Integrate Extreme Cloud IQ with Zero Trust Network Access

In this topic, you will find general instructions on how to integrate Extreme Cloud IQ with Portnox™ Zero Trust Network Access.

Create a Portnox Cloud application configuration

In this step, you will create a configuration in Portnox Cloud that will contain all the information necessary to integrate with Extreme.

  1. In a new tab of your browser, open your Portnox Cloud account by accessing the following URL: https://cloud.portnox.com/

    From now on, we will call this tab the Portnox tab.

  2. In the Cloud portal top menu, click on the Zero Trust Resources option.

  3. On the Resources screen, click on the Create resource button.

    1. In the What type of resource is this? section, select the SSO web application option.
    2. In the Authentication protocol section, select the SAML option.

    3. Click on the Next button.
  4. Optional: If you have more than one SAML identity provider configured, select the identity provider in the Select an identity provider to use for this resource section.
  5. In the Resource details section, enter a Resource name and optionally a Description.

    In this example, we used the name Extreme for the new application configuration but you can use any name you like.

  6. Keep this browser tab open. You will need it later.

Create an SSO IdP profile in ExtremeCloud IQ

In this section, you will access your ExtremeCloud IQ configuration, find the single sign-on (SSO) settings, and start creating a new IdP profile.

  1. In another tab of your browser, open the ExtremeCloud IQ login page. Then, log in with an account that has administrative privileges in ExtremeCloud IQ.

    From now on, we will call this tab the Extreme tab.

  2. Open your Account Details pane, and in the left-hand side menu, select the ADMINISTRATION > Enable Single Sign On (SSO) option.

  3. In the Single Sign-On Identity Provider (IdP) Profiles pane, click on the Add IdP Profile button.

  4. In the Add Identity Provider pane, in the Type step, click on the Generic SAML Server icon.

  5. In the Domain field, enter the fully qualified domain name and optionally a Description. Then, click on the Continue button.

    Users logging in to ExtremeCloud IQ with their email addresses in this domain will be automatically processed with SAML.

  6. In the Portnox tab, in the SAML metadata section, click on the Download metadata XML file link to download the XML file and save it to your local drive.

  7. In the Profile step, select the Import Metadata radio button, and then click on the Browse Files button. Then, select the XML file downloaded from Portnox Cloud.

  8. Click on the  ↥ button to upload the file to ExtremeCloud IQ.

  9. Scroll down to see the imported values, then copy the value of the SSO URL field and paste the same value in the SLO URL and SLO Response URL fields. Then, click on the Continue button.

Copy the SAML attributes/claims from your identity provider configuration

The ExtremeCloud IQ IdP configuration requires you to enter the values of essential SAML attributes (also known as claims). You need to find these attributes in your identity provider configuration, not your Portnox ZTNA configuration, and then copy them to a temporary text file.

  • If you use an Entra ID IdP configuration, in another browser tab, open the Entra ID SAML application that you created earlier and do the following steps.
    1. Open the Attributes & Claims pane (Enterprise apps > your Zero Trust Network Access application > Single sign-on > Attributes & Claims > Edit).

    2. In a temporary text file, save the exact values of the Claim name column for the attributes mapped to the following Values:
      • user.givenname
      • user.surname
      • user.mail
      • user.groups

      In most cases, the values will be:

      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
      http://schemas.microsoft.com/ws/2008/06/identity/claims/groups
      Note:
      If your configuration is missing the user.groups claim, click on the Add a group claim button and then in the Group Claims pane, select the option relevant to the way you set up groups in Entra ID. In most cases, it will be the All groups option. If your configuration is missing any other claims, add the recommended values as above.
      Note:
      We recommend that you save the attributes in the text file in exactly the order as presented above, because this will be order that you will enter them later in ExtremeCloud IQ.
  • If you use Google Workplace, open your admin console and do the following steps.
    1. Open the SAML attribute mapping pane (Apps > Web and mobile apps > your Zero Trust Network Access application > Configure SAML attribute mapping).

    2. In a temporary text file, save the exact values of the App attributes column for the attributes mapped to the following Google Directory attributes:
      • Basic information > Primary email
      • Basic information > First name
      • Basic information > Last name

      In the Group membership (optional) section, copy the name from the App attribute column.

      In our example, the values are:

      firstname
      lastname
      Email
      role

      However, these mappings depend on your other SAML applications and may be different in your environment. It is not important if the attributes are in the form of a simple name or a full URL, as long as you note them down exactly as entered in your Google Workspace configuration.

      Note:
      If your configuration does not have any SAML attribute mappings, you can add the Google directory attributes and App attributes as listed in the example above.

      If your configuration has an empty Group membership (optional) section, in the Google groups section, select the groups that you want to have access to ExtremeCloud IQ, and in the App attribute field, type a unique name, for example, role.

      Note:
      We recommend that you save the attributes in the text file in exactly the order as presented above, because this will be order that you will enter them later in ExtremeCloud IQ.

Add the SAML Attributes in ExtremeCloud IQ

The ExtremeCloud IQ IdP configuration requires you to enter the values of essential SAML attributes (also known as claims). You need to paste these attributes exactly as you copied them from your identity provider configuration.

  1. In the Extreme tab, continue your IdP profile creation in the IdP Connection step and in the First Name, Last Name, Email, and Group fields, enter the values copied from your IdP configuration in the previous section.

  2. Click on the Add a group name mapping link. In the IdP group field, enter the identifier of your identity provider group, and in the Select an ExtremeCloudIQ group field, select the appropriate ExtremeCloud IQ access level.
    Note:
    You must add group mappings to manage the ExtremeCloud IQ access level for different users. In the When no group mapping section, you can select the allow user login and assign a default user group option and assign the Observer (read-only) group. In that way, all users allowed to access ExtremeCloud IQ through ZTNA will have at least read-only access, and only selected users will have more access rights.
    • If you use Entra ID, the IdP group field must contain the Object Id of your Entra ID group (Groups > All groups > Object Id).

    • If you use Google Workspace, the IdP group field must contain the name of your Google Workspace group.

  3. Click on the Save & Finish button to save your configuration.

Copy configuration values from the Extreme tab to the Portnox tab

In this section, you will copy the values displayed in your ExtremeCloud IQ IdP configuration, and paste them in the relevant fields in Portnox Cloud.

  1. In the Extreme tab, in the Single Sign-On Identity Provider (IdP) Profiles pane, select the IdP profile that you just added, click on the  ⋮  icon, and select the Edit option.

  2. Click on the ExtremeCloud (SP) Connection tab.

  3. Click on the  ⧉  icon next to the SP Entity ID field.

  4. In the Portnox tab, in the Resource properties section, click on the empty field under the Entity ID / Service Provider Entity URL heading and paste the value copied from Extreme.

  5. In the Extreme tab, click on the  ⧉  icon next to the ACS URL field.

  6. In the Portnox tab, in the Resource properties section, click on the empty field under the Assertion Consumer Service (ACS) URL / Reply URL heading and paste the value copied from Extreme.

Finalize the configuration

In this section, you will finalize the configuration in Portnox Cloud and ExtremeCloud IQ.

  1. Finalize the configuration in the Portnox tab.
    1. Click on the OPTIONAL SETTINGS link to show additional fields, and then in the Application Login URI field, enter the following value: https://sso.extremecloudiq.com.
      Note:
      This step is required if you want to show this application in the ZTNA Secure Access Portal.

    2. Optional: Click on the Next button, and in the Policy enforcement section, in the Device risk assessment section, change the setting to Override with custom policy and then select a risk assessment policy if you want to assess risk with this application using a custom risk assessment policy, and in the Access control section, change the setting to Override with custom policy and then select an access control policy if you want to control access to this application using a custom access control policy.
      Note:
      To configure the access control policy, follow the steps in this topic: Create or edit an access control policy. To select the default access control policy, on the Groups screen, select a group that you want to configure the default for, click on the  ⋮  icon at the end of the row that represents the group, and then select the Group policies option. Then, in the ZTNA Resources section, select the policy in the SSO Web resources drop-down menu.
    3. Scroll all the way down to the end of the page, and then click on the Add resource button.

  2. Test the configuration in the Extreme tab.

    You can see the list of successful logins and the access level by accessing the Audit Logs pane (LOGS > Audit Logs).

Result: You have configured ExtremeCloud IQ to be accessible using Portnox Zero Trust Network Access.