Configuration

Mist Access Assurance – TEAP Windows Client Configuration

Currently TEAP is only supported on Windows 10 and above. As of time of this writing WiFi/Wired profile with TEAP can only be configured manually or via scripts, which can be distributed via MDM/GPO. Current MDM solutions do not provide out-of-the box support for TEAP configuration.   Navigate to Control Panel > Network and Sharing...

Mist Auth Proxy – Mist Edge VM Installation

This article covers requirements and installation instructions of a Mist Edge VM for the purposes of Mist Auth Proxy functionality. The following are the minimum hardware requirements for a Mist Edge VM for Mist Auth Proxy feature. Supported Hypervisor: VMware ESXi, tested versions – 6.7.0 and 7.0. Sizing for a Production is as below: CPU:...

Mist Edge Proxy IdP – eduroam

Overview Mist Access Assurance provides a capability to integrate with eduroam NROs (National Roaming Operators) using Mist Edge acting as a RADIUS proxy. Mist Edge would act as a gateway to eduroam RADIUS servers with a static public IP or NAT IP assigned such that it can be registered as a RADIUS client in the...

Okta Integration

Overview Mist Access Assurance allows you to integrate our authentication service natively into Okta directory using OAuth. How can you leverage OKTA as Identity Provider in combination with Mist Access Assurance? User authentication via EAP-TTLS Authenticate User by doing delegated authentication checking username and password via OAuth Obtain user group memberships to leverage them in...

Passwords vs Certificates for 802.1X

Passwords vs Certificates – TL;DR Understand your use-cases. Select the right authentication method (802.1X or MPSK) that has the right balance between security vs client and user capabilities. Certificates are always recommended especially as a long-term solution, current onboarding mechanisms provide good way to control cert provisioning at scale for all your client population. Use...