artofrf.com

Ali's Technology Blog

Menu
  • Home
  • Important Links
  • About Me
  • Tools and Scripts
Menu

Nile does NAC – Configuring Trust Engine

Posted on July 6, 2026August 7, 2026 by mali

I love innovation and the idea of removing complexity. I worked for a manager once and during our usual 1:1 meeting, he told me one day that I don’t want to you to be the guy who always looks at a blinking yellow light and press a button to make it go away just because someone told me so. Instead find out why that yellow light starts to blink and how to simplify and eliminate the cause.

Before I talk more about what I want to talk about, I’d like to share couple of other quotes that I absolutely love.

Any intelligent fool can make things bigger and more complex. It takes a touch of genius – and a lot of courage – to move in the opposite direction.
Alert Einstein

Simple can be harder than complex: You have to work hard to get your thinking clean to make it simple. But it’s worth it in the end because once you get there, you can move mountains.
Steve Jobs

RADIUS and NAC solutions are important to many organizations but they can be very complex to deploy. Previously I have written couple of articles on Cloud based RADIUS and NAC solutions.

  • Arista – AGNI
  • Juniper – Access Assurance

Both of these solutions brought innovation and simplicity delivered from the cloud to us. NOTE: this post is not about one verses the other but more focused on the evolution, innovation, configuration and simplification of RADIUS and NAC solutions.

I have written about Nile’s Cloud RADIUS in the past so I won’t get into the details of it in here, but focus on what is Nile bringing to table when it comes to NAC with it’s Trust Engine.

First I’m going to take a step back and bring up some important bullet points because they are part of the over all Zero Trust Fabric. Nile has some built in Zero-Trust and NAC features that Trust Engine uses to provide enhanced experience.

  • Host Based micro-segmentation – No two hosts on the same network are able to communicate with each other by default
  • Fingerprinting – Each device is fingerprinted and profiled
  • Continuous monitoring of the devices

NOTE: Keep these three features in mind as we dig more into the Trust Engine.

Let’s take a look at Nile’s Trust Engine and how to configure different options.

Introduction to Nile’s Trust Engine – Options and features

I’ll walk through different sections and what they are used for.

Policy Groups:

Nile’s zero trust fabric uses context and identity, policy groups as I see it allow creating and defining just that.

User Groups:

Define users based on if they are part of a segment, IDP Group or IP/Subnet. There are three options here:

  • Segment – This allows users to pick a segment that is already configured.
  • IDP Group – This allows users to pick an IDP group when using SSO.
  • IP/Subnet – Here users can manually enter IP/Subnet information manually.
Nile Trust Engine - User Groups based on Segments
Nile Trust Engine - User Groups based on the IDP Groups

Device Groups:

Define devices that are part of a segment, specific fingerprint, MAC/OUI or IP/Subnet. There are three options in here. Fingerprint, MAC/OUI and Network.

  • Segment – This allows users to use one of the predefined segments
  • Fingerprint – This allows users to setup Fingerprinting match.
  • MAC/OUI – This allows users to manually enter MAC and OUI information to match
  • IP/Subnet – Here users can manually enter IP/Subnet information manually.
Nile Trust Engine - Device Groups based on the Segment
Nile Trust Engine - Device Groups based on the Fingerprint
Nile Trust Engine - Device Groups based on the MAC/OUI

Device Group – Device Validation Check:

Device validation check feature is part of the Device Group. This is where I can specify validation checks to make sure only devices that have been authorized can join the network. Think printers or other devices if an IT team wants to make sure that only device they authorize should gain access to the network and if they do not pass the validation check they need to be quarantined they can use the following options to perform Device Validation Checks. SSH, SNMPv3, HTTP, HTTPS.

In the example below I am using a Finger Print to match devices to a group called “Linux”. Next I configured a Device Validation Check using SSH. If those credential do not exist on any of the devices that fall under those finger printing rules they will be quarantined.

App Groups:

App Groups currently support “IP/Subnet” but more interesting stuff is on the roadmap.

All Users & Devices – Assigned:

This section shows devices that Nile’s zero trust fabric has matched with the User, Device and App groups. Second screen shot also shows the policies that are associated with it based on that match.

Nile Trust Engine - Assigned devices
Nile Trust Engine - Device information that is assigned by the zero-trust fabric

All Users & Devices – Unclassified:

Any device that does not have a match any of the groups I mentioned above will end up as an “Unclassified” client.

Nile Trust Engine - Un classified clients

I am able to manually move this client into a User or a Device group if I want.

Nile Trust Engine - Un classified clients security details

Quarantined Devices:

This is where devices that fail any validation and/or posture checks will end up. By default they do not have access any where and nothing can access these devices.

In this screen shot, notice two policies applied to Quarantined Devices. I’m allowing specific SSO Group and Network (Employees) to be able to access these devices but only specific services. This can allow me to access these devices and remedy the situation such as adding relevant credentials or install software etc. Some things to point out here.

This is based on the Context and Identity and NOT the networks. Which means even if employees and these devices are in the same exact network same rules will apply.

Once I add the credentials that are part of the Device Validation Check I can either wait for the system to recheck the device or I can manually trigger that option.

Lastly, what if the device is failing a posture assessment and needs anti virus software installed from the server. A simple policy can be created allowing access to a server only to download the software (we will get into it in another blog, Nile integrates with Intune to perform posture assessment).

Service Profiles:

Service profiles is where different services can be configured, these can be a group with multiple services under that group or a single service.

Let’s start with creating a service profile of a single service, first give it a name and description. Then click on the “+” icon to add the service.

Nile Trust Service - Creating a Service Profile
Nile Trust Service - Creating a Service Profile
Nile Trust Service - Creating a Service Profile

Service profile is ready to be used

Nile Trust Service - Creating a Service Profile

Next I’ll create a Service Profile with multiple services. By repeating the process above I can keep adding the services I need.

Nile Trust Service - Creating a Service Profile - multiple services

Policy Sets:

Policy Sets, let users define an outcome based on source, services and destination. There are three outcomes here:

  • Allow
  • Deny
  • Forward

Check out the video below going over the Trust Engine and some configuration options.

This is a high level mind map showing the Policies in the Trust Engine.

Nile Trust Engine - Policies Mind Map

Policy Log:

Can’t have policies without the logs, because when you want to troubleshoot, view the traffic, see what is talking to what and what is not talking Nile provides a full Policy Log that is searchable. I will get into more details of these logs in my next post.

It is very important to understand that within Nile’s Zero Trust Fabric, the ability to isolate at the host level and enforce granular policies based on context and identity doesn’t require any third-party software, appliance or additional configuration. It is all an intrinsic part of the Nile’s Fabric and applies to wired and wireless devices.

Stay tuned for more and demo. As always would love to hear any feedback and questions. Thanks for reading.

Category: Nile, Nile Secure, Security, Trust Engine

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Recent Posts

  • CLI to UI – Nile Guest APIs
  • Nile Secure Guest – Configuration and Use Case
  • WLAN Pros Toolbox
  • Nile does NAC – Configuring Trust Engine
  • WLAN Validator

Tags

#MFD9 - Juniper Presents AP W318 arista Arista AGNI Arista CV-CUE Arista Hospitality AP Arista NAC Arista presents at MFD9 Arista wall plate AP Arista WIPS Arista WPA3 UPSK Aruba Central Automation CWAP 403 EAP Format MAC Addresses Hamina Network Planner Juniper Mist show cloud-native NAC Juniper SRX300 Marvis MFD8 MFD9 MistAI Mist MPSK Mist Premium Analytics Mist Wireless NaaS Networking Field Day NFD32 Nile APIs NileNav Nile Secure Nile Wi-Fi Tech Field Day Troubleshooting with Marvis Troubleshooting with Mist Troubleshooting with Mist AI Troubleshooting with Wireshark True NaaS Wireless Adjuster Wireless Adjuster Level II Wireless troubleshooting WLPC wlpc2023 Wyebot

Tech Blogs

  • CCNA Wireless
  • Cisco Full Bars
  • Packet Life
  • The ASCII Construct
  • Juniper Port Checker
  • Bad-Fi
  • Gjermund Raaen
  • Havilandweb
  • WiFiTodd
  • BadgerWiFi
  • WiFrizzy
  • Spectrum Chart

Recent Comments

  • Hiten Thakkar on PCAP I/O Graph Analyzer
  • mali on Deploying Nile Secure – My First NSB
  • Larry Farrish on Deploying Nile Secure – My First NSB
  • Courtney on Mist Access Point – CSV
  • ayoub chabrouk on Ubiquiti stealing the show at MFD11

Archives

  • August 2026
  • July 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • October 2025
  • August 2025
  • May 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • September 2023
  • August 2023
  • June 2023
  • May 2023
  • April 2023
  • February 2023
  • November 2022
  • October 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • May 2021
  • April 2021
  • March 2021
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • April 2019
  • March 2019
  • November 2018
  • October 2018
  • September 2018
  • May 2018
  • January 2018
  • December 2017
  • August 2017
  • January 2017
  • September 2014
  • December 2013
  • October 2013
  • May 2013
  • August 2012
  • July 2012

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Categories

  • AeroHive
  • Arista
  • Arista
  • Aruba
  • Aruba
  • Aruba Central
  • BYoD
  • Certifications
  • Cisco
  • Cisco
  • Cisco EEM Scripting
  • Cisco Routing
  • Cisco Security
  • Cisco VoIP
  • Cisco VPN
  • Cisco Wireless
  • Conferences and Meetings
  • Design
  • Ekahau
  • General
  • Hamina
  • IoT, IIoT, OT
  • Juniper Security
  • Juniper Switching
  • Juniper/Mist
  • Linux
  • Microsoft
  • Mist
  • Mist Wireless
  • Nile
  • Nile Secure
  • Nile Wi-Fi
  • Programming/Automation
  • Python
  • Ruckus
  • Ruckus Wireless
  • Ruckus/Brocade
  • Ruckus/Brocade Scripting
  • Ruckus/Brocade Switching
  • Secure Guest Service
  • Security
  • Switching
  • Tools
  • Troubleshooting
  • Trust Engine
  • Uncategorized
  • Windows
  • Wireless
  • Wireless
  • WLAN Tools
© 2026 artofrf.com | Powered by Minimalist Blog WordPress Theme