Arista CloudVision AGNI, Arista’s Next Generation NAC In Action
One of the core tenets of CloudVision AGNI is to be able to integrate with other enterprise security tools for profiling, access control and dynamic network access for a true Zero Trust Networking Solution. In this video, we will demo how CV AGNI can integrate with CrowdStrike for dynamic access control and also showcase Arista’s patented UPSK solution with segmentation.
Presented by Parul Sharma, Technical Marketing Engineer and Anubhav Gupta, Product Manager. Recorded live at Mobility Field Day 13 in Santa Clara, CA on May 8, 2025. Watch the entire presentation at https://techfieldday.com/appearance/arista-presents-at-mobility-field-day-13/ or visit https://techfieldday.com/event/mfd13/ or https://www.arista.com/assets/data/pdf/Arista-AGNI-Solution-Brief.pdf for more information.
Transcript
So this year in January, we launched our Agni on-prem. We got a, a lot of requests from our customers who had some, uh, concerns about like, uh, uh, cloud connectivity or security, or they were running some critical operations, right? So they wanted to have the on-prem solution.
So we are proud of, uh, announcing this launch. It's, uh, right now it's offered as on appliance 32, uh, 32 case case sessions capacity. You can deploy in HAGR in, uh, any mode.
And, uh, the good thing is that there's a inside out connection called the Arista, SRE. So we can help with the upgrade, update maintenance, maintenance, and uh, keeping, uh, monitoring your health, uh, your, uh, appliance status, all the authentication, everything, all the data. It remains on-prem, on the appliances.
So, Arista, SRE team will not have any visibility in that. It's just that for the monitoring purpose, we will have a connection. And if, if, God forbid, for any reason, internet goes down, so definitely because that's on-prem.
So our, for the critical operations, nothing will be impacted. So what is the difference, right? We already had the traditional n and now Agni offers SaaS as well as on-prem.
So with the traditional n the problem was like, okay, it was on-prem, but complex and costly. It was also difficult to, uh, configure, especially those, uh, segment policies or authorization policy. And if you can't, if you do one thing wrong, then everything is blocked, right?
So things were, so now versus Agni, as it says, we have been, uh, we have more than, uh, like in the past, uh, almost two years we launched. So customer really loved the true elastic scale. It uses the cloud native architecture and very simple to configure net policies.
So we took all these similar things in our Agni on-prem, as you can see. And let me just, uh, right here. So now with Agni on-prem, you can have the same scale as the traditional N but with 50% less hardware.
So if you, earlier, you needed probably 10 appliances or something. Now you can have much lesser, same again, just like cloud, uh, SaaS, simple NEC policy upgrade update. Its provided a service so you don't have to worry about it.
And right now we support up to eight node cluster, and it can be deployed, as I mentioned, that, um, across data center, different, uh, geographies moving forward. Now, I wanted to talk about the very key feature of Agni. UPSK.
UPSK is basically a unique pass phrase per user. Think of it as a, uh, simple and, uh, uh, smart way to control the network access for devices like BYOD or, uh, guest user devices, or even for the dorm residence in the, uh, university environment at core, the UPSK, actually it works in both WPA two and WPA three, environment six gigahertz. Mm-hmm.
And if I have time, I'll probably run the, uh, live demo. Does this support wifi seven and MLO and all of those features as well? Uh, we haven't done that tested, but probably, So what we've heard from everybody else is that any M-P-S-K-U-P-S-K, any of the SAE multi key solutions break, MLO.
So here, that's the beauty of this solution. Yeah. So it does not, so in, uh, UPSK, right, the client registration is automatically, which means that, as I mentioned, that it works on WPA two, WPA three mm-hmm.
In WPA three, the crack doesn't work. So what we do in this, we made this, uh, onboarding process very seamless, which means if a user has, uh, UPSK, right? They can be, uh, uh, they can use that UPSK, they can go to the portal, generate the UPSK, register their client, and that's it.
Their back address will be registered automatically. They don't have to do the manual registration at all. So, so what about, so what about MAC roaming, or, I'm sorry, uh, Mac, uh, rotation.
Rotation, thank you. That's the word of, that's the R word I was looking for. Uh, and, and all of the other issues that come there.
So I can take that question. Um, I, I can take that question. Uh, see, MAC randomization does not matter as long as if you're even MAC has rotated, right?
Uh, again, um, it'll redirect you to the portal, and the portal will plug in, um, as soon as it, I'm saying that as soon as the MAC rotates right, the system understands that and, you know, redirect you to the portal and automatically the new Mac will be registered. So we don't depend upon the same Mac. So as soon as the new Mac comes, we add it to the list automatically.
Okay. So you see this more as a, uh, as a user interactive solution, not a headless, uh, device IOT based solution, Correct? Well, It's more of a use for WPA three.
It is, uh, more of a user interactive. But in case of WPA two, it is, it works for headless device as well, seamlessly. Yeah, That's right.
So that was about the easy onboarding. Segmentation is also built in. That means all the devices connected within on same, uh, wlan, same vlan, you can block the communication if they are connected using different UPSK.
And not only that, uh, those isolated devices, because it's very critical that they should have access to the, uh, shared resources like printer, scanner in dorm environment, or a projector, right? So this built-in segmentation provides that as well, and that like, kind of saves a big headache that, okay, you don't have to manage multiple VLANs for different type of devices, right? Second thing is, uh, next thing is the security aware, which means if every, anytime your key gets compromised, it's okay, you can go to the self-service portal and just change your key.
So the devices which were connected using the old key, they will be disconnected, and your new key is the valid one. Now, last one is the guest access. And I showed that live demo last time.
So we made this, uh, we use this UPSK for the onboarding user, guest user as well. Before you go on, can we, can we understand how this is working since this isn't natively supported by the standards for WPA three and especially six gigahertz? Uh, Yes.
Yes. I actually have a demo. I wanted to show a live demo, but I do have the recorded one, so I'll just play and I'll show you how onboarding, uh, does work.
Yeah, I more, I more wanna understand what's happening on the backend since, because in WPA three, it's SAE and not PSK. So the, that, that king material can't be hashed and matched backwards. So is it, are you guys connecting with WPA two and then re upgrading them and, and pushing them over?
Uh, no. So when the initially client connects, it'll, it'll use the on, uh, onboarding of the common PSK. So now AP does not know about that, right?
So AP does send the request to our Agni, Agni will know, okay, this is, this client is new. So that means it has to use the common PSK, so it'll send that common PSK to ap. Now they will do the handshake and uh, uh, the client will be redirected to the portal.
When the, uh, user is on the self-service portal, it'll do the registration. At that time, Agni will automatically register the Mac address. Okay?
And that's the Way, okay, okay, I got that. Now I missed, I said earlier. Thanks.
Yeah. So for a guest user, similar thing that when they now guest user, they don't have to go through the annoying capture portal that you go and, uh, enter our information right here, guest walks in and on a, uh, probably self-registration, uh, set up on the kiosk, they can enter their email and boom, they get the QR code scan, the QR code, and they also get the QR code in their email. So now you scan the QR code, you are connected with your own UPS case.
So it's more secure than connecting to a open SSID or to a common, uh, pa like WPA two one. So let's move forward. So, um, for this demo, I had this apology you see to, uh, multiple devices.
And the different color shows that they are connected on the same wlan, same vlan. They'll get the same IP address from the same pool, and uh, they are isolated. Okay?
This is my, I'll try to do this one connect, and I'm using common pass phrase, hope it connects. All right? Uh, okay.
You see here, it's not, it didn't get, uh, complete. So I'm redirected to portal. I log in as Barbara Once I verify who I am, right?
And then automatically it tells me that, okay, you can register your client. I follow the instructions, copy your UPSK continue. And it tells, uh, like a very few instructions.
Basically what happens, some of the OS in AL always depends on the client. The, some of the client, when they, uh, cash the information, all PSK common pass phrase, and they will keep trying. And what happens, some of the OS will say, Hey, you got the wrong PSK, try new one.
Prompt. But some of them don't prompt. So we always have this instruction copy, paste and proceed.
And then you can go ahead and, uh, forget the network that is listed over here. Let me go here and say manage no network. I'll forget.
So you're not changing the SSID No, we are not changing the SSID, that's the beauty. But one single Ss I, but the End user must go through this forget cycle to to restart, restart the process. Well, they have to change their, their key.
Yeah. So, and they have, they have to do that somehow, and they Have to have a use the pre share key first before they can get to the portal to begin with. Yeah.
Yeah. But the thing about that is if you reset, if you forget the network and rejoin, now you have a new Mac address. Uh, Actually no, for the same SSID most of the time, like you just saw, I forgot the network, and I, I pasted the copied UPSK, it uses the same back address, but in, in case is new.
That's, That's end client. It's client, absolutely. Client.
Yeah, I can, I can show you a few that won't. Yeah. Mm-hmm.
So now let's see over here, Uh, sessions. Okay, so I have Barbara, which has, see if you see I have, uh, multiple users here. I have Barbara, which has two devices, 31 64, 31, 63, and shared device, 31 61 and Alex.
So they all are in the same vlan. They all have the, right now let, I'll go back to my, uh, where's my Barbara? Okay, now let's see if Barbara can ping.
So Barbara can ping share devices? Yes. Can Barbara ing its own devices?
Yes. Now can barber wrapping Alex device? Nope.
So that's all we see that UPSP solves, uh, first of easy onboarding both in WPA two WP three, and also it provides a segmentation while still providing the access to the, uh, common, uh, shared resources. Now, Even though they're in the same VAM mm-hmm. It's, you're just blocking client to client traffic.
Yes. Between the Yeah. Different users.
I just wanna come back to a question. JD Ally, which was it once, if you have got MAC randomization when your MAC address does change mm-hmm. I, I think the answer is you'd go back to the portal, but you wouldn't, would you?
Because you would be using the wrong v shared key or in your device. Sorry. Uh, So if you've, you've got pre shared key stored in your device, which is your new pre shared key, then your MAC address forta mm-hmm.
You are not gonna be able to connect at that point until you've put in the initial pre shared Key. Yeah. You have to go back and use the initial pre A user.
You have to forget the network User. You are not gonna know that every time. You're not gonna know that your MAC addresses changed how you un rotated.
Yeah. Help desk call every, every time. Yeah.
Step one, Turn off Mac randomization. Yeah, No, I, I Can say there are lot of organizations that tell that, tell their users you need to disable that. Yeah.
Or push it with, so I can answer that question. So either, either the solution Jennifer, um, is to have a turnoff macro randomization in this case, or you can, the same solution works with, if you want a separate a society also two, a society solution where one is onboarding and one is, uh, a far connecting, that also works. So eventually, if your client is not connecting, you just switch to the previous one, it redirects and the job is done.
And then Mac Register, you can connect back, uh, to the actual SSID. So that's how, uh, it's, uh, you, I mean, user need not to copy Mac as and add it into the portal again and again. And we also have a feature that, um, well, this not allow clients using Random Mac to join the network.
It, it's, you, you can turn that on as well if you want to enforce no random max on your network.