artofrf.com

Ali's Technology Blog

Menu
  • Home
  • Important Links
  • About Me
  • Tools and Scripts
Menu

MFD9 – Arista lights up their session with AGNI

Posted on June 23, 2023June 23, 2023 by mali

Most of my Arista experience has been Data Center. However, I had the opportunity to explore Aristas campus and mobility side of the things for the first time during the Mobility Field Day 8 event. Two main things that caught my attention last time were MSSG and Live Trace. Since then, I have had a little more familiarity with their Cognitive Campus architecture, so seeing their name as one of the presenters, I was looking forward to their presentation and announcements.

Sriram Venkiteswaran (Director of Product Management) started the Arista presentation, “What’s New with Arista Cognitive Campus.

AGNI – Arista Guardian for Network Identity:

When I first heard that the Cloud NAC Solution from Arista is called “Agni”, my immediate thought was “Fire”; which is what the word “Agni” means in Sanskrit. My brain started to relate it with the Firewall icon that we normally see in topology diagrams. But it actually is an acronym for “Arista Guardian for Network Identity“. Pretty creative in my opinion.

While the legacy NAC solutions are expensive and complicated to deploy, Arista focused on simplicity while keeping it scalable and secure.

MFD9 – Arista AGNI

For starters AGNI offers all the features of a modern cloud architecture, such as Micro services and Globally distributed high availability, integration with multiple cloud providers and cloud directory services such as Okta, Azure etc.

  • AGNI has multi vendor support,
  • Offers different options for the devices (Switches and Access Points).
  • For all Arista switches and access points it will use RadSec.
  • For other vendors switches and APs that support RadSec AGNI can have a direct connection.

What happens when a legacy device (Switch/AP) does not support RadSec? Any Arista switch can act as a RadSec proxy. NOTE: I would like to point out that Bhagya Prasad mentioned a module that needs to be purchased to accomplish this if you are trying to use an Arista switch as a Proxy for RadSec.

MFD9 – Bhagya Prasad NR presenting Arista AGNI
MFD9 – Arista AGNI – Capabilities

AGNI is a cloud based solution, which means if there is no cloud connectivity due to a circuit failure and/or latency, technical teams must understand what will happen to their clients. Arista team explained Authentication Survivability. What happens when the WAN link goes down?

MFD9 – Arista AGNI Auth Survivability

Note the light green check mark; these features are currently not available. I had a conversation with Sriram Venkiteswaran on these scenarios and here are some of my notes to further elaborate:

  • Distributed cache/Smart control plane
  • Wherever the client was connected last will hold the cache
    • No central location for caching
    • Consider a user was connected to AP#13 on the second floor when he closed his laptop.
    • That AP#13 will cache the key for 12 hours
    • When device roams, this key will be provided to the other access points (provided, user reconnects within 12 hour time period)
  • NOTE: AGNI is scheduled to be GA approximately in July.

Logs, session details, debugging, are very crucial when troubleshooting issues, but running debugging sessions on production systems can impact the performance of an overall system. Since Arista AGNI is a cloud based NAC solution, it can leverage the computing power available in the cloud to run these sessions without impacting any system performance.

MFD9 – Arista AGNI Debugging
MFD9 – Arista presents AGNI

Arista UPSK:

Each vendor has a solution that uses different PSKs for the clients. Arista calls it UPSK (Unique PSK). Arista UPSK has two different flavors:

  • UPSK.
    • Each client will have their own passphrase.
    • UPSK Can be without segmentation or with segmentation
    • Group of devices can use the same UPSK
  •  Shared Client.
    • If UPSK is isolating clients and you want to share a printer or a scanner. It can be marked as a shared client (think shared resources, printers, scanners, faxes etc). This will allow other clients to communicate with this “Shared Device”.
MFD9 – Supara Dam discussing UPSKs

WPA3 – UPSK Solution:

There was decent interest from the delegates and the online community on WPA3 support with UPSK . Arista mentioned that they were able to achieve this without downgrading to WPA2.

@AristaNetworks have their UPSK solution working with WPA3 #MFD9 🤯

— Peter Mackenzie (@MackenzieWiFi) May 19, 2023

HOW?!?!?! We want to know publicly!!! WPA3 uPSK @AristaNetworks #MFD9

— Mark Houtz CWNE 5️⃣0️⃣0️⃣ 🦈 🛜 (@marko_with_a_k) May 19, 2023

Wow. So @AristaNetworks can microsegment with VxLAN, which is cool, but even cooler – their multiple PSK solution works with WPA3. So far I *think* they're the only vendor who can do this. (Feel free to correct if I'm wrong.) #MFD9 pic.twitter.com/Hf6cme4BkO

— John Kilpatrick (@HypergeekWiFi) May 19, 2023

Arista has taken a creative approach and accomplishes this using SSO, every user gets their own portal to manage their devices. Here is a high level diagram of the process.

MFD9 – Arista WPA3 UPSK with AGNI

For headless devices, users will need to log into the portal and manually add them in the portal.

MFD9 – Watch Arista AGNI and UPSK presentation

Arista WIPS:

Jatin Parekh, Robert Ferruolo presented an updated on Arista WIPS. Previously, legacy way to handle and prevent clients connecting to unauthorized APs or rogue APs that are not on the wire was to send deauth frames. WPA3 and encrypted management frames (802.11w), makes this impossible.

MFD9 – Robert explaining Arista WIPs solution

How is Arista doing this ? It is part of the CV-CUE, using the dedicated Multi-function radio. Arista Uses a different frame/parameters to force a target client to disassociate from un-authorized WPA3 SSID. Further technical details are not available currently since the solution is patent pending. Robert did show a quick demo of WIPS in action disconnecting a WPA3 client.

MFD9 – Arista WIPS

Multi-function Radio:

All Arista access points come with a multi-function radio which plays a vital role towards the Root Cause Analysis and troubleshooting. It also plays a key role for the WIPS. One feature of this radio was its ability to act as a client and perform end to end testing. I’d love to see this in action and test it out myself.

MFD9 – Arista Multi Function Radio and AIOps

Arista Cognitive Campus Unified Wired + Wireless Architecture:

Kumar Narayanan presented Campus United Wired and Wireless Architecture. What really sparked my interest during this presentation was Arista APs ability to terminate IPSec tunnels to any standard IPSec firewall.

This wall plate access point from Arista C318 is able to build IPSec tunnel back, supports NAT. I can see this as an excellent use case for a small branch office and/or remote work.

MFD9 – Arista – Wi-Fi 6E 2×2 Wall Plate

My final thoughts and wish list:

Impressive presentation from team Arista and all the new features that were announced, particularly, AGNI, WPA3/UPSK and WIPS. As I’ve gotten more familiar with the Arista story, here are few things I’d love to see from Arista.

  • An enterprise firewall solution, integrated with CV-CUE
    • NOTE: I did see Edge Threat Management on their website that talked about the NGFW, but I am not familiar with the solution. I believe these are Arista NGFW devices.
  • SD-WAN Solution integrated in CV-CUE
  • Ability to search NAC logs
  • Switch stacking
  • Mesh and Point to Point connectivity configuration and easy deployment
  • Outdoor 6E access point once AFC approval is complete.

Lastly, can I have one in black also? Thank you.

MFD9 – Arista T Shirt
Category: Conferences and Meetings

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Recent Posts

  • Nile Secure Guest – Configuration and Use Case
  • WLAN Pros Toolbox
  • Nile does NAC – Configuring Trust Engine
  • WLAN Validator
  • PCAP I/O Graph Analyzer

Tags

AirDrop arista Arista AGNI Arista CV-CUE Arista NAC Arista WIPS Arista WPA3 UPSK Aruba Central Automating Mist Switch Templates Automation AWDL Configuring Switch Templates in Mist CWAP 403 EAP Format MAC Addresses Hamina Network Planner Juniper SRX300 MacBook Marvis mdns MFD8 MFD9 Mist Access Assurance MistAI Mist Auto Placement Mist MPSK Mist Wireless NaaS Networking Field Day NFD32 NileNav Nile Secure Nile Wi-Fi Social Channels Tech Field Day Troubleshooting with Marvis Troubleshooting with Mist Troubleshooting with Mist AI Troubleshooting with Wireshark Wireless Adjuster Wireless Adjuster Level II Wireless troubleshooting WLPC wlpc2023 Wyebot

Tech Blogs

  • WiFiTodd
  • CCNA Wireless
  • Cisco Full Bars
  • Packet Life
  • Havilandweb
  • Gjermund Raaen
  • Bad-Fi
  • The ASCII Construct
  • Juniper Port Checker
  • WiFrizzy
  • Spectrum Chart
  • BadgerWiFi

Recent Comments

  • Hiten Thakkar on PCAP I/O Graph Analyzer
  • mali on Deploying Nile Secure – My First NSB
  • Larry Farrish on Deploying Nile Secure – My First NSB
  • Courtney on Mist Access Point – CSV
  • ayoub chabrouk on Ubiquiti stealing the show at MFD11

Archives

  • August 2026
  • July 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • October 2025
  • August 2025
  • May 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • September 2023
  • August 2023
  • June 2023
  • May 2023
  • April 2023
  • February 2023
  • November 2022
  • October 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • May 2021
  • April 2021
  • March 2021
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • April 2019
  • March 2019
  • November 2018
  • October 2018
  • September 2018
  • May 2018
  • January 2018
  • December 2017
  • August 2017
  • January 2017
  • September 2014
  • December 2013
  • October 2013
  • May 2013
  • August 2012
  • July 2012

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Categories

  • AeroHive
  • Arista
  • Arista
  • Aruba
  • Aruba
  • Aruba Central
  • BYoD
  • Certifications
  • Cisco
  • Cisco
  • Cisco EEM Scripting
  • Cisco Routing
  • Cisco Security
  • Cisco VoIP
  • Cisco VPN
  • Cisco Wireless
  • Conferences and Meetings
  • Design
  • Ekahau
  • General
  • Hamina
  • IoT, IIoT, OT
  • Juniper Security
  • Juniper Switching
  • Juniper/Mist
  • Linux
  • Microsoft
  • Mist
  • Mist Wireless
  • Nile
  • Nile Secure
  • Nile Wi-Fi
  • Programming/Automation
  • Python
  • Ruckus
  • Ruckus Wireless
  • Ruckus/Brocade
  • Ruckus/Brocade Scripting
  • Ruckus/Brocade Switching
  • Secure Guest Service
  • Security
  • Switching
  • Tools
  • Troubleshooting
  • Trust Engine
  • Uncategorized
  • Windows
  • Wireless
  • Wireless
  • WLAN Tools
© 2026 artofrf.com | Powered by Minimalist Blog WordPress Theme