Konica Minolta bizhub C3850FS bizhub C3850FS/C3850/C3350 Applied Functions Use - Page 43

[IEEE802.1X], [Limiting Access to Destination] - [Restrict User Access], If [EAP-TLS], [EAP-TTLS]

Page 43 highlights

1.5 Available operations in Administrator mode 1 [IEEE802.1X] To display: Administrator mode - [Security] - [IEEE802.1X] Using IEEE802.1X authentication, you can connect devices that are only authorized by administrators to the LAN environment. If IEEE802.1X authentication is installed in your environment, configure the following settings. Item [IEEE802.1X] [EAP Type] [User ID] [Password] [TTLS Anonymous Name] [TTLS Authentication Type] [Send Client Certificate] [Server ID] [Encryption Strength] [Network Stop] Description Select [Enable] to use the IEEE802.1X authentication. [Disable] is specified by default. Select an EAP authentication method. • [Server Specification]: The EAP type provided by the authentication server will be used for authentication. Configure the supplicant settings as required for this machine according to the EAP type that is provided by the authentication server. • Do not select [None]. [None] is specified by default. Enter the user ID (using ASCII characters of up to 128 bytes). This user ID is used for all EAP types. Enter the password (using ASCII characters of up to 128 bytes). The password is used for all EAP types other than [EAP-TLS]. To enter (change) the password, select the [Change Password] check box, then enter a new password. Enter the anonymous name used for EAP-TTLS authentication (using ASCII characters of up to 128 bytes) if [EAP Type] is set to [EAP-TTLS] or [Server Specification]. [anonymous] is specified by default. Select an internal authentication protocol for EAP-TTLS if [EAP Type] is set to [EAP-TTLS] or [Server Specification]. [MS-CHAPv2] is specified by default. Select whether or not to encrypt the authentication information using a certificate for this machine, if necessary. This setting can be configured if the following conditions are satisfied: • The certificate is registered on this machine • [EAP-TTLS], [PEAP], or [Server Specification] is selected from [EAP Type]. To verify CN of the certificate, enter the server ID (using ASCII characters of up to 64 bytes). If [EAP-TLS], [EAP-TTLS], [PEAP], or [Server Specification] is selected from [EAP Type], select an encryption strength for encryption by TLS, if necessary. • [Medium]: Keys that are more than 56 bits in length are used for communi- cation. • [High]: Keys that are more than 128 bits in length are used for communica- tion. [Medium] is specified by default. Specify the delay time between the start of an authentication process and the end of network communication, if necessary. If an authentication process does not succeed within the specified time, all network communication will stop. To specify the delay time, set [Network Stop] to [Enable], and enter the delay (sec.) in [Limit Time]. To restart the authentication process after network communication stopped, reboot this machine. [Disable] is specified by default. [Limiting Access to Destination] - [Restrict User Access] To display: Administrator mode - [Security] - [Limiting Access to Destination] - [Restrict User Access] Specify the functions for which user operation is restricted. Item [Registering and Changing Addresses] Description Select whether or not to allow the user to register or change destinations. [Allow] is specified by default. [Applied Functions] 1-37

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168

[Applied Functions]
1-37
1.5
Available operations in Administrator mode
1
[IEEE802.1X]
To display:
Administrator mode
- [Security] - [IEEE802.1X]
Using IEEE802.1X authentication, you can connect devices that are only authorized by administrators to the
LAN environment.
If IEEE802.1X authentication is installed in your environment, configure the following settings.
[Limiting Access to Destination] - [Restrict User Access]
To display:
Administrator mode
- [Security] - [Limiting Access to Destination] - [Restrict User Access]
Specify the functions for which user operation is restricted.
Item
Description
[IEEE802.1X]
Select [Enable] to use the IEEE802.1X authentication.
[Disable] is specified by default.
[EAP Type]
Select an EAP authentication method.
[Server Specification]: The EAP type provided by the authentication server
will be used for authentication. Configure the supplicant settings as re-
quired for this machine according to the EAP type that is provided by the
authentication server.
Do not select [None].
[None] is specified by default.
[User ID]
Enter the user ID (using ASCII characters of up to 128 bytes).
This user ID is used for all EAP types.
[Password]
Enter the password (using ASCII characters of up to 128 bytes).
The password is used for all EAP types other than [EAP-TLS].
To enter (change) the password, select the [Change Password] check box,
then enter a new password.
[TTLS Anonymous
Name]
Enter the anonymous name used for EAP-TTLS authentication (using ASCII
characters of up to 128 bytes) if [EAP Type] is set to [EAP-TTLS] or [Server
Specification].
[anonymous] is specified by default.
[TTLS Authentication
Type]
Select an internal authentication protocol for EAP-TTLS if [EAP Type] is set to
[EAP-TTLS] or [Server Specification].
[MS-CHAPv2] is specified by default.
[Send Client Certificate]
Select whether or not to encrypt the authentication information using a certifi-
cate for this machine, if necessary.
This setting can be configured if the following conditions are satisfied:
The certificate is registered on this machine
[EAP-TTLS], [PEAP], or [Server Specification] is selected from [EAP Type].
[Server ID]
To verify CN of the certificate, enter the server ID (using ASCII characters of up
to 64 bytes).
[Encryption Strength]
If [EAP-TLS], [EAP-TTLS], [PEAP], or [Server Specification] is selected from
[EAP Type], select an encryption strength for encryption by TLS, if necessary.
[Medium]: Keys that are more than 56 bits in length are used for communi-
cation.
[High]: Keys that are more than 128 bits in length are used for communica-
tion.
[Medium] is specified by default.
[Network Stop]
Specify the delay time between the start of an authentication process and the
end of network communication, if necessary.
If an authentication process does not succeed within the specified time, all net-
work communication will stop.
To specify the delay time, set [Network Stop] to [Enable], and enter the delay
(sec.) in [Limit Time].
To restart the authentication process after network communication stopped,
reboot this machine.
[Disable] is specified by default.
Item
Description
[Registering and
Changing Addresses]
Select whether or not to allow the user to register or change destinations.
[Allow] is specified by default.