Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Juniper Mist Access Assurance Guide
Table of Contents Expand all
list Table of Contents

Juniper Mist Authentication Proxy: Third-Party Device Support

date_range 24-Mar-25

Follow these steps to configure third-party device support for Juniper Mist Authentication Proxy.

Overview

Juniper Networks Mist Access Assurance supports user and device authentication by leveraging a Mist Auth Proxy application running on a Mist Edge device.

The Juniper Mist Cloud manages the Mist Edge device. The Mist Edge device serves as a 'gateway' for non-Mist managed devices that need to authenticate end-clients connecting to them or require management user authentication.

Examples of such devices include:

  • A third-party switch
  • A wireless LAN controller
  • An Access Point
  • Firewalls or switches requiring admin login to their CLI management interface

As the administrator, you must add third-party devices as RADIUS clients at the Mist Edge Cluster. The Mist Edge Cluster then wraps all authentication traffic into a secured RadSec tunnel and sends it to the Mist Access Assurance cloud.

Figure 1: Juniper Mist Edge as Auth Proxy—Flow of Connections Juniper Mist Edge as Auth Proxy—Flow of Connections

Juniper Mist Edge appliences require out-of-band management (OOBM) interface to act as Juniper Mist Auth Proxy.

Design Considerations

  • Mist Edge can serve as authentication proxy from multiple sites; it is not required to have an edge per site.
  • For redundancy purposes, we recommend to install at least a few Mist Edges in different data centers or points of presense (PoP).
  • All Mist Edge appliences, including VMs, provide support for Mist Auth Proxy functionality. We recommend that you use a dedicated Mist Edge appliance (or VM) for Mist Auth Proxy and avoid combining Mist Auth Proxy with Tunterm or OCProxy functionality.
  • If you are using Mist Edge VM, note that you need only a single network interface and need ME-VM-OC-PROXY to unlock the Mist Auth proxy functionality. See Juniper Mist Edge Datasheet.

About RADIUS Attributes

  • Based on the configured vendor, Mist Access Assurance automatically sends correct RADIUS Attributes in access-accept response to assign VLANs, roles (Firewall filters) and session timeouts.
  • Leverage custom vendor-specific RADIUS attribute labels to send specific attribute back in case of any special use-cases.

Settings in Juniper Mist Cloud Portal

  1. From the left menu of the Juniper Mist portal, select Mist Edges.
  2. Under Mist Edge Clusters, click an existing cluster or create a new cluster using Create Cluster option.
    Figure 2: Selecting Mist Edge Cluster Selecting Mist Edge Cluster
  3. In the cluster page, under Radius Proxy section, complete the following steps:
    Figure 3: Mist Auth Proxy Settings Mist Auth Proxy Settings
    1. Select the Enabled option.
    2. Set type as Mist Auth Proxy, then click Add Client.
    3. Provide an IP address or IP subnet for the RADIUS client (a 3rd party device).
    4. Enter RADIUS shared secret.
    5. Select vendor of the 3rd party device.
    6. Select the site where that 3rd party device is located (optional).
  4. Click check-mark to save your settings.

Now you can leverage different Network Access Server (NAS) vendors in your authentication policy rules to differentiate between various vendors/rule combinations as shown in the following example.

Figure 4: Example: Authentication Policy Rules with NAS Vendor as Match Criteria Example: Authentication Policy Rules with NAS Vendor as Match Criteria

Configuration of the NAS Device

Now you point your third-party NAS devices towards Mist Edge OOBM IP address as the RADIUS server.

In case you are deploying multiple Mist Edges, add each Mist Edge as RADIUS server in failover or load-balance mode, depending on your third-party device support.

file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
Juniper Mist Authentication Proxy: Third-Party Device Support
keyboard_arrow_right
footer-navigation
keyboard_arrow_down
file_download
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
language