Juniper-Networks-logo

Juniper Networks Mist Access Assurance

Juniper-Networks-Mist-Access-Assurance-product

Imininingwane

  • Igama Lomkhiqizo: Mist Access Assurance Client Onboarding – NAC Portal
  • Inguqulo: 1.0
  • Umthengisi: Juniper

Ulwazi Lomkhiqizo
The Mist Access Assurance Client Onboarding – NAC Portal is a solution provided by Juniper for secure client-driven self-provisioning within organizations. It includes features such as PSK Portal, MPSK, BYOD support, PSK Admin, NAC Portal, EAP-TLS, Marvis Client for various platforms (iOS/iPadOS/Android), and more.

Imiyalo yokusebenzisa

NAC Portal Configuration
To configure the NAC Portal for client onboarding, follow these steps:

  1. Navigate to Organization > Certificates and set up Onboard CA Configuration (Active).
  2. Configure the Onboard Certificate Authority under Onboard CA Configuration.
  3. Add the NAC Onboarding Portal under NAC settings.
  4. Set up Portal Settings, including Name, Portal Type, and NAC Portal URL.
  5. Configure Portal Authorization settings like SSO and SAML.

Inqubo yokugibela
Follow these steps for the onboarding process:

  1. Download and install the Marvis Client App if not already installed.
  2. Proceed with SCEP for Wi-Fi profile and client certificate setup.

Ukuphathwa Kwesitifiketi
For managing certificates, navigate to Organization > Certificates, where you can view, revoke, or manage internal certificates.

Mist Access Assurance Client Onboarding – NAC Portal

Inguqulo 1.0

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

1

Client Onboarding – NAC Portal

20259 Mist Cloud https://www.juniper.net /documentation /us /en /software /mist /product-updates /latest.html

Mist Documentation
Juniper Mist Access Assurance Guide

Inkungu https://www.juniper.net/jp/ja/local/solution-technical-information/mist.html

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

2

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

3

umlando

Inguqulo
Isiqephu 1.0

20259

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

4

© 2025 Juniper Networks

Ukungena Kwekhasimende
5 Juniper Business Sebenzisa Kuphela

Ukungena Kwekhasimende
Client-driven self provisioning

NAC Portal

PSK Portal
MPSK

I-BYOD
· PSK Portal · SSO(SAML) (password + MFA etc..) · QR SSID/passphrase passphrase email (Optional) · MPSK SSID

PSK Admin

NAC Portal
I-EAP-TLS

· PSK Portal · SSO(SAML) (password + MFA etc..) · SSID/passphrase passphrase email · MPSK SSID
Marvis Client
Marvis Client Marvis Client(iOS/iPadOS/Android)
· NAC Portal · SSO(SAML) (password + MFA etc..) · Marvis Client & profile/certificate · WPA3/WPA2 802.1X(Mist Auth) SSID

NOTE: Marvis Client Client Onboarding 20259()

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

6

© 2025 Juniper Networks

NAC Portal
NOTE: 20259()
7 Juniper Business Sebenzisa Kuphela

NAC Portal
Organization > Certificates
[Organization] [Certificates]

Onboard CA Configuration (Active)

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

8

NAC Portal
Onboard Certificate Authority

Onboard CA Configuration ()

[ ] [Onboard CA Configuration] [Onboard Certificate Authority] [Active] [OK]Juniper-Networks-Mist-Access-Assurance-fig-1

Ingaphandle/Yangaphakathi

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

9

NAC Portal
I-NAC
[Organization] [Client Onboarding] [NAC] [Add NAC Onboarding Portal]

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

10

NAC Portal
Name / Portal Settings [Name] [Portal Type] [Marvis Client] [Create] NAC Portal URL URL
NAC Portal URL

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

11

NAC Portal
Portal Authorization
[Portal Authorization] SSO
· [ URL] [SSO URL] · [Microsoft Entra ][Issuer]

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

Entra ID Mist 1
Entra Name ID Format
URL
12

NAC Portal
Portal Authorization
[Portal Authorization] SSO
· (Base64) [][Certificate] · [] [SAML ][] SAML

Entra ID Mist 2

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

13

NAC Portal
Portal Authorization
[Portal SSO URL] Entra ID [] [ URL]

Mist Entra ID

© 2025 Juniper Networks

Portal SSO URL
14 Juniper Business Sebenzisa Kuphela

NAC Portal
Onboarding Parameters
[Onboarding Parameters] [Save]

WLAN Template

Amapharamitha
I-SSID
Security Type Client Certificate Format Certificate expires in X days

Incazelo
WLAN Template SSID ­ WPA2/WPA3 > Enterprise(802.1X) ­ Authentication Server: Mist Auth WPA2/WPA3
(: 365)

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

15

NAC Portal
Organization > Auth PoliciesJuniper-Networks-Mist-Access-Assurance-fig-2

Auth Policy

[Organization] [Auth Polices] [Add Rule] Auth Policy

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

16

NAC Portal
Inqubo yokugibela

[NAC Portal URL] [NAC Portal URL] Client Onboarding() SSO

IdP(Entra ID etc)

NAC Portal URL

URL

Portal SSO URLJuniper-Networks-Mist-Access-Assurance-fig-5

SSO(SAML)

© 2025 Juniper Networks

+ MFA()
Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

Landa futhi ufake uhlelo lokusebenza
Marvis Client
Already have the app?

17

NAC Portal
Inqubo yokugibela

I-SCEP

Marvis Client ()Wi-Fi

Marvis Client

I-Wi-Fi Profile

Isitifiketi Seklayenti

© 2025 Juniper Networks

I-Wi-Fi
Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

18

NAC Portal
Organization > Certificates
[Organization] [Certificates] [Internal]

© 2025 Juniper Networks

NAC Portal
19 Juniper Business Sebenzisa Kuphela

NAC Portal
Organization > Certificates > Revoke Certificate

[Revoke Certificate]

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

20

© 2025 Juniper Networks

Appendix Entra ID SAML SSO
21 Juniper Business Sebenzisa Kuphela

Entra ID SAML SSO
Entra ID > > Entra ID [] []

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

22

Entra ID SAML SSO

Mist Cloud Admin SSO

[] [] [] []

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper KuphelaJuniper-Networks-Mist-Access-Assurance-fig-3

23

Entra ID SAML SSO
[]

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

24

Entra ID SAML SSO
SAML [SAML]

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

25

Entra ID SAML SSO

SAML

I-ID yokungena

SAML

Portal SSO URL
( ID) URL

Microsoft Entra Issuer
SAML
(Base64) Certificate
URL SSO URL

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper Kuphela

Inkungu
26

© 2025 Juniper Networks

Ukusetshenziswa Kwebhizinisi LeJuniper KuphelaJuniper-Networks-Mist-Access-Assurance-fig-4

27

Amadokhumenti / Izinsiza

Juniper Networks Mist Access Assurance [pdf] Umhlahlandlela Womsebenzisi
Mist Access Assurance, Access Assurance, Assuranc

Izithenjwa

Shiya amazwana

Ikheli lakho le-imeyili ngeke lishicilelwe. Izinkambu ezidingekayo zimakiwe *