Wi-Fi employee access – Arista CV-CUE
In this topic, you will learn how to configure Arista™ CloudVision Cognitive Unified Edge (CV-CUE) to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections.
Create RADIUS server entries
In this section, you will create RADIUS server entries for the Portnox™ Cloud RADIUS servers. You will use these servers later when you configure your SSIDs.
Optional: Create RadSec server entries
This is an optional task. Follow this task only if you want to connect to Portnox Cloud RADIUS servers using RadSec.
Before you begin, in Portnox Cloud, go to , select the relevant RADIUS instance, select , activate the Enable RADIUS over TLS (RadSec) option, and disable the Validate NAS Client Certificate (RadSec) option. Then, click on the Save button.
-
Open a support ticket with Arista and request the certificate that signs the access point’s default device certificate (issued by
CN=WiFi-TPM-Authority, O="Arista Networks, Inc."). -
Generate a certificate signing request (CSR) for a new certificate tag in CV-CUE, sign it with your own self-signed certificate authority, and upload the resulting device certificate and CA certificate back into CV-CUE. Then, assign this new tag as the Certificate Tag for the RadSec server. For more information, see Arista documentation.
Result: You created a RadSec-enabled RADIUS server entry. When you configure an SSID, activate the RadSec checkbox in the RADIUS Settings section to select this entry, instead of a non-RadSec entry, as described in the following topics.
established/down/reconnecting entries for the RadSec IP address.
A healthy tunnel shows a single established entry that is not followed by a
down/reconnecting cycle.Create an SSID for 802.1X authentication
In this section, you will create a new SSID and configure it for WPA2 Enterprise authentication, using the RADIUS servers that you created earlier.
Result: You created an SSID that authenticates employee Wi-Fi devices using 802.1X and the Portnox Cloud RADIUS servers.
Optional: Create an SSID for MAC-based authentication
This is an optional task. Follow this task only if you want to authenticate devices, such as IoT devices, that do not support 802.1X, using their MAC address instead. Skip this task if you do not need MAC-based authentication.
Result: You created a separate SSID that authenticates IoT devices by their MAC address using the Portnox Cloud RADIUS servers on the basis of MAC-based accounts.














