C-02 | AGNI UPSK Wireless Policy¶
Overview¶
In this lab we're going to explore the power of Unique Pre-Shared Keys (UPSK),
CV-CUE Login¶
If you're not already logged into CV-CUE, navigate to the Arista Launchpad for your lab.
Create Identity UPSK SSID¶
Let's create our new UPSK SSID by copying/modifying the PSK SSID we created in the CV-CUE lab.
-
While on your
CorpAfolder, Click onConfigureand thenWiFi -
Next, click on the and select
Create a Copyon your specific SSIDYour SSID
Student Name Student 1 ATD-##-PSKStudent 2 ATD-##-PSKwhere ## is a 2 digit character between 01-12 that was assigned to your lab/Pod
-
Select
Currently Selected Foldersand thenContinue. -
Click on the new SSID and select
Edit -
On the
BasicTab rename the SSID to the followingSettings
Student Student 1 Student 2 Name ATD-##-UPSKATD-##-UPSKProfile Name ATD-##-UPSKATD-##-UPSK -
Next, click on the
Securitytab and configure the followingUPSK Information
For more information on UPSK visit the article on Unique PSK
Settings
Field Value Security Method WPA2 / UPSK UPSK Identity Lookup Enabled -
Next, click on the
Access Controltab and configure the followingSettings
Field Value Radius Settings Select RadSecAuthentication Server AGNI-##Accounting Server AGNI-##Username and Password MAC Address without Delimiter Call Station ID %m-%sChange of Authorization Enabled -
Finally,
Save and turn on the SSIDandSave SSID -
Only select the
5 GHzoption on the next screen (deselect the 2.4 GHz box if it’s checked), then clickTurn SSID On.
AGNI Login¶
If you're not already logged into AGNI, navigate to the Arista Launchpad for your lab.
Create UPSK Network and Segment¶
In this section we are going to configure AGNI for our new SSID network and apply segmentation policy to enforce UPSK.
-
Click on
Networksand then+ Add Network. -
Add the following:
Settings
Field Student 1 Student 2 Name ATD-##-UPSKATD-##-UPSKConnection Type Wireless Wireless SSID ATD-##-UPSKATD-##-UPSKAuthentication Type Unique PSK (UPSK) Unique PSK (UPSK) -
Finally, click
Add Network -
You should now see this listed in your
Networks. -
Next, we will add the Segment.
-
Under Access Control, click on
Segmentsand then+ Add Segment -
Configure the following:
Segment Conditions
If there are multiple conditions, they must MATCH ALL.
Settings
Field Student 1 Student 2 Name ATD-##-UPSKATD-##-UPSKDescription ATD-##-UPSKATD-##-UPSKCondition #1 Network:Name is ATD-##-UPSKNetwork:Name is ATD-##-UPSKCondition #2 Network:Authentication Type is UPSKNetwork:Authentication Type is UPSKAction #1 Allow AccessAllow Access -
Finally, click on
Add Segment. -
You should now see your new segment in the list of segments.
Enroll Personal Device with Local User¶
In this section you will create a local user and enroll the MAC of your device.
-
In AGNI, under
Identity, click onUserand then+ Add User. -
Fill out the fields for a new user
Settings
Field Student 1 Student 2 Name whatever_you_want whatever_you_want UserId whatever_you_want whatever_you_want Password Arista!123Arista!123User must change password at next login Disabled Disabled -
Click
Add User -
You will notice that
Passwordhas now changed toUPSK Passphrase -
Copy and write down or save to text file the new UPSK Passphrase.
- Next, connect your client to
ATD-##A/B-UPSKusing your UPSK Passphrase. -
Click on
Sessionsand validate your device connection. -
Next, validate your device by clicking on
Userand thenUsers. Select your user. -
Click on
Show Clients
Create an AGNI Client Group¶
In this section, you will simulate your device as an IoT device.
- Disable and forget previously saved lab networks so your wireless connection on your test device does not auto connect.
-
In AGNI under your
User Clientslist,DeleteyourDevice. -
Next, you will add your client device as an IoT device in a Client Group.
- First, we will need to create the Client Group.
- In AGNI, under
Identity, click onClients > Client Groupsand then+ Add Client Group. -
Configure the following
Settings
Field Student 1 Student 2 Name CorpA Approved DevicesCorpA Approved DevicesDescription CorpA Approved DevicesCorpA Approved DevicesUser Association Not user associated Not user associated Group UPSK Enabled Enabled -
Copythe UPSK Passphrase and click onAdd Group - Next, connect your client to ATD-##-UPSK using the Client Group UPSK Passphrase.
-
Click on
Sessionsand validate your device connection. -
Next Click on your
Client. -
Notice your Client Group. Here you have the option to change the Client Group your device belongs to.
🎉 CONGRATS! You have completed this lab! 🎉
























