Panasonic Network Camera Bb Hcm371a Operating Instructions
Have a look at the manual Panasonic Network Camera Bb Hcm371a Operating Instructions online for free. It’s possible to download the document as PDF or print. UserManuals.tech offer 10737 Panasonic manuals and user’s guides for free. Share the user manual or guide on Facebook, Twitter or Google+.
Operating Instructions [For assistance, please call: 1-800-272-7033] 51 2.4 What is IPsec? IPsec provides security for the transmission of sensitive information over unprotected networks such as the Internet. IPsec authenticates IP packets between participating IPsec devices. Cameras IPsec Feature The camera can use IPsec in both IPv4/IPv6. The camera supports the following IPsec feature. Item Supported Feature IKEv1 Pre-shared Key Method Phase 1 mode Phase 2 mode Cipher Algorithm Message-Digest Algorithm: Main mode *1 : Quick mode : DES-CBC, 3DES-CBC, AES-CBC (128, 192, 256 bits) : HMAC-MD5, HMAC-SHA-1 *1The camera does not support aggressive mode. IPsec ESP (Encapsulating Security Payload)*2 Transport mode, Tunnel mode *2The camera does not support authentication header (AH). Cipher Algorithm Message-Digest Algorithm:DES-CBC, 3DES-CBC, AES-CBC (128, 192, 256 bits) :HMAC-MD5-96, HMAC-SHA-1-96 Malicious User Internet Image Allowed User Readable Unreadable
Operating Instructions 52 IPsec Mode Selection Select transport mode or tunnel mode to access the camera. Transport Mode (IPv4 Only) The image is encrypted in the whole way between the camera and your PC. In the environment of Windows XP Service Pack 1 or later, transport mode is available only in IPv4. Prepare the following requirements. Item Supported Feature PC Operating System Web Browser ISP Service: Windows XP Service Pack 1 or later : Internet Explorer 6.0 or later : Services for multiple global addresses (A global address must be set up on your PC.) Note To use IPsec, you need to set up your operating system. See the Panasonic Network Camera support website at http://panasonic.co.jp/pcc/products/en/netwkcam/ for the setup. Camera ISP Service : Services for multiple global addresses (A global address must be set up to the camera.) Transport Mode Encrypted
Operating Instructions [For assistance, please call: 1-800-272-7033] 53 Tunnel Mode (IPv4/IPv6) An IPsec mode of operation where the entire IP packet including IP header is authenticated and encrypted. A new IP header is added (protecting the entire original packet). Both VPN clients and VPN gateways can use this mode. Note The camera can be accessed only from the PCs under the VPN router. Other PCs cannot access the camera. Prepare the following requirements. Item Supported Feature PC Operating System Web Browser: Windows XP, Windows 2000, Windows Me, Windows 98SE (in IPv4) : Windows XP Service Pack 1 or later (in IPv6) : Internet Explorer 6.0 or later Router ISP Service (in IPv4) ISP Service (in IPv6): Static global address service (A global address must be set up to the WAN side of the router.) : IPv4/IPv6 Dual-Stack or IPv6 over IPv4 Tunneling service Note See the Panasonic Network Camera support website at http://panasonic.co.jp/pcc/products/en/netwkcam/ for the recommended router. Camera ISP Service (in IPv4) ISP Service (in IPv6): Services for multiple global addresses (A global address must be set up to the camera.) : IPv4/IPv6 Dual-Stack or IPv6 over IPv4 Tunneling service Encrypted Not EncryptedTunnel Mode WA N LAN
Operating Instructions 54 2.5 Encrypt the Camera Image in Transport Mode The camera can encrypt the image using IPsec transport mode. Note If you use IPsec, refresh interval slows down. 1.Click [IPsec] on the Setup page. 2.Click Camera in the Transport column. •If you use transport mode in E-mail or FTP transfer, click No. in the Buffer/ Transfer column. 3.Enter each parameter in the data field.The display shows that the communication is in HTTP and any people can access the camera if they have the pre-shared key (see page 55). Set up these settings to transfer images in transport mode (see page 111).
Operating Instructions [For assistance, please call: 1-800-272-7033] 55 4.Click [Save] when finished. •New settings are saved. 5.Click [Cancel]. •The IPsec page is displayed. 6.Check [Use] in the IPsec column, check encoding strength, and click [Save]. Setting Description Status•Check the box to use this encryption method. Pre-Shared Key•It is the key to use in the authentication of communications. Enter the same pre-shared key as your PC. •Enter ASCII characters for the host name (see page 150). But [Space], [], [], [&], [] are not available. Note If the pre-shared key leaks to a third party, it may lead to illegal access, private information leak or interference. To protect your security and privacy, pay attention to the following points. •Make it known only to the specified people. •Set it as many characters as possible. •Change the password regularly. Setting Description IPsec•Check the box to enable IPsec features. If you clear the box, whole IPsec features will be invalid. Encoding strength•Encoding strength for IPsec can be selected. If you select [Standard], DES or NULL is valid as an algorithm, and then the data will become easier to be decrypted.
Operating Instructions 56 7.Click [Restart]. 8.Set up your PC as it fits to the requirements on page 52. •Set the FTP server or E-mail server to transfer images. 9.Access the camera (see page 13). •If you can access the camera, the IPsec setup is complete. Notes •In IPsec communications, IPsec is displayed on the Top page or the Single Camera page. •If you cannot communicate using IPsec, see 2.10 IPsec in the Troubleshooting section of the Installation/Troubleshooting. •See the Panasonic Network Camera support website at http://panasonic.co.jp/pcc/products/en/netwkcam/ for the IPsec features.
Operating Instructions [For assistance, please call: 1-800-272-7033] 57 2.6 Encrypt the Camera Image in Tunnel Mode The camera can encrypt the image using IPsec tunnel mode. Notes •Do not set IPsec on the PCs under the VPN router. Communications may be blocked. •If you use IPsec, refresh interval slows down. •The camera can be accessed only from the PCs under the VPN router. Other PCs cannot access the camera. 1.Click [IPsec] on the Setup page. 2.Click Add in the Tunnel column. 3.Enter each parameter in the data field.
Operating Instructions 58 4.Click [Save] when finished. •New settings are saved. 5.Click [Cancel]. •The IPsec page is displayed. 6.Check [Use] in the IPsec column, check encoding strength, and click [Save]. Setting Description Status•Check the box to use this encryption method. Pre-Shared Key•It is the key to use in the authentication of communications. Enter the same pre-shared key as your VPN router. •Enter ASCII characters for the host name (see page 150). But [Space], [], [], [&], [] are not available. Note If the pre-shared key leaks to a third party, it may lead to illegal access, private information leak or interference. To protect your security and privacy, pay attention to the following points. •Make it known only to the specified people. •Set it as many characters as possible. •Change the password regularly. Network address•Enter the destination network address. •Enter IP address/Prefix length in the data field. Router address•Enter the WAN IP address of the VPN router on a destination network. Notes •IPv6 link-local address is not available. •The camera can be accessed only from the PCs under the VPN router. Other PCs cannot access the camera.
Operating Instructions [For assistance, please call: 1-800-272-7033] 59 7.Click [Restar t]. 8.Set up your VPN router as shown below. •To use tunnel mode, you need to set up your VPN router. Setting Description IPsec•Check the box to enable IPsec features. If you clear the box, whole IPsec features will be invalid. Encoding strength•Encoding strength for IPsec can be selected. If you select [Standard], DES or NULL is valid as an algorithm, and then the data will become easier to be decrypted. IKE Items Settings Phase 1 Authentication MethodPre-shared Key Method ID Specifies by address. Mode Main mode *1 Diffie-Hellman MODP GroupSpecifies 1 or 2. Cipher Algorithm Select from DES-CBC, 3DES-CBC or AES-CBC (128, 192, 256 bits). (Multiple selections are available.) Message-Digest AlgorithmHMAC-MD5, HMAC-SHA-1 Lifetime Specifies by 28800 s (Byte setting is not supported.)
Operating Instructions 60 •Set up the IPsec policy as the following. 9.Access the camera (see page 13). •If you can access the camera, the IPsec setup is complete. Notes •In IPsec communications, IPsec is displayed on the Top page or the Single Camera page. •If you cannot communicate using IPsec, see 2.10 IPsec in the Troubleshooting section of the Installation/Troubleshooting. •See the Panasonic Network Camera support website at http://panasonic.co.jp/pcc/products/en/netwkcam/technic/rtr_setup/ for the IPsec features. Phase 2 Mode Quick mode PFS Specifies either of Off, D-H Group 1 or D- H Group 2. Cipher Algorithm Select from DES-CBC, 3DES-CBC, AES-CBC (128, 192, 256 bits) or NULL. (Multiple selections are available.) Message-Digest AlgorithmHMAC-MD5-96, HMAC-SHA-1-96 Lifetime Specifies by 28800 s (Byte setting is not supported.) *1The camera does not support aggressive mode. Items Settings Protocol ANY Source Network Network address and subnet mask on the LAN side of the VPN router Source IP address A global address on the WAN side of the VPN router Destination Network A global address of the camera Destination IP address A global address of the cameraIKE Items Settings