Integrate ExtremeCloud IQ Wireless with Universal ZTNA

Before you begin

Complete the onboarding steps found in Configure UZTNA Access, specifically Deploy RadSec Proxies.

About this task

To integrate ExtremeCloud IQ Wireless with Universal ZTNA, do the following:

Procedure

  1. From the ExtremeCloud IQ portal main navigation, select Configure > Common Objects > Policy > SSIDs.
  2. Select your SSID and select the edit (pencil) icon.
  3. Under SSID Usage, ensure the SSID Authentication and Enterprise tabs are selected.
  4. Under Authentication Settings, create an external RADIUS Server Group with your Radsec proxy IP address by selecting Plus Iconunder Authenticate via RADIUS Server. This is the same IP address used for the Radsec proxy deployment in Deploy RadSec Proxies.
  5. In the Configure RADIUS Servers window, configure the server details and select Save.
  6. Identify the required filter-ID value needed.
    You will use this filter-ID in the assignment rule for the name of the Universal ZTNA policy in the next step. You can find the filter-ID in the User Profile Assignment Rule section of the SSID configuration under the Value column heading.
  7. Create Universal ZTNA policies using the ExtremeCloud IQ filter-IDs as the policy name.
    The policy name is used in the RADIUS response for user authentication: as follows:
    • SelectAdd Policy > Network Policy
    • Set the name of the policy to the filter-ID from the assignment rule and add access groups and conditions. The network section is ignored for ExtremeCloud IQ policies; only the name, access groups (user groups or device groups), and conditions are used. If this policy is being used with another operating system,complete the network sections..
  8. (Optional) You can force a reauthorization in ExtremeCloud IQ wireless by doing the following:
    1. From the ExtremeCloud IQ main navigation, select ML Insights > Network 360 Monitor
    2. Select the floor map where the client access point is located.
    3. Select the access point and select Disconnect next to your client's station address.