Overlay Authentication

Overlay authentication is a security mechanism used within a virtualized network layer (overlay) in a Central NAC architecture. It verifies the identity of users or devices before granting access to network resources, independent of the underlying physical network. This approach enables identity-based access control, microsegmentation, and secure communication, ensuring that only authenticated entities can interact with specific services or applications within the overlay network.

To configure an overlay wired authentication, see Configuring Overlay Wired Authentication.

Note:

Overlay Authentication is supported from AOS-10.8.0.0 and further releases.

Prerequisites

  • Ensure to set up an access point and gateway required to establish the overlay tunnel.

  • Create a new group and move the AP and gateway under this group. For more information, see Group Personas

Configuration

To configure an overlay authentication, ensure to do the following:

  1. Configuring High Availability

  2. Creating an Access Type WLAN Profile

  3. Configuring Authentication Profiles

  4. Configuring Authorization Policy

Authentication

After successful configuration, you can proceed to connect to each of the WLAN profiles created and connect the device to the overlay network.