Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
MPSK Support
Cloud Authentication supports Multi Pre-Shared Key (MPSK Multi Pre-Shared Key. The Cloud Authentication and Policy server enables MPSK in a WLAN network in Aruba Central, to provide seamless wireless network connection to the end-users and client devices.).
A Multi Pre-Shared Key (MPSK) is the network password that a user or device uses to connect to the network in Classic Central. MPSK can be unique for an individual user or admin created entity. The behavior is identical to a normal PSK Pre-shared key. A unique shared secret that was previously shared between two parties by using a secure channel. This is used with WPA security, which requires the owner of a network to provide a passphrase to users for network access. network other than multiple keys that exist on the same SSID Service Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network., which allow different authorizations to be applied when using the Cloud Authentication Cloud Authentication and Policy allows you to configure user and client access policies that provide a secured, cloud-based network access control (NAC). functionality.
Cloud Authentication requires AOS-10.4 and above software versions to support the MPSK feature.
MPSK passwords are generated using the following options:
- Passphrase—is an unpredictable string or sequence of words that is longer than a traditional password. For example: "bleak tinker avenge lively".
- Random password—is similar to a traditional password that is auto-generated using a combination of letters and numbers. For example: "kdcc8mht".
Pre-Shared Keys (PSKs) can be assigned in two ways:
-
A maximum of 5000 MPSKs are supported in the foundation license. This applies to all the user managed, admin managed, and enabled MPSKs across all networks.
-
Users can connect multiple devices with a single MPSK, without pre-registering their devices.
User Managed MPSK
These PSKs are specific to the user in the identity store and are auto-generated when the user signs in to the MPSK portal with their credentials. End-users can connect multiple devices with this MPSK.
Admin Managed MPSK
This is also referred to as Named MPSK. PSKs are auto-generated when the admin creates a named MPSK entry. Admin can share this with one or more users or use it to configure multiple devices.
For more information, see Named MPSK.
User Workflow
This section describes the workflow for user managed MPSK and admin managed MPSK.
User Managed MPSK
-
Navigate to the password portal.
-
Sign-in using identity store credentials.
-
Connect one or more clients to the MPSK network using the displayed password.
Named MPSK
The admin shares MPSK passwords shown in the Named MPSK table with users. Users can use the shared MPSK passwords to connect one or more clients.
