QuestionQ20

Juniper Mist Configuration Basics

Your organization currently uses Access Assurance for 802.1X authentication of wireless users with user certificates. After authentication, all users are currently assigned to the same VLAN. Your sites contain multiple VLANs.

In this scenario, how should you configure Access Assurance to improve network security?

Explanation

EAP-TLS is the certificate-based 802.1X method for secure user authentication. Access Assurance can use identity-provider group information to apply identity-based authorization; assigning WxLAN roles based on AD user groups provides role-based segmentation so users are dynamically placed into the appropriate VLAN or policy segment. MAC Authentication Bypass is for non-802.1X devices, while EAP-TTLS/PAP is a credential-based method.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!