artofrf.com

Ali's Technology Blog

Menu
  • Home
  • Important Links
  • About Me
  • Tools and Scripts
Menu

Mist Updates – BYoD PSK Portal

Posted on August 28, 2022August 29, 2022 by mali

Mist folks were busy, and as always, pushed out some cool updates past Thursday. Here is a quick list that caught my attention and I was waiting for.

  • Client onboarding – PSK Portal
  • VRF Configuration
  • Global Application Policies
  • Custom Virtual Routers (SRX)
  • For full details, please see this link

“BYoD” is something many organizations struggle with. Device onboarding, certificates, licenses, expensive and complicated NAC solutions, troubleshooting the work flows, security, all this can get overwhelming. Depending on the organizational needs, there are multiple ways to accomplish this.

Client onboarding – PSK Portal

Client onboarding and PSK Portal are part of the Mist IoT Assurance subscription. Last week’s update pushed out Client onboard and PSK Portal. This simplifies BYoD work flow and can be configured using the Mist UI or the APIs. PSK Portal uses BYoD (SSO) and uses an external “Idp” for SAML 2.0 authentication. For my testing, I used “Okta”, but you can also use MS Azure AD (Note: I tried to use Jump Cloud but I could not get it to work. I have created a ticket with their help desk; once I have more information, I will update my post). Setup with “Okta” is straightforward. You can read about the different setup options using this link.

Mist Setup:

Step one would be to create an “SSID” for the “PSK Portal” to use. Security must be “WPA2/PSK” with multiple pass phrases”. Under the “VLAN”, choose “List” and add all the “VLANs” that will get assigned to different users.

In step two, I created the “PSK Portal”. From “Organization – Admin – Client onboarding” click on “Add PSK Portal”.

Name the portal whatever you want to name it; I named it based on the VLAN assignment. It can be named based on the group of users, for example, contractors, employees, facilities, executives, etc.

Step three can be “Portal Authorization” but I completed the “PSK Parameters” first.

Next, under “Portal Authorization” I needed to get the “Portal SSO URL”. For now, I just added some generic information so that I can generate that URL.

Okta Configuration

For “Okta” configuration, start with a new “Create app integration” and choose “SAML 2.0”.

Name your app (upload logo if you want to).

Next screen is for the “SAML” settings. I only had to change three fields here as shown.

That should be it. Finish the setup process to complete the Mist setup. For that, I had to open up my app, and navigate to Sign On and “SAML setup”.

Next, I copied the settings from “Okta” to “Mist”, hit save and I’m done.

For testing, I embedded the link on my website. This can allow users to onboard their devices by clicking on the link, and signing in using their credentials (I had users created in “Okta”).

Art of RF – BYoD Onboarding

I am not a video editor, but I’ve tried to create couple of videos showing the process of a user onboarding a BYoD device. My apologies in advance if something is not clear in the video please feel free to leave any feedback and comments if something is not right and/or missing.

Art of RF BYoD – Mist Client Onboarding

Next video I will use my phone to scan the QR code and connect to the SSID. NOTE: you can also use the “PSK” displayed here to connect.

Art of RF BYoD – iPhone Video

After the device successfully connects, Mist portal shows the user and the device connected in the UI.

Art of RF BYoD – Self provisioned client

Once the self provisioning is complete, you also receive an email with the information. Thanks to Dan LaMay from Mist Systems pointing that out.

Art of RF BYoD – E Mail from PSK Portal

If any Admin changes the PSK key from the portal, you will get an email with the new QR code and the key.

Art of RF BYoD – PSK Change email

Summary

This is certainly an impressive offering from Mist that can not only simplify the BYoD integration but also save cost for the organizations planning on BYoD and IoT deployments. Always happy to hear the feedback. let me know if I may have missed anything here, is incorrect, or you would like to share your use case. Thank you for reading.

Category: BYoD, IoT, IIoT, OT, Juniper/Mist, Mist, Mist Wireless, Wireless

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Recent Posts

  • CLI to UI – Nile Guest APIs
  • Nile Secure Guest – Configuration and Use Case
  • WLAN Pros Toolbox
  • Nile does NAC – Configuring Trust Engine
  • WLAN Validator

Tags

#MFD9 - Juniper Presents AP W318 arista Arista AGNI Arista CV-CUE Arista Hospitality AP Arista NAC Arista presents at MFD9 Arista wall plate AP Arista WIPS Arista WPA3 UPSK Aruba Central Automation CWAP 403 EAP Format MAC Addresses Hamina Network Planner Juniper Mist show cloud-native NAC Juniper SRX300 Marvis MFD8 MFD9 MistAI Mist MPSK Mist Premium Analytics Mist Wireless NaaS Networking Field Day NFD32 Nile APIs NileNav Nile Secure Nile Wi-Fi Tech Field Day Troubleshooting with Marvis Troubleshooting with Mist Troubleshooting with Mist AI Troubleshooting with Wireshark True NaaS Wireless Adjuster Wireless Adjuster Level II Wireless troubleshooting WLPC wlpc2023 Wyebot

Tech Blogs

  • CCNA Wireless
  • Cisco Full Bars
  • Packet Life
  • The ASCII Construct
  • Juniper Port Checker
  • Bad-Fi
  • Gjermund Raaen
  • Havilandweb
  • WiFiTodd
  • BadgerWiFi
  • WiFrizzy
  • Spectrum Chart

Recent Comments

  • Hiten Thakkar on PCAP I/O Graph Analyzer
  • mali on Deploying Nile Secure – My First NSB
  • Larry Farrish on Deploying Nile Secure – My First NSB
  • Courtney on Mist Access Point – CSV
  • ayoub chabrouk on Ubiquiti stealing the show at MFD11

Archives

  • August 2026
  • July 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • October 2025
  • August 2025
  • May 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • September 2023
  • August 2023
  • June 2023
  • May 2023
  • April 2023
  • February 2023
  • November 2022
  • October 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • May 2021
  • April 2021
  • March 2021
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • April 2019
  • March 2019
  • November 2018
  • October 2018
  • September 2018
  • May 2018
  • January 2018
  • December 2017
  • August 2017
  • January 2017
  • September 2014
  • December 2013
  • October 2013
  • May 2013
  • August 2012
  • July 2012

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Categories

  • AeroHive
  • Arista
  • Arista
  • Aruba
  • Aruba
  • Aruba Central
  • BYoD
  • Certifications
  • Cisco
  • Cisco
  • Cisco EEM Scripting
  • Cisco Routing
  • Cisco Security
  • Cisco VoIP
  • Cisco VPN
  • Cisco Wireless
  • Conferences and Meetings
  • Design
  • Ekahau
  • General
  • Hamina
  • IoT, IIoT, OT
  • Juniper Security
  • Juniper Switching
  • Juniper/Mist
  • Linux
  • Microsoft
  • Mist
  • Mist Wireless
  • Nile
  • Nile Secure
  • Nile Wi-Fi
  • Programming/Automation
  • Python
  • Ruckus
  • Ruckus Wireless
  • Ruckus/Brocade
  • Ruckus/Brocade Scripting
  • Ruckus/Brocade Switching
  • Secure Guest Service
  • Security
  • Switching
  • Tools
  • Troubleshooting
  • Trust Engine
  • Uncategorized
  • Windows
  • Wireless
  • Wireless
  • WLAN Tools
© 2026 artofrf.com | Powered by Minimalist Blog WordPress Theme