artofrf.com

Ali's Technology Blog

Menu
  • Home
  • Important Links
  • About Me
  • Tools and Scripts
Menu

Mist Access Assurance – Mist Cloud NAC Configuration

Posted on September 18, 2023October 4, 2023 by mali

Back in May, #MFD9 – Mobility Field Day 9 Juniper Networks unveiled their long-awaited cloud NAC solution (Check out my write-up on #MFD9 – Juniper Presents); Juniper branded it as Access Assurance, it also included all the features from IoT Assurance. I am not an expert NAC architect; My experience has been with the on-perm solutions. Anyone who has deployed a NAC knows all the aches and pains of getting 802.1X working with a NAC, especially if you are trying to do EAP-TLS, EAP-TTLS.

Can I do this?

This weekend, I had time to see if this is as easy to configure as advertised. I wanted to configure it without any assistance or hand-holding by reading the documentation and videos located here. Can I do this? Let’s find out my experience as I share my journey.

EAP-TTLS with Okta Directory:

There are couple of things to understand before I go any further:

  • Mist Access Assurance is a cloud NAC solution it works with cloud directories such as Okta and MS Azure.
  •  If you have an on-prem Windows AD install, this is not a solution for you.

EAP-TTLS Flow:

I am a visual learner, so I drew a quick high-level diagram of the process using Okta with the steps involved:

  • Setup Okta Directory.
  •  Configure Native Application Service.
  •  Configure API Service.
  •  Setup IDP in Mist Access Assurance.
  •  Download the Mist Cert and set up a profile on iPad/iPhone using Apple Configurator.
  •  Install the profile and connect.
Mist Access Assurance with Okta – EAP-TTLS

The following link has the official Juniper Mist documentation on different configuration scenarios. You can always ask Marvis. I won’t get too deep into every step, but I did run into a few things that confused me a little. I am organizing some of that data flow.

Mist Access Assurance – EAP-TTLS

First step is to copy the Okta tenant ID. Do not copy “.okta.com“, this is important and the instructions on the Mist website explicitly mention the same thing.

Follow this link for detailed “Okta Integration” step-by-step directions. After going through all the steps, the next step is to create IDP in the Mist dashboard. I mixed this one up initially, so I figured a visual representation of what goes where should be helpful. NOTE: “Private key will come from when you are generating the the “Public and Private Keys” as shown below.

Mist Access Assurance – Idp creation
Mist Access Assurance – Idp Creation

Tenant ID Error:

Note: I initially had “.okta.com” in my “OAuth Tenant ID” which ended up causing this error, I knew something was wrong in my Idp config and I thought it may have been the keys and credentials. Only after creating the support ticket I realized it was simply the additional text. I liked the fact that the Description points out an error, would love to see it actually say something along the lines of, “Wrong Tenant ID” instead.

Mist Access Assurance – Idp Issue

Next step is to create some “Auth Policy Labels” that will be used in the “Auth Policy”. Think of labels as something that will get assigned to the users/devices and based on the labels other actions can be performed.

Mist Access Assurance – Auth Policy Labels

High level work flow of the “Auth Policy Labels” and “Auth Policy”

Mist Access Assurance – TTLS Auth

There will be four labels for this process. The first set of roles will match with the Directory Attributes Idp is sending, “contractor” and “employee”. Next will assign those from “Mist Access Assurance”. The following link has the full list of all the “Mist RADIUS Attributes“.

Mist Access Assurance – Labels

After the labels, the next step is to create “Auth Policies”. These policies will be used to assign actions once users/devices connect. I am using the “Auth Policy” to assign RADIUS attributes such as VLAN and roles.

In the example below, if the Directory Role from the Idp is “employee” and they are using EAP-TTLS on the Wireless, they will get the RADIUS attributes of “employee” and VLAN “30”.

Similarly, if the Directory Role from the Idp is “contractor” and they are using EAP-TTLS on the Wireless, they will get the RADIUS attributes of “contractor” and VLAN “40”.

Mist Access Assurance – Auth Policies

I was using my iPad and iPhone for testing, next I needed to get the TTLS profile loaded on them. I used “Apple Configurator” for that. First I needed to download the Mist Server Certificate. Simply copy the cert and save it as “mist_cert.crt”. This is the server cert that the device will need to trust to connect. NOTE: There was a little confusion on what should it say for the CN. I read “auth.mist.com” in some locations, but it would be the “Org ID”.

Mist Access Assurance – Mist Server Cert

The following link has step by step directions on setting up the EAP-TTLS profile using the Apple Configurator. I basically created two profiles:

  • Employee
  • Contractor

Upload Mist Server Certificate that was saved earlier.

Fill in the Wi-Fi section as follows:

  • SSID name – Mist-TTLS
  • Protocols – TTLS
  • Inner Authentication – PAP
  • Trust – Check the Mist Server Certificate.
Mist Access Assurance – Apple Configurator TTLS Profile

One thing to notice here is the use of PAP for “Inner Authentication”. Immediately, concerns around security come up, after all, “PAP” is supposed to be clear text. I am no security expert, however, I believe using EAP-TTLS as the outer authentication method and PAP as inner authentication can provide a decent secure 802.1X Wi-Fi SSID. But I leave that up to you and your needs and requirements to figure out what is best for you and your organization. I am not endorsing anything specific.

I encourage you to read up more on this here Is PAP Secure. I also highly recommend reading the following book, “Wireless Security Architecture” by Jennifer (JJ) Minella. Helped me clear up some security-related questions.

Wireless Security Architecture – Jennifer (JJ) Minella

NOTE: I haven’t tried any other “Inner Autherntication” methods so far with EAP-TTLS, that is something I’d like to try it later.

Creating an SSID to use Mist Access Assurance is a simple process, you simply choose, “Mist Auth” under “Authentication Servers” and add the Dynamic VLANs with VLAN Type set as “Tunnel-Private-Group-ID”.

Mist Access Assurance – SSID Mist Auth

Connecting to an EAP-TTLS SSID:

Time to connect to the SSID and look at the logs. First, I logged in with the “contractor” profile and entered the wrong password.

The Mist dashboard shows the whole process and the failure reason.

  • NAC Server Certificate was validated.
  • IDP Credentials failed, which led to NAC denying the client access.
    •  The “Authorization Failure” log message Description shows the error with “username/password”. NOTE: Correct “User Group” was applied (contractor).
  •  Dynamic pcap.
Mist Access Assurance – EAP-TTLS Failure

Dynamic Packet Captures has been an excellent feature of Mist since the beginning. I was curious to see what information it would provide me when using Mist Access Assurance. I was able to view the complete process from the start to the failure and the “deauthentication”.

In the next step I am going to connect with the correct credentials. When the connection is successful, Mist Dashboard will show the logs showing the successful connection. List of steps:

  • NAC Server Certificate Validation – No change to this
  • NAC IDP Authentication Success – Success this time
  • NAC IDP Group Lookup Success – This wasn’t present in the failure
  • NAC Client Access Allowed – Success
    • NOTE: It is important to mention that during this step you are able to see the “Auth Rule” that was used/applied for this client access by simply clicking on it (see the last screenshot). This can help troubleshoot Policy related issues.
  • Authorization and Association – Success with the User Group assigned as “contractor”.
Mist Access Assrance – EAP-TTLS Successful connection

Lastly, since the “contractor” is assigned VLAN40 from the “Auth Policies”, DHCP Success shows the IP address from VLAN40.

Mist Access Assurance – Contractor Profile

If I follow the same process, install the “employee” profile and then connect to the Mist-TTLS SSID, I should get assigned the User Group “employee” and VLAN30.

Mist Access Assurance – Mist-TTLS SSID Employee role

NOTE: These roles can also be used with WxLAN policies to allow or deny access to certain resources. I will have to do a separate write up for that.

EAP-TLS Flow:

EAP-TTLS is great, but can Mist Access Assurance do EAP-TLS and how complicate is it to configure? Unlike EAP-TTLS, EAP-TLS requires client and server side certificates and uses a different flow. It can also be a daunting task setting it all up, you either need your own PKI infrastructure or some some kind of cloud based provider to issue certificates and then use MDM to push them out. Before going any further I’ll post a high level EAP-TLS Flow (Note we have already completed the Idp configuration).

Mist Access Assurance – EAP-TTLS Flow

I do not have my own PKI in the lab, nor access to any cloud based provider, so I used what Mist recommends for testing in the following video, “Optional – Certificate creation for lab/testing use“. It was simple to use, and I was able to get my own CA up and running in less than 10 min (that also included watching parts of that video multiple times to catch up). I will not go over every step, but I will post some screen shots of client certificate creation.

Mist Access Assurance – EAP-TLS Client Certificate

Note the .pfx file as it contains the complete chain. In production you wouldn’t be using this method, this is just for testing and lab.

CA that was created earlier that was used to create the client certificates can now be imported into the Mist Dashboard. Under “Certificate Authorities” click on “Add CA”, paste your cert and you are good to go. When clients connect they will be able to Authenticate to this server and since this CA issued the client certificates, it can authenticate the clients.

Mist Access Assurance – Importing CA

Auth Policies:

For EAP-TLS, I created the Auth Policies using the CN Label, but tested connectivity using the CN and Groups successfully.

Mist Access Assurance – EAP-TLS Auth Policies with CN
Mist Access Assurance – EAP-TLS Auth Policies with Group

Connecting to an EAP-TLS SSID:

After I loaded up the EAP-TLS profile for a contractor I was able to successfully connect using client certificates.

If I want to find out which Auth Policy this client device is hitting, I can get that information by clicking on the Auth Rule displayed in one of the steps. Since this is a “contractor”, it should be using the “contractor” Auth Policy.

Mist Access Assurance – Auth Policy being used

What happens if I change it to using Groups and Employee profile?

Mist Access Assurance – Employee Profile

Employee is hitting the employee authentication policy

Mist Access Assurance – Employee Auth Policy

Since this profile is supposed to use VLAN30, DHCP Success message should display VLAN 30 and and IP address from 192.168.30.x range.

Mist Access Assurance – Employee DHCP Success

EAP-TLS Issues:

When I first created the “employee” certificate and profile I created the certificate wrong and ran into issues with connectivity. My connection was not successful. When I looked into the Mist Dashboard I saw the following errors. My client was failing and getting deauthenticated; but why? Take a look at the User Group, this is supposed to be “employee” but it was showing up as “contractor”

Mist Access Assurance – EAP-TLS Troubleshooting

Dynamic Packet Capture was also available for deeper analysis.

Client was not recognizing the the CA and I realized that when I created the “employee” cert, I created it wrong and not created it under the CA, I also used the wrong private key.

CA Certificate
Client not recognizing the CA

Summary:

As I mentioned previously that I am no NAC Expert, but the fact that I was able to setup working EAP-TTLS and EAP-TLS SSIDs in about 4 hours (which included watching the videos, some multiple times, reading the documentation, troubleshooting couple of issues using the the Mist Dashboard as I was testing different scenarios etc) is not bad at all. I have written about “Client Onboarding and PSK Portal” in the past, which is also part of Mist Access Assurance now. There isn’t a need to configure, manage and install an onsite appliance, cloud based NAC solution allows Geo-redundancy and resiliency. Integrates with the Mist Dashboard well for insights and troubleshooting. Two additional things I would like to test using Mist Access Assurance:

  • What happens if there is no Internet connectivity, will my existing connections continue to work until session time out or will they drop.
  • Micro-segmentation on the wire, GBP.

It is still an evolving product, looking forward to Juniper Mist adding more features to it, such s posture assessment, profiling, possibly Mist MDM etc. Thank you for reading, if you are deploying, have deployed or tested Mist Access Assurance, feel free to share your thoughts and feedback.

Category: Juniper Security, Juniper/Mist, Mist

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Recent Posts

  • Nile Secure Guest – Configuration and Use Case
  • WLAN Pros Toolbox
  • Nile does NAC – Configuring Trust Engine
  • WLAN Validator
  • PCAP I/O Graph Analyzer

Tags

AirDrop arista Arista AGNI Arista CV-CUE Arista NAC Arista WIPS Arista WPA3 UPSK Aruba Central Automating Mist Switch Templates Automation AWDL Configuring Switch Templates in Mist CWAP 403 EAP Format MAC Addresses Hamina Network Planner Juniper SRX300 MacBook Marvis mdns MFD8 MFD9 Mist Access Assurance MistAI Mist Auto Placement Mist MPSK Mist Wireless NaaS Networking Field Day NFD32 NileNav Nile Secure Nile Wi-Fi Social Channels Tech Field Day Troubleshooting with Marvis Troubleshooting with Mist Troubleshooting with Mist AI Troubleshooting with Wireshark Wireless Adjuster Wireless Adjuster Level II Wireless troubleshooting WLPC wlpc2023 Wyebot

Tech Blogs

  • WiFiTodd
  • CCNA Wireless
  • Cisco Full Bars
  • Packet Life
  • Havilandweb
  • Gjermund Raaen
  • Bad-Fi
  • The ASCII Construct
  • Juniper Port Checker
  • WiFrizzy
  • Spectrum Chart
  • BadgerWiFi

Recent Comments

  • Hiten Thakkar on PCAP I/O Graph Analyzer
  • mali on Deploying Nile Secure – My First NSB
  • Larry Farrish on Deploying Nile Secure – My First NSB
  • Courtney on Mist Access Point – CSV
  • ayoub chabrouk on Ubiquiti stealing the show at MFD11

Archives

  • August 2026
  • July 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • October 2025
  • August 2025
  • May 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • September 2023
  • August 2023
  • June 2023
  • May 2023
  • April 2023
  • February 2023
  • November 2022
  • October 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • May 2021
  • April 2021
  • March 2021
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • April 2019
  • March 2019
  • November 2018
  • October 2018
  • September 2018
  • May 2018
  • January 2018
  • December 2017
  • August 2017
  • January 2017
  • September 2014
  • December 2013
  • October 2013
  • May 2013
  • August 2012
  • July 2012

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Categories

  • AeroHive
  • Arista
  • Arista
  • Aruba
  • Aruba
  • Aruba Central
  • BYoD
  • Certifications
  • Cisco
  • Cisco
  • Cisco EEM Scripting
  • Cisco Routing
  • Cisco Security
  • Cisco VoIP
  • Cisco VPN
  • Cisco Wireless
  • Conferences and Meetings
  • Design
  • Ekahau
  • General
  • Hamina
  • IoT, IIoT, OT
  • Juniper Security
  • Juniper Switching
  • Juniper/Mist
  • Linux
  • Microsoft
  • Mist
  • Mist Wireless
  • Nile
  • Nile Secure
  • Nile Wi-Fi
  • Programming/Automation
  • Python
  • Ruckus
  • Ruckus Wireless
  • Ruckus/Brocade
  • Ruckus/Brocade Scripting
  • Ruckus/Brocade Switching
  • Secure Guest Service
  • Security
  • Switching
  • Tools
  • Troubleshooting
  • Trust Engine
  • Uncategorized
  • Windows
  • Wireless
  • Wireless
  • WLAN Tools
© 2026 artofrf.com | Powered by Minimalist Blog WordPress Theme