MPSK Support

Cloud Authentication requires AOS-10.4 and above software versions to support the MPSK feature.

MPSK passwords are generated using the following options:

  • Passphrase—is an unpredictable string or sequence of words that is longer than a traditional password. For example: "bleak tinker avenge lively".
  • Random password—is similar to a traditional password that is auto-generated using a combination of letters and numbers. For example: "kdcc8mht".

Pre-Shared Keys (PSKs) can be assigned in two ways:

  • A maximum of 5000 MPSKs are supported in the foundation license. This applies to all the user managed, admin managed, and enabled MPSKs across all networks.

  • Users can connect multiple devices with a single MPSK, without pre-registering their devices.

User Managed MPSK

These PSKs are specific to the user in the identity store and are auto-generated when the user signs in to the MPSK portal with their credentials. End-users can connect multiple devices with this MPSK.

Admin Managed MPSK

This is also referred to as Named MPSK. PSKs are auto-generated when the admin creates a named MPSK entry. Admin can share this with one or more users or use it to configure multiple devices.

For more information, see Named MPSK.

User Workflow

This section describes the workflow for user managed MPSK and admin managed MPSK.

User Managed MPSK

  1. Navigate to the password portal.

  2. Sign-in using identity store credentials.

  3. Connect one or more clients to the MPSK network using the displayed password.

Named MPSK

The admin shares MPSK passwords shown in the Named MPSK table with users. Users can use the shared MPSK passwords to connect one or more clients.