PEAP
Server
Authentication
None
Public Key
(Certificate)
Public Key
(Certificate)
Public Key
(Certificate)
Supplicant
Authentication
Password Hash
Public Key
(Certificate or Smart
Card)
MSCHAP, MS-
CHAP(v2)
MSCHAP, MS-
CHAP(v2)
Authentication
Attributes
One-Way
Authentication
Mutual
Authentication
Mutual
Authentication
Mutual
Authentication
Dynamic Key
Delivery
No
Yes
Yes
Yes
Deployment
Difficulty
Easy
Hard
Moderate
Moderate
Security Risks
Identity exposed,
Dictionary attack,
Man-in-the-Middle
(MitM) attack
Identity exposed
MitM attack
MitM attack
Identity hidden in
Phase 2, but
potential exposure in
Phase 1