CyberArk

Axis Network Cameras

Description

Securely connect to Axis Q3517 or Q3515 Network Cameras via Google Chrome.



Vendor

This connection component is designed for secure connection to the following target:

VendorAxis
ProductNetwork Cameras
Product Category

Security Appliance

Product Versions



CyberArk

This connection component works with the following CyberArk versions:

CyberArk Solution

Privileged Session Management 

CyberArk Product

Privileged Session Manager (PSM)

CyberArk Versions10.1 and above
Artifact Version
Out of the Box

NO

Out of the Box in versions



Support & Certification

Support Level

STANDARD

Developed byCyberArk
Certification Level

CERTIFIED



Linked Accounts

Logon Account

Supported

NO

Required

NO

Platforms


Permissions


Prerequisites

The following prerequisites are required on the machine running this connection component:

Google Chrome installed.





Installation

Do the following to set up the connection component:

StepHow To
Copy files to PSM Server
  1. Unzip Axis Web.zip
  2. Copy PSMAxisDispatcher.exe to the Components Directory on the PSM Server(s).
Create the Connection Component
  1. In the PVWA go to Administration -> Options -> Connection Components
  2. Select the connection component named “PSM-VNCClientSample”, right-click it and select copy
  3. Right-click on “Connection Components” and paste
  4. Rename the newly created component by setting “Id” to “PSM-AxisWeb”
    1. Under the new connection component:
      1. Go to “Target Settings” and modify the “ClientDispatcher” field by replacing “PSMRealVNCDispatcher.au3” with “PSMAxisDispatcher.exe”
      2. Go to “Target Settings” -> “Lock Application Window” and set “Enable” to “No”
      3. Go to “Target Settings” → “Client Specific” → Right click → Add Parameter
        1. Add and set the following parameters (see Target Settings section for more information):
          1. Protocol= Https
          2. ChromeTimeout = 20
          3. ChromePath = C:\Program Files (x86)\Google\Chrome\Application

  5. Click “OK” to save
Add the connection component to a platform
  1. Go to Administration -> Platform Management

2. Select the platform for which you would like to use this connector

3. Click “Edit”

4. Go to “UI & Workflows” -> Right click -> “Add Privileged Session Management” (it may be grayed out if the platform already has it configured) ▪ If there is no “Connection Components” : Right click -> “Add Connection Components” ▪ “Connection Components” → Add Connection Component

5. Rename newly created “Connection Component” to “PSM-AxisWeb”

6. Click “OK” to save

7. Wait for the PSM refresh interval to pass. For immediate refresh restart the service “Cyber-Ark Privileged Session Manager”. Note- restarting the service will kick all active PSM sessions.




Configuration

AppLocker Settings

If your PSM server is hardened, you will need to make the following change in order for Google Chrome to be excluded from the Applocker rules:

1. On the PSM Server, open Powershell as Administrator from C:\Program Files (x86)\Cyberark\PSM\Hardening

2. Run notepad PSMConfigureAppLocker.xml

3. Towards the end of the PSMConfigureAppLocker.xml file, before the end tag, add the following line:

<Application Name="Google Chrome" Type="Exe" Path="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" Method="Hash"/>

Note - if Google Chrome is not installed in the suggested path then the value of Path will be different.

4. In the same Powershell window run PSMConfigureAppLocker.ps1 

Connection Component Settings

Specify the following parameters at the connection component level:

Target Settings section

Parameters that define specific target machines settings. These parameters can be overridden at platform or account level.

Parameter NamePathDescriptionAcceptable ValuesDefault Value
Protocol
The Protocol to connect to the Axis website.Https or HttpHttps
ChromePath
The path where Goolge Chrome is installed on the PSM Server.Windows PathC:\Program Files (x86)\Google\Chrome\Application

Account Settings

Account Mandatory Parameters

Specify the following parameters on the account:

Parameter NameDescriptionAcceptable Values
UsernameThe username to authenticate to the Axis websiteString
AddressThe address of the Network CameraIP Addres, FQDN, Hostname