Juniper-Networks-logo

Juniper Networks Mist Access Assurance

Juniper-Networks-Mist-Access-Assurance-product

ዝርዝሮች

  • የምርት ስም: Mist Access Assurance Client Onboarding – NAC Portal
  • ሥሪት: 1.0
  • ሻጭ: Juniper

የምርት መረጃ
The Mist Access Assurance Client Onboarding – NAC Portal is a solution provided by Juniper for secure client-driven self-provisioning within organizations. It includes features such as PSK Portal, MPSK, BYOD support, PSK Admin, NAC Portal, EAP-TLS, Marvis Client for various platforms (iOS/iPadOS/Android), and more.

የአጠቃቀም መመሪያዎች

NAC Portal Configuration
To configure the NAC Portal for client onboarding, follow these steps:

  1. Navigate to Organization > Certificates and set up Onboard CA Configuration (Active).
  2. Configure the Onboard Certificate Authority under Onboard CA Configuration.
  3. Add the NAC Onboarding Portal under NAC settings.
  4. Set up Portal Settings, including Name, Portal Type, and NAC Portal URL.
  5. Configure Portal Authorization settings like SSO and SAML.

የመሳፈር ሂደት
Follow these steps for the onboarding process:

  1. Download and install the Marvis Client App if not already installed.
  2. Proceed with SCEP for Wi-Fi profile and client certificate setup.

የምስክር ወረቀት አስተዳደር
For managing certificates, navigate to Organization > Certificates, where you can view, revoke, or manage internal certificates.

Mist Access Assurance Client Onboarding – NAC Portal

ስሪት 1.0

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

1

Client Onboarding – NAC Portal

20259 Mist Cloud https://www.juniper.net /documentation /us /en /software /mist /product-updates /latest.html

Mist Documentation
Juniper Mist Access Assurance Guide

ጭጋግ https://www.juniper.net/jp/ja/local/solution-technical-information/mist.html

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

2

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

3

ታሪክ

ሥሪት
Ver 1.0

20259

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

4

© 2025 Juniper አውታረ መረቦች

የደንበኛ መሳፈር
5 የጥድ ቢዝነስ አጠቃቀም ብቻ

የደንበኛ መሳፈር
Client-driven self provisioning

NAC Portal

PSK Portal
MPSK

ቤዮድ
· PSK Portal · SSO(SAML) (password + MFA etc..) · QR SSID/passphrase passphrase email (Optional) · MPSK SSID

PSK Admin

NAC Portal
EAP-TLS

· PSK Portal · SSO(SAML) (password + MFA etc..) · SSID/passphrase passphrase email · MPSK SSID
Marvis Client
Marvis Client Marvis Client(iOS/iPadOS/Android)
· NAC Portal · SSO(SAML) (password + MFA etc..) · Marvis Client & profile/certificate · WPA3/WPA2 802.1X(Mist Auth) SSID

NOTE: Marvis Client Client Onboarding 20259()

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

6

© 2025 Juniper አውታረ መረቦች

NAC Portal
NOTE: 20259()
7 የጥድ ቢዝነስ አጠቃቀም ብቻ

NAC Portal
Organization > Certificates
[Organization] [Certificates]

Onboard CA Configuration (Active)

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

8

NAC Portal
Onboard Certificate Authority

Onboard CA Configuration ()

[ ] [Onboard CA Configuration] [Onboard Certificate Authority] [Active] [OK]Juniper-Networks-Mist-Access-Assurance-fig-1

ውጫዊ / ውስጣዊ

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

9

NAC Portal
NAC
[Organization] [Client Onboarding] [NAC] [Add NAC Onboarding Portal]

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

10

NAC Portal
Name / Portal Settings [Name] [Portal Type] [Marvis Client] [Create] NAC Portal URL URL
NAC Portal URL

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

11

NAC Portal
Portal Authorization
[Portal Authorization] SSO
· [ URL] [SSO URL] · [Microsoft Entra ][Issuer]

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

Entra ID Mist 1
Entra Name ID Format
URL
12

NAC Portal
Portal Authorization
[Portal Authorization] SSO
· (Base64) [][Certificate] · [] [SAML ][] SAML

Entra ID Mist 2

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

13

NAC Portal
Portal Authorization
[Portal SSO URL] Entra ID [] [ URL]

Mist Entra ID

© 2025 Juniper አውታረ መረቦች

Portal SSO URL
14 የጥድ ቢዝነስ አጠቃቀም ብቻ

NAC Portal
Onboarding Parameters
[Onboarding Parameters] [Save]

WLAN Template

መለኪያዎች
SSID
Security Type Client Certificate Format Certificate expires in X days

መግለጫ
WLAN Template SSID ­ WPA2/WPA3 > Enterprise(802.1X) ­ Authentication Server: Mist Auth WPA2/WPA3
(: 365)

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

15

NAC Portal
Organization > Auth PoliciesJuniper-Networks-Mist-Access-Assurance-fig-2

Auth Policy

[Organization] [Auth Polices] [Add Rule] Auth Policy

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

16

NAC Portal
የመሳፈር ሂደት

[NAC Portal URL] [NAC Portal URL] Client Onboarding() SSO

IdP(Entra ID etc)

NAC Portal URL

URL

Portal SSO URLJuniper-Networks-Mist-Access-Assurance-fig-5

SSO(SAML)

© 2025 Juniper አውታረ መረቦች

+ MFA()
Juniper የንግድ አጠቃቀም ብቻ

መተግበሪያውን ያውርዱ እና ይጫኑት።
Marvis Client
Already have the app?

17

NAC Portal
የመሳፈር ሂደት

SCEP

Marvis Client ()Wi-Fi

Marvis Client

Wi-Fi Profile

የደንበኛ የምስክር ወረቀት

© 2025 Juniper አውታረ መረቦች

ዋይ ፋይ
Juniper የንግድ አጠቃቀም ብቻ

18

NAC Portal
Organization > Certificates
[Organization] [Certificates] [Internal]

© 2025 Juniper አውታረ መረቦች

NAC Portal
19 የጥድ ቢዝነስ አጠቃቀም ብቻ

NAC Portal
Organization > Certificates > Revoke Certificate

[Revoke Certificate]

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

20

© 2025 Juniper አውታረ መረቦች

Appendix Entra ID SAML SSO
21 የጥድ ቢዝነስ አጠቃቀም ብቻ

Entra ID SAML SSO
Entra ID > > Entra ID [] []

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

22

Entra ID SAML SSO

Mist Cloud Admin SSO

[] [] [] []

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻJuniper-Networks-Mist-Access-Assurance-fig-3

23

Entra ID SAML SSO
[]

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

24

Entra ID SAML SSO
SAML [SAML]

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

25

Entra ID SAML SSO

ሳኤምኤል

Entra መታወቂያ

ሳኤምኤል

Portal SSO URL
( ID) URL

Microsoft Entra Issuer
ሳኤምኤል
(Base64) Certificate
URL ኤስኤስኦ URL

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻ

ጭጋግ
26

© 2025 Juniper አውታረ መረቦች

Juniper የንግድ አጠቃቀም ብቻJuniper-Networks-Mist-Access-Assurance-fig-4

27

ሰነዶች / መርጃዎች

Juniper Networks Mist Access Assurance [pdf] የተጠቃሚ መመሪያ
Mist Access Assurance, Access Assurance, Assuranc

ዋቢዎች

አስተያየት ይስጡ

የኢሜል አድራሻዎ አይታተምም። አስፈላጊ መስኮች ምልክት ተደርጎባቸዋል *