Universal ZTNA supports Fabric Engine/VOSS and Switch Engine/EXOS NOSs. The minimum versions are:
Managed Mode
Supported NOS: Switch Engine. Switches are onboarded directly from the cloud workflow using the Manage your Devices workflow.
ExtremeCloud IQ manages switch configuration. The Instant Secure Port workflow provisions the following components on the switch:
Universal ZTNA updates the policy configuration on the switch, including static policy roles and rules, based on the provisioned network policy.
Locally Managed Mode
Supported NOS: Switch Engine and Fabric Engine. Switches are onboarded using the Manage your Devices Locally workflow.
ExtremeCloud IQ does not configure switches in local managed mode. In local manage mode, during the authentication process, based on the provisioned network policy, Universal ZTNA provisions policy on the switch using dynamic ACLs (dACL) conveyed using Radius VSAs.
Configuration Details for Fabric Engine and Switch Engine