Distributed link failure resilient low latency network access control with authentication offloading
By caching the policy actions of the NAC system on the NAS device, the authentication difficulties and latency issues caused by link disconnection in cloud-based NAC systems are resolved, achieving low-latency and efficient network access control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-09
- Publication Date
- 2026-03-27
AI Technical Summary
Cloud-based network access control systems can lead to difficulties in network access authentication for client devices when links are disconnected or there is significant latency, resulting in problems such as high latency and high costs.
The last policy action identified by the Network Access Control System (NAC) for client devices is cached on the Network Access Server (NAS) device to enable local authentication and authorization, reducing reliance on cloud systems.
Even when the cloud system is unavailable, NAS devices can still quickly authenticate and authorize client devices to access the network, reducing latency and cloud utilization, and improving system resilience and efficiency.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
[0001] This application is a PCT application having U.S. utility priority to U.S. Patent Application No. 18 / 395,023, filed December 22, 2023, and claims the benefit of U.S. Provisional Patent Application No. 63 / 519,081, filed August 11, 2023, the entire contents of each of which are incorporated herein by reference. Technical Field
[0002] This disclosure generally relates to computer networks, and more particularly to the management of access to computer networks. Background Technology
[0003] A network access server (NAS) device authenticates client devices (or simply "clients") and grants them access to the network. Authentication can occur via a handshake exchange between the client device, the NAS device, and the authentication, authorization, and accounting (AAA) server that controls access to the NAS device. NAS devices can include wireless access points (APs), switches, routers, or any network device capable of authenticating and authorizing client devices to access the corporate network.
[0004] For example, commercial locations or sites, such as offices, hospitals, airports, stadiums, or retail stores, typically install complex wireless network systems throughout the premises, including a network of wireless access points (APs) to provide wireless network services to one or more wireless client devices. An AP is a physical electronic device that uses various wireless network protocols and technologies, such as Wireless LAN protocols (i.e., "WiFi") conforming to one or more standards in the IEEE 802.11 standard, Bluetooth / Bluetooth Low Energy (BLE), mesh networking protocols such as ZigBee, or other wireless network technologies, to enable other devices to wirelessly connect to the wired network.
[0005] Many different types of wireless client devices, such as laptops, smartphones, tablets, wearables, appliances, and Internet of Things (IoT) devices, incorporate wireless communication technologies and can be configured to connect to a wireless access point when the device is within range of a compatible access point (AP). To gain access to the wireless network, the wireless client device may first need to authenticate with the AP. In this case, the AP acts as a Network Access Server (NAS) device, which authenticates the client device and grants it access to the network. Summary of the Invention
[0006] Cloud-based Network Access Control (NAC) systems provide centralized maintenance of access policies for networks across multiple organizational sites. Access policies outline the rules and guidelines for managing client devices' access to the network and / or network resources, and define the conditions under which network access can be granted or denied to client devices. NAC systems can also handle certificate exchange and authentication with client devices requesting to join the network via a Network Access Server (NAS) device at a site. However, cloud-based NAC systems can cause difficulties when the link from the NAS device at the site to the cloud-based NAC system is broken or experiences significant latency.
[0007] This disclosure describes a technique for certificate-based authentication performed by the NAS device itself and client devices. Furthermore, this disclosure describes a technique for the NAS device to cache last access policy actions previously identified by the NAC system for client devices, and for authorizing network access for client devices based on the cached last access policy actions.
[0008] According to the disclosed technology, even when the link from the NAS device to the NAC system that maintains network access policies is lost, the NAS device can quickly authenticate and authorize client devices to access the network. As described, the NAS device may include a policy cache that stores the latest or last policy action for one or more client devices at the site. The policy cache allows the NAS device to determine the latest or last policy action for a client device when the connection to the NAC system is unavailable, and can provide client device authorization with lower latency without waiting for a response from the NAC system. The policy cache at the NAS device may have entries for one or more client devices, where each entry includes the last policy action previously identified by the NAC system for the corresponding client device.
[0009] When the NAS device receives an access request for the wireless network from a client device, the NAS device can authenticate the client device based on the exchange of authentication certificates associated with the NAC system and the client device. Alternatively, or in combination, the NAS device can authenticate the client device based on password authentication. The Network Management System (NMS) can provide the NAS device with lists of server certificates and client certificates. Initial authentication may be sufficient to indicate that the client device is known (e.g., the client device is an employee's client device), so the NAS device can grant the client device default policy access (which may be greater than guest access to the network only).
[0010] If the client device is in the policy cache, the NAS device can authorize the client device to access the wireless network based on the last policy action taken against the client device. Therefore, when access to the NAC system is unavailable (e.g., due to the WAN link between the NAS device and the NAC system being shut down or the NAC system being shut down), the NAS device can still authorize the client device to access the wireless network based on the cached policy action.
[0011] The described system offers several technical advantages. A cloud-based NAC system can advantageously maintain access policies at the cloud-based NAC system rather than on the local device, enabling centralized updating, management, and storage of access policies. Policy caching at the NAS device provides resilience by authorizing client devices to access the network "offline," as the NAS device can use cached policy actions even when the NAC system is inaccessible. Furthermore, even when the NAC system is available, using the policy cache at the NAS device to authorize client devices to access the network reduces latency experienced when requesting policy decisions from the NAC system, since the NAS device is local at the site, unlike the remote NAC system. Moreover, implementing certificate-based authentication on a local NAS device can lead to reduced cloud utilization and associated costs for the NAC system compared to using a cloud-based NAC system for certificate-based authentication.
[0012] In one example, this disclosure relates to a NAS device on a wireless network at a site, the NAS device comprising: a memory including a policy cache having entries for one or more client devices, wherein each entry includes a last policy action previously identified by a network access control (NAC) system for the corresponding client device; and processing circuitry configured to: authenticate the client device upon receiving an access request for the wireless network from the client device; determine, after authentication of the client device, whether the client device is included in the policy cache; and, based on the client device being included in the policy cache, authorize the client device to access the wireless network according to the last policy action of the client device.
[0013] In another example, this disclosure relates to a system comprising: a network access control (NAC) system that communicates with multiple network access server (NAS) devices of a wireless network at one or more sites, the NAC system being configured to maintain access policy rules for the wireless network; and a NAS device among the multiple NAS devices of the wireless network at the site, the NAS device being configured to: authenticate a client device upon receiving an access request for the wireless network from a client device; after authentication of the client device, determine whether the client device is included in a policy cache at the NAS device, the policy cache having entries for one or more client devices, wherein each entry includes a last policy action previously identified by the NAC system for the corresponding client device; and, based on the client device being included in the policy cache, authorize the client device to access the wireless network according to the last policy action of the client device.
[0014] In yet another example, this disclosure relates to a method comprising: upon receiving an access request for a wireless network at a site from a client device, authenticating the client device by a network access server (NAS) device on the wireless network based on the exchange of authentication certificates associated with a network access control (NAC) system and the client device; after authentication of the client device, determining by the NAS device whether the client device is included in a policy cache at the NAS device, the policy cache having entries for one or more client devices, wherein each entry includes a last policy action previously identified by the NAC system for the corresponding client device; and based on the client device being included in the policy cache, authorizing the client device to access the wireless network by the NAS device according to the last policy action of the client device.
[0015] Details of one or more examples of the technology disclosed herein are set forth in the accompanying drawings and the following description. Other features, objects, and advantages of these technologies will become apparent from the specification, drawings, and claims. Attached Figure Description
[0016] Figure 1A This is a block diagram of an example network system including a network management system, a network access control system, and a network access server device, based on one or more technologies disclosed herein.
[0017] Figure 1B It is a diagram. Figure 1A A block diagram showing further details of another example of a network system.
[0018] Figure 2 This is a block diagram of an example network access control system based on one or more technologies of this disclosure.
[0019] Figure 3This is a block diagram of an example network management system based on one or more technologies disclosed herein.
[0020] Figure 4 This is a block diagram of an example network access server based on one or more technologies disclosed herein.
[0021] Figure 5 This is a block diagram of an example edge device based on one or more technologies according to this disclosure.
[0022] Figure 6 This is a flowchart illustrating an example policy access process based on one or more techniques disclosed herein.
[0023] Figure 7 This is a flowchart illustrating an example operation of policy caching for a network access server according to one or more techniques disclosed herein. Detailed Implementation
[0024] Figure 1A This is a block diagram of an example network system 100 including a network access control (NAC) system 180A-180K (collectively referred to as "NAC system 108") and a network management system (NMS) 130, according to one or more technologies disclosed herein. The example network system 100 includes multiple sites 102A-102N (collectively referred to as "sites 102"), at which a network service provider manages one or more wireless networks 106A-106N, respectively. Although in Figure 1A In this work, each site 102A-102N is shown as comprising a single wireless network 106A-106N, but in some examples, each site 102A-102N may include multiple wireless networks, and this disclosure is not limited in this respect.
[0025] Each site 102A-102N includes multiple Network Access Server (NAS) devices 108A-108N, such as Access Points (APs) 142, switches 146, and routers 147. NAS devices can include any network infrastructure devices capable of authenticating and authorizing client devices to access the corporate network. For example, site 102A includes multiple APs 142A-1 to 142A-M, switch 146A, and router 147A. Similarly, site 102N includes multiple APs 142N-1 to 142N-M, switch 146N, and router 147N. Each AP 142 can be any type of wireless access point, including but not limited to commercial or enterprise APs, routers, or any other device connected to a wired network and capable of providing wireless network access to client devices within the site. In some examples, each AP among APs 142N-1 to 142N-M at site 102A may be connected to one or both of switch 146A and router 147A. Similarly, each of the APs 142N-1 to 142N-M at site 102N can be connected to one or both of switch 146N and router 147N.
[0026] Each site 102A-102N also includes multiple client devices, also known as user equipment (UE), generally referred to as client devices 148, representing various wireless-enabled devices within each site. For example, multiple client devices 148A-1 to 148A-K are currently located at site 102A. Similarly, multiple client devices 148N-1 to 148N-K are currently located at site 102N. Each client device 148 can be any type of wireless client device, including but not limited to mobile devices such as smartphones, tablets or laptops, personal digital assistants (PDAs), wireless terminals, smartwatches, smart rings, or other wearable devices. Client devices 148 may also include wired client-side devices, such as IoT devices (such as printers, security devices, environmental sensors) or any other device connected to a wired network and configured to communicate over one or more wireless networks 106.
[0027] To provide wireless network services to client device 148 and / or communicate via wireless network 106, AP 142 and other wired client-side devices at site 102 are directly or indirectly connected to one or more network devices (e.g., switches, routers, gateways, etc.) via physical cables (e.g., Ethernet cables). Although in Figure 1AThe diagram illustrates each site 102 as including a single switch and a single router; however, in other examples, each site 102 may include more or fewer switches and / or routers. Furthermore, two or more switches at a site may be interconnected with each other and / or connected to two or more routers, for example, via a mesh or partial mesh topology in a center-radial architecture. In some examples, the interconnected switches 146 and routers 147 comprise a wired local area network (LAN) located at site 102 hosting the wireless network 106.
[0028] Example network system 100 also includes various networking components for providing networking services within a wired network. As an example, it includes NAC systems 180A-180K, which include or provide access to an Authentication, Authorization, and Accounting (AAA) server for authenticating users and / or client devices 148; a Dynamic Host Configuration Protocol (DHCP) server 116 for dynamically assigning network addresses (e.g., IP addresses) to client devices 148 during authentication; a Domain Name System (DNS) server 122 for resolving domain names to network addresses; multiple servers 128A-128X (collectively referred to as "Server 128") (e.g., web servers, database servers, file servers, etc.); and an NMS 130. Figure 1A As shown, various devices and systems of network 100 are coupled together via one or more networks 134 (e.g., the Internet and / or corporate intranets).
[0029] exist Figure 1A In the example, NMS 130 is a cloud-based computing platform that manages wireless networks 106A-106N at one or more of sites 102A-102N. As further described herein, NMS 130 provides an integrated suite of management tools and implements various technologies disclosed herein. Generally, NMS 130 can provide a cloud-based platform for wireless network data acquisition, monitoring, activity logging, reporting, predictive analytics, network anomaly identification, and alarm generation. In some examples, NMS 130 outputs notifications, such as alerts, warnings, graphical metrics on dashboards, log messages, text / SMS messages, email messages, etc., and / or suggestions regarding wireless network issues, to a site or network administrator (“admin”) who interacts with and / or operates admin device 111. Additionally, in some examples, NMS 130 operates in response to configuration input received from an administrator who interacts with and / or operates admin device 111.
[0030] The administrator and administrator device 111 may include IT personnel and administrator computing devices associated with one or more sites in site 102. Administrator device 111 may be implemented as any suitable device for presenting output and / or accepting user input. For example, administrator device 111 may include a display. Administrator device 111 may be a computing system, such as a mobile or non-mobile computing device operated by a user and / or administrator. Administrator device 111 may, for example, represent a workstation, laptop or notebook computer, desktop computer, tablet computer, or any other computing device that can be operated by a user and / or present a user interface according to one or more aspects of this disclosure. Administrator device 111 may be physically separate from and / or located in a different location from NMS 130, such that administrator device 111 can communicate with NMS 130 via network 134 or other communication methods.
[0031] In some examples, one or more NAS devices in NAS device 108, such as AP 142, switch 146, and router 147, can be connected to edge devices 150A-150N via physical cables (e.g., Ethernet cables). Edge device 150 includes a cloud-managed wireless local area network (LAN) controller. Each edge device in edge device 150 may include an internal device at site 102 that communicates with NMS 130 to extend certain microservices from NMS 130 to the local NAS device 108, while utilizing NMS 130 and its distributed software architecture for scalable and resilient operation, management, troubleshooting, and analysis.
[0032] Each network device in network system 100, such as NAC system 180, servers 116, 122 and / or 128, AP 142, switch 146, router 147, client device 148, edge device 150, and any other server or device attached to or forming part of network system 100, may include a system log or error log module, wherein each of these network devices records the status of the network device, including normal operating status and error conditions. Throughout this disclosure, one or more network devices in network system 100, such as servers 116, 122 and / or 128, AP 142, switch 146, router 147, and client device 148, may be considered "third-party" network devices when owned and / or associated with an entity other than NMS 130, such that NMS 130 does not directly receive, collect, or otherwise access the recorded status and other data of the third-party network devices. In some examples, edge device 150 can provide a proxy that can report the log status and other data of third-party network devices to NMS 130.
[0033] exist Figure 1A In the example, each NAC system in NAC system 180 includes a cloud-based network access control service at multiple geographically distributed points of presence. Typically, network access control functions are provided by local devices, which are limited by processing power, memory, and maintenance and upgrade issues. Providing cloud-based network access control services avoids these limitations and improves network management. As described in more detail below, centralized, cloud-based deployments of network access control functions can introduce problems with latency and connectivity failures that can prevent client devices from accessing the network.
[0034] The NAC System 180 provides multiple points of presence or NAC clouds across several geographic regions. The NMS 130 is configured to manage NAC configurations, including access policies for the enterprise network, and push appropriate NAC configuration data or files to the corresponding NAC clouds 180A-180K. In this way, the NAC System 180 provides the same benefits as a centralized, cloud-based network access control service with lower latency and higher availability.
[0035] Client devices 148 can include various categories of devices for a given enterprise, such as trusted enterprise devices, Bring Your Own Device (BYOD) devices, IoT devices, and guest devices. The NAC system 180 can be configured to subject each category of device to different types of tracking, different types of authorization, and different levels of access. In some examples, after a client device gains access to the enterprise network, the NAC system 180 can monitor the client device's activity to identify security issues and, in response, reassign the client device to an isolated VLAN or another VLAN with fewer privileges to restrict the client device's access.
[0036] The NMS 130 is configured to operate based on an AI / machine learning-based computing platform that provides comprehensive automation, insights, and assurance (WiFi assurance, wired assurance, and WAN assurance) ranging from “clients” (e.g., client devices 148 connected to wireless network 106 and wired local area network (LAN) at site 102) to “the cloud” (e.g., cloud-based application services that can be hosted by computing resources within a data center).
[0037] The NMS 130 provides an integrated set of management tools and implements various technologies disclosed herein. Generally, the NMS 130 provides a cloud-based platform for wireless network data acquisition, monitoring, activity logging, reporting, predictive analytics, network anomaly identification, and alarm generation. For example, the NMS 130 can be configured to proactively monitor and adaptively configure network 100 to provide self-driving capabilities.
[0038] In some examples, the AI-driven NMS 130 also provides configuration management, monitoring, and automated supervision of a software-defined wide area network (SD-WAN) that operates as an intermediary network communicatively coupling the wireless network 106 and wired LAN of site 102 to the data center and application services. Generally, SD-WAN provides seamless, secure, traffic-engineered connectivity between “branch” routers (e.g., router 147) of the wired LAN hosting the wireless network 106 (such as a branch or campus enterprise network) to bring the “central” router closer to the cloud stack toward cloud-based application services. SD-WAN typically operates and manages overlay networks on the underlying physical wide area network (WAN) that provides connectivity to geographically separated customer networks. In other words, SD-WAN extends software-defined networking (SDN) capabilities to the WAN and allows one or more networks to decouple the underlying physical network infrastructure from the virtual network infrastructure and applications, enabling flexible and scalable network configuration and management.
[0039] In some examples, the AI-driven NMS 130 can enable intent-based configuration and management of network system 100, including the construction, presentation, and execution of intent-driven workflows for configuring and managing devices associated with wireless network 106, wired LAN network, and / or SD-WAN. For example, NMS 130 can implement declarative requirements that express the desired configuration of network components without specifying exact local device configurations and control flows. By utilizing declarative requirements, NMS 130 can specify what should be accomplished, rather than how it should be accomplished. Declarative requirements contrast with mandatory instructions that describe the exact device configuration syntax and control flows used to achieve the configuration. By utilizing declarative requirements instead of mandatory instructions, users and / or user systems can alleviate the burden of determining the exact device configurations needed to achieve the user / system's desired results. For example, when utilizing various types of devices from different vendors, specifying and managing exact mandatory instructions to configure each device in the network is often difficult and cumbersome. Network 134 can include various types and kinds of network devices that can dynamically change as new devices are added and device failures occur. Network administrators (such as those operating administrator device 111) may find it difficult to manage various types of devices from different vendors with different configuration protocols, syntaxes, and software versions, and may find configuring the cohesive network of devices challenging. Therefore, by requiring only user / system specification of declarative requirements that specify the expected results applicable to various types of devices, the NMS 130 can more effectively manage and configure network devices. Further examples of details and techniques for intent-based network management systems are described in U.S. Patent No. 10,756,983 entitled "Intent-based Analytics" and U.S. Patent No. 10,992,543 entitled "Automatically generating an intent-based network model of an existing computer network," each of which is incorporated herein by reference.
[0040] In some examples, the techniques described above can be performed by any other computing device(s), system(s), and / or server(s), and this disclosure is not limited in this respect. For example, one or more computing devices configured to perform the functions of the techniques disclosed herein may reside in a dedicated server, or be included in any other server besides NAC system 180 or NMS 130, or may be distributed throughout network 100 and may or may not form part of NAC system 180 or NMS 130.
[0041] NAC system 180 can maintain access policies for NAS devices 108 at multiple sites 102A-102N across multiple organizations and networks. NAC system 180 can provide appropriate access policies to client devices 148 based on their identity, for example, by assigning client devices to certain Virtual Local Area Networks (VLANs), applying certain Access Control Lists (ACLs), or directing client devices to certain registration portals. NAC system 180 can also identify client devices 148 by analyzing their network behavior (referred to as fingerprinting). NAC system 180 can perform client device identification based on Media Access Control (MAC) addresses, DHCP options used to request IP addresses, Link Layer Discovery Protocol (LLDP) packets, user agent information, and / or device type and operating system information.
[0042] According to one or more techniques disclosed herein, NAS device 108 is configured to perform authentication of client device 148. Examples of authentication may include certificate authentication and password authentication. After NAS device 108A authenticates client device 148, NAS device 108A can use policy caching to authorize client device 148A-1 to access wireless network 106A based on the access policy action of client device 148A-1.
[0043] Regarding certificate authentication, instead of having NAC system 180 handle certificate exchange and authentication for client device 148 at site 102, NAS device 108 is configured to perform certificate-based authentication for client device 148. For example, when a NAS device in NAS device 108A receives an access request for the wireless network from client device 148A-1, NAS device 108A can authenticate client device 148A-1 based on the exchange of authentication certificates associated with either NAC system 180 or client device 148A-1.
[0044] In an authentication process, once client device 148A-1 has contacted NAS device 108A, NAS device 108A can send an Extensible Authentication Protocol (EAP) ID request to client device 148A-1. Client device 148A-1 can then respond to NAS device 108A using the EAP ID. Extensible Authentication Protocol (EAP) is an authentication framework for computer networks and communication protocols. It provides a secure and flexible method for authentication between client devices and network services such as Wi-Fi networks, Virtual Private Networks (VPNs), and network access control based on 802.1X ports.
[0045] NAS device 108 can store certificates in an agent for NAC system 180. NMS 130 can provide NAS device 108A with a list of server and client certificates associated with NAC system 180. After client device 148A-1 sends an EAP ID response to NAS device 108, NAS device 108A can provide the server certificate to client device 148A-1.
[0046] The client device 148A-1 can then verify the server certificate. The client device 148A-1 can examine the server certificate and check its digital signature, expiration date, and other attributes. The server certificate may contain a chain of trust, including intermediate certificates and root certificates. The client device 148A-1 can perform various checks to verify the integrity and authenticity of the certificate, including verifying the digital signature, ensuring the certificate has not expired, and checking the issuer's identity.
[0047] If client device 148A-1 successfully verifies the server certificate, it provides the client certificate to NAS device 108A. NAS device 108A can store a list of client certificates used to verify the client certificates provided by NMS 130. NAS device 108A can then use this list to verify the client certificates. NAS device 108A can examine the client certificates, checking their digital signatures, expiration dates, and other attributes. NAS device 108A can receive client certificates that include a chain of trust, including intermediate and root certificates. NAS device 108A can perform various checks to verify the integrity and authenticity of the certificates, including verifying digital signatures, ensuring the certificates are not expired, and checking the issuer's identity. In one example, NAS device 108A does not need to check whether the client certificate has been revoked. NAS device 108A can rely on NAC system 180 or edge device 150 to maintain and check the Certificate Revocation List (CRL) to determine the status of client certificates of client device 148A-1. The NAS device can check with the edge device 150 and / or the NAC system 180 to determine whether the client certificate of the client device 148A-1 has been revoked.
[0048] For password authentication, NAS device 108A can locally cache username and password pairs and then use them to authenticate client device 148A-1. Client device 148A-1 can provide the username and password pair to NAS device 108A. NAS device 108A can then check to ensure that client device 148A-1 has provided the correct username and password pair. NAS device 108A can use a hashing process to securely store passwords, which uses a hashing algorithm (such as bcrypt, SHA, etc.) to convert the password into a hash value. NAS device 108A can use irreversible hashing algorithms, so the hash value cannot be used to recreate the password. NMS 130 can provide NAS device 108A with the username and password hashes specific to the client device.
[0049] The NAC system 180 can maintain access policies. Network access policies help maintain network security and integrity. Network access policies can outline the rules and guidelines for managing client devices' access to network resources and define the conditions for allowing or denying access.
[0050] NAC system 180 can perform an identity provider lookup at identity providers 115A-C (collectively, "identity provider 115") to obtain identity information for client device 148. NAC system 180 can use the identity obtained from identity provider 115 to evaluate policy rules for access policies. Identity provider 115 can be a system or service responsible for managing user identities, authenticating user identities, and providing authorization information to other systems or services. Examples of identity providers include Microsoft Azure Active Directory and Google Cloud Identity Platform. Identity provider 115 can act as a central authority for identity management within an organization or across multiple organizations.
[0051] The NAC system 180 can use access policies to determine which client devices should access network resources based on groups (employees, contractors, or specific user groups, etc.). The NAC system 180 can enforce access policies using Access Control Lists (ACLs), which are rules that control inbound and outbound traffic based on source and destination IP addresses, port numbers, and protocols. The NAC system 180 can also enforce access policies that divide the network into different segments or Virtual Local Area Networks (VLANs) to control access between different parts of the network, thereby enforcing firewall rules and VLAN configurations to restrict communication between network segments and restrict access to sensitive resources.
[0052] NAS device 108 can cache the last policy action for client device 148 previously identified by NAC system 180 in a policy cache to provide the latest policy action for client device 148 even if the link from NAS device 108 to NAC system 180 is interrupted. The last policy action in NAS device 108's policy cache can indicate access levels based on operational functions and requirements, such as access to VLANs or network partitions. NAS device 108 can check the last access policy action in the policy cache for client device 148 and provide access to client device 148 based on the cached last policy action.
[0053] When NAS device 108 receives an updated policy action from NAC system 180, NAS device 108 can update the cached policy action for client device 148. The policy cache allows NAS device 108 to determine the latest or last policy action for a client device when the connection to the Network Access Control (NAC) system is unavailable. The policy cache can also provide fast access authorization without waiting for a response from NAC system 180. The policy cache at NAS device 108 can have entries for one or more client devices 148, where each entry includes the last policy action previously identified by the NAC system for the corresponding client device 148. When access to NAC system 180 is unavailable (e.g., due to a WAN link interruption between NAS device 108 and NAC system 180), if client device 148 is in the policy cache, NAS device 108 can still authorize client device 148 to access the wireless network based on the cached policy action.
[0054] Even when NAC system 180 is available, NAS device 108 can authorize client device 148 to access the wireless network based on cached policy actions, while simultaneously checking with NAC system 180 for updates or modifications to the access policy. In this way, NAS device 108 reduces connection latency for client device 148. If the access policy has changed since the last policy action for the client device stored in NAS device 108's policy cache, NAS device 108 can re-authenticate and authorize client device 148 to access the wireless network based on the updated access policy and update the policy cache.
[0055] Whenever NAS device 108 receives a new policy action for a client device from NAC system 180, NAS device 108 can update its policy cache. NAC system 180 can also maintain a Certificate Revocation List (CRL) and indicate to NMS 130 when a client device has a revoked certificate. NMS 130 can instruct all NAS devices associated with a client device that has a revoked certificate to clear the policy cache of that client device. NMS 130 can also push updated client certificates to NAS devices to enable certificate-based authentication at NAS device 108. NMS 130 can also push username and password hashes to NAS device 108 to enable password-based authentication at NAS device 108.
[0056] NAS device 108 can synchronize its policy cache with the policy caches of one or more other NAS devices at the site. NAS device 108 can maintain a list of neighboring NAS devices and notify them whenever it updates its policy cache, allowing them to update their own policy caches accordingly. NAS device 108 can synchronize the policy caches of adjacent NAS devices, enabling fast roaming of client devices between them. Otherwise, client device 148 might encounter delays at the second NAS device after having already authenticated with the first.
[0057] The technology disclosed herein provides one or more technical advantages and practical applications. A cloud-based NAC system 180 that interacts with NAS device 108 using a policy cache can offer many advantages over traditional on-premises NAC solutions, including centralized access policy management, resilience, reduced latency, and reduced cloud utilization. NAC system 180 can store access policies in the cloud instead of on-premises, allowing for centralized updating, management, and storage of access policies. The policy cache at NAS device 108 allows access to policies maintained by NAC system 180, even when NAC system 180 is unavailable. The policy cache at NAS device 108 can reduce latency in obtaining policy decisions because NAS device 108 is local to the site, unlike remote NAS device 180. NAS device 108 performing certificate authentication or password authentication can reduce cloud utilization and associated costs for NAC system 180 compared to NAS device 108 using NAC system 180 for certificate checks. This centralized access policy management can save time and resources because administrators no longer need to manage access policies on multiple on-premises devices.
[0058] Figure 1B It is a diagram. Figure 1A A block diagram showing further details of another example of a network system. In this example, Figure 1B The diagram illustrates the logical connections 178A-178N, 182A-182N, and 184A-184K between the NAS device 108, NAC system 180, and NMS 130 at site 102. Furthermore, Figure 1B The illustration shows an NMS 130 configured to operate according to an AI-based computing platform to provide configuration and management of one or more NAC systems 180 and NAS devices 108 at site 102 via logical connections.
[0059] In operation, NMS 130 observes, collects, and / or receives network data 137, which may take the form of data extracted from messages, counters, and statistics (e.g., from one or more of AP 142, switch 146, router 147, edge device 150, NAC system 180, and / or other nodes within network 134). NMS 130 provides a management plane for network 100, including the management of enterprise-specific configuration information 139 for one or more of the NAS devices 108 and NAC systems 180 at site 102. Each NAS device 108 and each NAC system 180 may have a secure connection to NMS 130, such as a RadSec (RADIUS over Transport Layer Security (TLS)) tunnel or another encrypted tunnel. According to one or more techniques disclosed herein, NAS device 108 may not need to implement a RADIUS stack when authentication is implemented locally. Each of the NAS device 108 and the NAC system 180 can download appropriate enterprise-specific configuration information 139 from the NMS 130 and enforce that configuration. In some scenarios, one or more NAS devices in the NAS device 108 may be third-party devices or otherwise not support establishing a secure connection directly with the NMS 130. In these scenarios, the edge device 150 can provide a proxy through which the NAS device 108 can connect to the NMS 130.
[0060] In one specific implementation, a computing device is part of NMS 130. In other implementations, NMS 130 may include one or more computing devices, dedicated servers, virtual machines, containers, services, or other forms of environments for performing the techniques described herein. Similarly, computing resources and components implementing VNA 133 may be part of NMS 130, may be executed on other servers or execution environments, or may be distributed across nodes within network 134 (e.g., routers, switches, controllers, gateways, etc.).
[0061] In some examples, NMS 130 monitors network data 137 received from each site 102A-102N, such as one or more Service Level Expectations (SLE) metrics, and manages network resources (such as one or more of APs 142, switches 146, routers 147, and edge devices 150 at each site) to deliver a high-quality wireless experience to end users, IoT devices, and clients at the sites. In other examples, NMS 130 monitors network data 137 received from NAC system 180 and manages enterprise-specific configuration information 139 for NAC system 180 to enable unconstrained network access control services with low latency and high availability for client devices 148 at site 102.
[0062] like Figure 1B As illustrated, NMS 130 may include a Virtual Network Assistant (VNA) 133, which implements an event processing platform to provide real-time insights into IT operations and streamline troubleshooting, and automatically takes corrective actions or provides recommendations to proactively resolve network problems. For example, VNA 133 may include an event processing platform configured to handle hundreds or thousands of concurrent network data streams 137 from sensors and / or agents associated with AP 142, switch 146, router 147, edge device 150, NAC system 180, and / or other nodes within network 134. For example, VNA 133 of NMS 130 may include a low-level analytics and network error identification engine, as well as an alerting system, according to various examples described herein. The low-level analytics engine of VNA 133 can apply historical data and models to inbound event streams to calculate assertions such as the anomalies or predicted occurrences of events constituting network error conditions. Furthermore, VNA 133 can provide real-time alerts and reports to notify site or network administrators of any predicted events, anomalies, or trends via administrator device 111, and can perform root cause analysis and automatic or assisted error correction. In some examples, the VNA 133 of NMS 130 can apply machine learning techniques to identify the root causes of error conditions detected or predicted from the flow of network data 137. If the root cause can be resolved automatically, VNA 133 can invoke one or more corrective actions to correct the root cause of the error condition, thereby automatically improving underlying SLE metrics and also automatically improving user experience.
[0063] Further examples of the operation implemented by the VNA 133 of the NMS 130 are detailed in U.S. Patent No. 9,832,082, entitled "Monitoring Wireless Access Point Events," published November 28, 2017; U.S. Publication No. US 2021 / 0306201, entitled "Network System Fault Resolution Using a Machine Learning Model," published September 30, 2021; U.S. Patent No. 10,985,969, entitled "Systems and Methods for a Virtual Network Assistant," published April 20, 2021; and U.S. Patent No. 10,985,969, entitled "Methods and Apparatus for Facilitating Fault Detection and / or Predictive Fault," published March 23, 2021. The contents of all of these patents are described in U.S. Patent No. 10,958,585 entitled “Method for Spatio-Temporal Modeling”, issued March 23, 2021; and U.S. Patent No. 10,958,537 entitled “Method for Conveying AP Error Codes Over BLE Advertisements”, issued December 8, 2020, and are incorporated herein by reference in their entirety.
[0064] In addition, such as Figure 1BAs illustrated, NMS 130 may include NAC controller 138 implementing a NAC configuration platform that provides a user interface to create and assign access policies for client devices 148 of wireless network 106 and to provide appropriate enterprise-specific configuration information 139 to the corresponding NAC clouds 180A-180K. NMS 130 may have secure connections 184A-184K, such as RadSec tunnels or other encrypted tunnels, to each NAC system in NAC systems 180A-180K. Through secure connection 184, NAC controller 138 can receive network data 137, such as NAC event data, from each NAC system in NAC system 180, and each NAC system in NAC system 180 can download appropriate configuration information 139 from NMS 130. In some examples, NAC controller 138 may log or map which enterprise networks are served by which NAC systems 180. In addition, the NAC controller 138 can monitor the NAC system 180 to identify failures in the primary NAC system and manage failover to the backup NAC system.
[0065] exist Figure 1BIn the example illustrated, each NAS device in NAS device 108 has a direct or indirect connection to at least one NAC system in NAC system 180. For example, each AP 142A within site 120A has a connection 182A to NAC system 180A. As discussed below, when NAS device 108 implements certificate authentication, NAS device 108 does not need to implement RADIUS or RadSec (a protocol for transmitting RADIUS datagrams over TCP and TLS). Instead, NAS device 108 can communicate using simpler protocols such as Hypertext Transfer Security Protocol (HTTPS) instead of using a RADIUS tunnel to one of the NAC systems. Each of the switches 146A and routers 147A within site 120A has an indirect connection to NAC system 180A via edge device 150A. In this example, switch 146A and router 147A may not support establishing a secure connection directly to NAC system 180A, but edge device 150A can provide a proxy through which switch 146A and router 147A can connect to NAC system 180A. For example, each of switch 146A and router 147A has a direct connection 178A to edge device 150A, and edge device 150A has a direct secure connection 182A to NAC system 180A. Similarly, for site 102N, each NAS device in NAS device 108N has an indirect connection to NAC system 180K via edge device 150N. In this example, AP 142N, switch 146N, and router 147N may not support establishing a secure connection directly to NAC system 180K, but edge device 150N can provide a proxy through which NAS device 108N can connect to NAC system 180K. For example, each of the AP 142N, switch 146N, and router 147N has a direct connection 178N to edge device 150N, and edge device 150N has a direct secure connection 182N to NAC system 180K.
[0066] Through a secure connection 182, NAC system 180 can receive network access requests from client device 148 via NAS device 108 (or edge device 150 in some cases) at a nearby enterprise site 102. In response to the network access request, NAC system 180 uses an identity provider 115 (such as an AAA server) to authenticate the requesting client device. NAC system 180 may perform fingerprinting to identify the authenticated client device. NAC system 180 then enforces an appropriate access policy on the identity of the authenticated client device based on enterprise-specific configuration information 139 downloaded from NMS 130. According to one embodiment, a computing device is part of each NAC system in NAC system 180. According to other embodiments, each NAC system in NAC systems 180A-180K may include one or more computing devices, dedicated servers, virtual machines, containers, services, or other forms of environment for performing the techniques described herein.
[0067] According to one or more techniques disclosed herein, NAS device 108 can directly authenticate client device 148, instead of requiring NAS device 108 to use NAC system 180 to authenticate client device 148. For certificate authentication, NMS 130 can send the server certificate and key of NAC system 180, along with a list of certification authorities (CAs), to NAS device 108 to verify the client certificate. NAS device 108 can then authenticate client device 148 as a proxy of NAC system 180. NAS device 108 can implement an Extensible Authentication Protocol (EAP) stack as the authentication framework. NAS device 108 will typically be associated with a relatively small number of client devices, and not all associated client devices will be authenticated simultaneously; therefore, the authentication functionality will not be a significant computational overhead on NAS device 108.
[0068] The NAC system 180 can also perform CRL checks to determine whether the certificate of the client device 148 has been revoked. The edge device 150 can also implement CRL checking functionality for the NAS device 108. Having CRL checking functionality outside the NAS device 108 reduces the computational burden on the NAS device 108.
[0069] For password authentication, NAS device 108 can locally cache username and password hash pairs and then use them to authenticate client device 148. NAS device 108 can check to ensure that client device 148 provides the correct username and password pair. NAS device 108 can securely store passwords using a hashing process that uses a hash algorithm to convert the password into a hash value.
[0070] NAC system 180 can maintain access policies for client device 148. Access policies can allow different levels of access to resources, including wireless networks, virtual local area networks (VLANs), and resources defined by access control lists (ACLs). NAS device 108 can cache the last policy action for client device 148. If NAC system 180 is unavailable, NAS device 108 can use the cached policy action for client device 148. NAS device 108 can distribute the cached policy action to neighboring NAS devices, allowing neighboring NAS devices to also use the cached policy action during authorization.
[0071] In response to an incoming request from client device 148, if the policy action is already in the cache, NAS device 108 can authorize client device 148 to access wireless network 106 based on the cached policy action and send a policy request to NAC system 180. If the policy response from NAC system 180 differs from the cached policy, NAS device 108 can initiate a CoA change to re-trigger authentication. Since the policy is not frequently modified, NAS device 108 can receive a policy response that typically matches the policy response provided by NAC system 180. When NAC system 180 is unavailable, and when NAS device 108 determines that client device 148 is not in the cache, NAS device 108 can grant client device 148 a default policy, since NAS device 108 has already authenticated client device 148. This default policy can provide greater access than guest access only or fallback internet access.
[0072] When NAC system 180 is unavailable, edge device 150 can implement a version of policy checking to evaluate certain policies. Therefore, edge device 150 can provide some policy checking functionality when NAC system 180 is unavailable. NMS 130 can provide policy configuration data to edge device 150. When NAC system 180 is unavailable, NAS device 108 can then check policy actions against client device 148 with edge device 150. Because edge device 150 can store policy configuration data, it can perform policy evaluation to reduce latency even when the NAC system is available. For complex rules, edge device 150 can send policy requests to the NAC system. In the example, edge device 150 can send a policy request including a CRL check with thousands of entries to one or more NAC systems in NAC system 180.
[0073] NAC system 180 can invalidate entries in the policy cache of NAS device 108. NAC system 180 can send a CoA request for client device 148 to NMS 130. NMS 130 relays the CoA request along with messages such as Vendor Specific Attributes (VSA) to the relevant NAS device to clear the policy cache for the entry for client device 148. NAS device 108 can then invalidate the entry in the policy cache and disconnect client device 148 to force re-authentication.
[0074] The technology disclosed herein provides one or more technical advantages and practical applications. A NAC system 180 interacting with a NAS device 108 using a policy cache can provide one or more advantages over traditional NAC solutions, including centralized access policy management, resilience, reduced latency, and reduced cloud utilization. The NAC system 180 can store access policies in the cloud, rather than on a local device, enabling centralized updating, management, and storage of these policies. Even if the NAC system 180 becomes unavailable, the policy cache at the NAS device 108 ensures continuous access to the policies maintained by the NAC system 180. The policy cache located on the NAS device 108 reduces latency for obtaining policy decisions because it is site-local, unlike the remote location of the NAC system 180. Furthermore, a certificate-enabled NAS device 108 can reduce cloud utilization and associated costs for the NAC system 180 compared to a NAS device 108 that relies on the NAC system 180 for certificate authentication.
[0075] Figure 2 This is a block diagram of an example network access control (NAC) system 200 according to one or more technologies disclosed herein. The NAC system 200 can be implemented, for example, Figure 1A , Figure 1B Any of the NAC systems in NAC system 180. In this example, NAC system 200 is responsible for authenticating and authorizing one or more client devices 148 to access the wireless network 106 at a subset of nearby enterprise sites 102A-102N. For clarity, [the following will be used]. Figures 1A to 1B Discussed in the context of one or more components Figure 2 .
[0076] NAC system 200 includes a communication interface 230, one or more processors 206, memory 212, and a database 218. Various components are coupled together via bus 214, through which they can exchange data and information. In some examples, NAC system 200 communicates via... Figure 1A , Figure 1BNAS devices 108 (in some cases, edge devices 150) at a subset of nearby enterprise sites 102 receive network access requests from one or more client devices among client devices 148. In response to the network access request, NAC system 200 authenticates the requesting client device. In some examples, NAC system 200 authenticates the client device based on the data received from... Figure 1A , Figure 1B The enterprise-specific configuration information 217 downloaded by NMS 130 enforces appropriate access policies on authenticated client devices. In some examples, NAC system 200 can be... Figure 1A , Figure 1B This could be a portion of another server, or a portion of any other server.
[0077] One or more processors 206 execute software instructions (such as software instructions for defining software or computer programs) stored in a computer-readable storage medium (such as memory 212), such as a non-transitory computer-readable medium including storage devices (e.g., disk drives or optical drives) or memories (such as flash memory or RAM) or any other type of volatile or non-volatile memory, the stored instructions causing one or more processors 206 to perform the techniques described herein. One or more processors 206 may be, be part of, or include processing circuitry that performs operations according to one or more aspects of this disclosure.
[0078] Communication interface 230 may include, for example, an Ethernet interface. Communication interface 230 couples NAC system 200 to a network and / or the Internet (such as...). Figure 1A (Any network and / or any local area network in network 134 shown). Communication interface 230 includes receiver 232 and transmitter 234, through which NAC system 200 communicates with / to AP 142, switch 146, router 147, edge device 150, NMS 130 or servers 116, 122, 128 and / or any other network node, device or system (such as...) forming part of network system 100. Figure 1A , Figure 1B (As shown) Receive / transmit data and information.
[0079] Data and information received by the NAC system 200 may include, for example, configuration information 217 associated with one or more enterprise sites in enterprise site 102 downloaded from the NMS 130. Configuration information 217 may include enterprise-specific NAC configuration information, including access policies and associated policy allocation criteria. For example, configuration information 217 may define specific virtual local area networks (VLANs), access control lists (ACLs), registration entries, etc., associated with specific categories of client devices. Configuration information 217 may also define different types of tracking, different types of authorization, and / or different levels of access permissions for each client device in different categories of client devices. Furthermore, data and information received by the NAC system 200 may include identification information of client devices 148 from the NAS device 108, which the NAC system 200 uses to perform end-user device fingerprinting to enforce access policies as defined in configuration information 217. The NAC system 200 may also transmit data and information, including, for example, NAC event data, to the NMS 130 via communication interface 330, which the NMS 130 can use to remotely monitor the performance of the NAC system 200.
[0080] Memory 212 includes one or more devices configured to store programming modules and / or data associated with the operation of NAC system 200. For example, memory 212 may include a computer-readable storage medium, such as a non-transitory computer-readable medium including storage devices (e.g., disk drives or optical drives) or memories (such as flash memory or RAM) or any other type of volatile or non-volatile memory, which stores instructions to cause one or more processors 206 to perform the techniques described herein.
[0081] In this example, memory 212 includes API 220, authentication manager 240, fingerprint module 242, policy manager 244, NMS connector 250, and NAC monitoring unit 252. NAC system 200 may also include any other programming modules, software engines, and / or interfaces for authentication and authorization configuration of client device 148.
[0082] As discussed elsewhere in this disclosure, NAS device 108 can authenticate client device 148, but authentication manager 240 can perform CRL checks. Authentication manager 240 can also perform authentication for NAS devices that do not have authentication capabilities. Authentication manager 240 implements authentication of client device 148 at NAS device 108 to access wireless network 106 (such as a branch or campus corporate network) at a subset of enterprise sites 102 communicating with NAC system 200. Authentication manager 240 can perform the functions of an AAA server (e.g., a RADIUS server) or provide access to an AAA server to authenticate client device 148 (potentially using identity provider 115) before providing access to wireless network 106 via NAS device 108. In some examples, authentication manager 240 can participate in the handshake exchange between client device, NAS device, and NAC system 200 that controls access at NAS device. In other examples, authentication manager 240 can implement certificate-based authentication of client devices or implement interaction with a cloud directory service to authenticate client devices.
[0083] Fingerprint module 242 identifies client device 148, which is used to provide appropriate authorization or access policies to the client device based on its identity or classification. Fingerprint module 242 can identify client device 148 by analyzing its network behavior. Fingerprint module 242 can receive network behavior data of the client device from NAS device 108 and / or edge device 150 communicating with NAC system 200. For example, fingerprint module 242 can perform fingerprint identification of client device 148 based on one or more of the following: MAC address, DHCP options used to request an IP address, LLDP packets, user agent information, and / or device type and operating system information.
[0084] Policy Manager 244 enforces authorization or access policies based on the identity or classification of authenticated client devices. For example, Policy Manager 244 can assign authenticated client devices to specific VLANs, apply specific ACLs, or direct client devices to specific registration entries, based on configuration information 217 for the corresponding enterprise of the client device. Each of these is associated with different types of tracking, different types of authorization, and / or different levels of access permissions. In some examples, after a client device gains access to the enterprise network, Policy Manager 244 can monitor the client device's activity to identify security issues and, in response, reassign the client device to an isolated VLAN or another VLAN with fewer privileges to restrict the client device's access.
[0085] NMS connector 250 manages the data and information exchanged between NAC system 200 and NMS 130, for example, via RadSec tunnel or another encrypted tunnel 184, such as... Figure 1B As shown in the diagram, the NMS connector 250 can maintain logs or mappings of which enterprise networks are served by the NAC system 200, as well as corresponding configuration information 217 for those enterprises. The NMS connector 250 can also manage any updates or modifications to the configuration information 217 received from the NMS 130.
[0086] According to one or more techniques disclosed herein, policy manager 244 can use policies stored in configuration information 217 to determine policy actions for client device 148. Policy manager 244 can respond to policy requests from NAS device 108 for client device 148 using the current policy action for client device 148. NAS device 108 can then update its policy cache using the current policy action for client device 148.
[0087] As discussed above, NAS device 108 can authenticate client device 148. However, authentication manager 240 can perform certain authentication functions (such as CRL checks) that NAS device 108 does not perform. Some authentication functions (such as CRL checks) can potentially consume too many resources of NAS device 108 (e.g., CPU utilization and / or communication bandwidth utilization). Authentication manager 240 can maintain a CRL list, and when NAC system 200 receives authentication or other requests for client devices on the CRL list, NAC system 200 can instruct NAS device 108 to revoke the certificate. NAS device 108 can then deauthenticate the client device.
[0088] Figure 3 This is a block diagram of an example network management system (NMS) 300 according to one or more technologies disclosed herein. The NMS 300 can implement, for example... Figure 1A , Figure 1B The NMS 130 is used in this example. In this case, the NMS 300 is responsible for monitoring and managing one or more wireless networks 106A-106N at sites 102A-102N respectively. For clarity, in... Figures 1A to 1B Discussed in the context of one or more components Figure 3 .
[0089] The NMS 300 includes a communication interface 330, one or more processors 306, a user interface 310, a memory 312, and a database 318. Various components are coupled together via a bus 314, through which they can exchange data and information. In some examples, the NMS 300 receives data from one or more of the following: client device 148, AP 142, switch 146, router 147, edge device 150, NAC system 180, and other network nodes (e.g., routers and gateway devices) within the network 134. These devices can calculate one or more SLE metrics and / or update network data 316 in the database 318. The NMS 300 analyzes this data for cloud-based management of the wireless network 106A-106N. In some examples, the NMS 300 may be... Figure 1A This could be a portion of another server, or a portion of any other server.
[0090] One or more processors 306 execute software instructions (such as software instructions for defining software or computer programs) stored in a computer-readable storage medium (such as memory 312), such as a non-transitory computer-readable medium including storage devices (e.g., disk drives or optical disk drives) or memories (such as flash memory or RAM) or any other type of volatile or non-volatile memory, the stored instructions causing one or more processors 306 to perform the techniques described herein. One or more processors 306 may be, be part of, or include processing circuitry that performs operations according to one or more aspects of this disclosure.
[0091] The communication interface 330 may include, for example, an Ethernet interface. The communication interface 330 couples the NMS 300 to a network and / or the Internet (such as...). Figure 1A (Any one or more of the networks 134 shown and / or any local area network). The communication interface 330 includes a receiver 332 and a transmitter 334, through which the NMS 300 communicates with / to any client device 148, AP 142, switch 146, router 147, edge device 150, NAC system 180, server 116, 122, 128 and / or forms a network such as... Figure 1A Any other network node, device, or system within the network system 100 shown receives / transmits data and information. In some scenarios where the network system 100 described herein includes “third-party” network devices that own and / or are associated with entities different from NMS 300, NMS 300 does not directly receive, collect, or access network data from the third-party network devices. In some examples, edge devices (such as those from…) Figure 1A , Figure 1B The edge device 150 can provide a proxy that can report network data from third-party network devices to the NMS 300.
[0092] The data and information received by the NMS 300 may include, for example, telemetry data, SLE-related data, or event data received from one or more of the client devices 148, AP 142, switch 146, router 147, edge device 150, NAC system 180, or other network nodes (e.g., routers and gateway devices). The NMS 300 uses this data to remotely monitor the performance of the wireless networks 106A-106N and application sessions from client devices to cloud-based application servers. The NMS 300 can also transmit data via communication interface 330 to any of the network devices (such as client devices 148, AP 142, switch 146, router 147, edge device 150, NAC system 180, or other network nodes within network 134) to remotely manage portions of the wireless networks 106A-106N and the wired network.
[0093] Memory 312 includes one or more devices configured to store programming modules and / or data associated with the operation of NMS 300. For example, memory 312 may include a computer-readable storage medium, such as a non-transitory computer-readable medium including storage devices (e.g., disk drives or optical disk drives) or memories (such as flash memory or RAM) or any other type of volatile or non-volatile memory, which stores instructions to cause one or more processors 306 to perform the techniques described herein.
[0094] In this example, memory 312 includes API 320, SLE module 322, Virtual Network Assistant (VNA) / AI engine 350, Radio Resource Management (RRM) engine 360, and NAC controller 370. NMS 300 may also include any other programming modules, software engines, and / or interfaces configured for remote monitoring and management of wireless networks 106A-106N and portions of wired networks (including remote monitoring and management of any of AP 142, switch 146, router 147, edge device 150, NAC system 180, or other network devices (e.g., routers and gateway devices)).
[0095] SLE module 322 implements the setting and tracking of thresholds for SLE metrics for each network 106A-106N. SLE module 322 further analyzes SLE-related data collected by, for example, APs (such as any of AP 142) from client devices in each wireless network 106A-106N. For example, APs 142A-1 to 142A-N collect SLE-related data from client devices 148A-1 to 148A-N currently connected to wireless network 106A. This data is transmitted to NMS 300, which is executed by SLE module 322 to determine one or more SLE metrics for each client device 148A-1 to 148A-N currently connected to wireless network 106A. This data, except for any network data collected by one or more APs 142A-1 to 142A-N in wireless network 106A, is transmitted to NMS 300 and stored in database 318 as, for example, network data 316.
[0096] RRM Engine 360 monitors one or more metrics for each site 102A-102N to learn and optimize the RF environment at each site. For example, RRM Engine 360 can monitor coverage and capacity SLE metrics for wireless network 106 at site 102 to identify potential problems with SLE coverage and / or capacity in wireless network 106 and adjust the radio settings of access points at each site to address the identified problems. For example, RRM Engine 360 can determine the channel and transmit power distribution on all APs 142 in each network 106A-106N. For example, RRM Engine 360 can monitor events, power, channels, bandwidth, and the number of clients connected to each AP. RRM Engine 360 can also automatically change or update the configuration of one or more APs 142 at site 102 with the aim of improving coverage and capacity SLE metrics, thereby providing users with an improved wireless experience.
[0097] The VNA / AI engine 350 analyzes data received from network devices and its own data to identify when one of the network devices encounters an unexpected anomalous state. For example, the VNA / AI engine 350 can identify the root cause of any unexpected or anomalous state, such as any poor SLE metric(s) indicating connectivity problems at one or more network devices. Furthermore, the VNA / AI engine 350 can automatically invoke one or more corrective actions designed to address the identified root cause(s) of one or more poor SLE metrics. In some examples, the ML model 380 may include a supervised ML model trained using training data, which includes pre-collected, labeled network data received from network devices. The supervised ML model may include one of logistic regression, Naive Bayes, support vector machines (SVM), etc. In other examples, the ML model 380 may include an unsupervised ML model. Although... Figure 3 Not shown, but in some examples, database 318 may store training data, and VNA / AI engine 350 or dedicated training module may be configured to train ML model 380 based on the training data to determine appropriate weights on one or more features of the training data.
[0098] Examples of corrective actions that can be automatically invoked by the VNA / AI Engine 350 may include, but are not limited to, invoking the RRM360 to restart one or more APs, adjusting / modifying the transmit power of a specific radio in a specific AP, adding an SSID configuration to a specific AP, changing the channel on an AP or a group of APs, etc. Corrective actions may also include restarting switches and / or routers, invoking the download of new software to APs, switches, or routers, etc. These corrective actions are given for illustrative purposes only, and this disclosure is not limited in this respect. If automatic corrective actions are unavailable or insufficient to resolve the root cause, the VNA / AI Engine 350 may proactively provide a notification including recommended corrective actions to be taken by IT personnel (e.g., a site administrator or network administrator using Administrator Device 111) to resolve the network error.
[0099] The NAC controller 370 implements an NAC configuration platform, which provides configuration options for (e.g., via...) Figure 1AThe administrator device 111 displays a user interface 310 to the enterprise network administrator, through which access policy information for the enterprise network is received. Based on the input received via the user interface 310, the NAC controller 370 creates enterprise-specific configuration information 317 stored in a database 318. Configuration information 317 may include NAC configuration information for one or more enterprise networks managed by the NMS 300. For each enterprise, configuration information 317 may include access policies and associated policy allocation criteria. For example, configuration information 317 may define specific VLANs, ACLs, registration entries, etc., associated with specific categories of client devices, and may also define different types of tracking, different types of authorization, and / or different levels of access permissions for each different category of client devices. Configuration information 317 may be substantially similar to... Figure 1B Configuration information 139.
[0100] The NAC controller 370 manages the data and information exchanged between the NMS 300 and the NAC system 180, for example, via the RadSec tunnel or another encrypted tunnel 184, such as... Figure 1B As shown in the diagram, the NAC controller 370 can also maintain logs or mappings of which enterprise networks are served by which NAC systems 180, and corresponding configuration information 317 for those enterprises. The NAC controller 370 can also manage any updates or modifications to the configuration information 317 to be pushed down to the NAC system 180. Furthermore, the NAC controller 370 can monitor the NAC system 180 to identify failures in the primary NAC system and manage failover to the standby NAC system.
[0101] According to one or more techniques disclosed herein, the certificate provisioning module 375 can provide the NAS device 108 with a list of server certificates for the NAC system 180 and client certificates for the client devices 148. The NMS 300 can store the server certificates for the NAC system 180 and the client certificates for the client devices 148 used by the NAS device. The certificate provisioning module 375 can create a relevant client certificate list for each NAS device 108 based on data obtained while monitoring the network, client devices 148, and NAS device 108. When a client device not in the client certificate list contacts the provisioned NAS device 108, the NAS device 108 can request a client certificate from the NMS 300, for example, through the NAC system 180.
[0102] Although the technology of this disclosure is described in this example as being performed by NMS 300, the technology described herein can be performed by one or more other computing devices, systems, and / or servers, and this disclosure is not limited in that respect. For example, one or more computing devices configured to perform the functions of the technology of this disclosure may reside in a dedicated server, or be included in any other server besides NMS 300, or may be distributed throughout network 100 and may or may not form part of NMS 300.
[0103] Figure 4 This is a block diagram of an example network access server (NAS) device 400 according to one or more technologies disclosed herein. Figure 4 The example NAS device 400 shown can be used to implement as described in this article. Figure 1A Any of the NAS devices shown and described in NAS device 108, such as access point 142, switch 146, and router 147. The following description includes wireless functionality, but NAS device 400 may also be a wired device.
[0104] exist Figure 4 In the example, NAS device 400 includes a wired interface 430, wireless interfaces 420A-420B, one or more processors 406, memory 412, and input / output 410 coupled together via bus 414. These components can exchange data and information via bus 414. Wired interface 430 represents a physical network interface and includes a receiver 432 and a transmitter 434 for sending and receiving network communications (e.g., packets). Wired interface 430 couples NAS device 400 directly or indirectly to wired network devices, such as Ethernet cables, within a wired network. Figure 1A , Figure 1B One of the switches 146 or routers 147.
[0105] The first wireless interface 420A and the second wireless interface 420B represent wireless network interfaces and respectively include receivers 422A and 422B. Each receiver includes a receiving antenna, and the NAS device 400 can receive signals from wireless communication devices, such as... Figure 1A , Figure 1B The client device 148 receives wireless signals. The first wireless interface 420A and the second wireless interface 420B also include transmitters 424A and 424B, respectively. Each transmitter includes a transmitting antenna, through which the NAS device 400 can transmit signals to wireless communication devices, such as… Figure 1A , Figure 1BThe client device 148 transmits wireless signals. In some examples, the first wireless interface 420A may include a Wi-Fi 802.11 interface (e.g., 2.4 GHz and / or 5 GHz), and the second wireless interface 420B may include a Bluetooth interface and / or a Bluetooth Low Energy (BLE) interface. As described above, the NAS device 400 can transmit wireless signals to nearby NAC systems (e.g., Figure 2 NAC system 180 or Figure 1A , Figure 1B (One of the NAC systems 180) requests network access for one or more client devices 148.
[0106] One or more processors 406 are programmable, hardware-based processors configured to execute software instructions (such as software instructions for defining software or computer programs) stored in a computer-readable storage medium (such as memory 412), which is a non-transitory computer-readable medium including storage devices (e.g., disk drives or optical drives) or memories (such as flash memory or RAM) or any other type of volatile or non-volatile memory, the stored instructions causing one or more processors 406 to perform the techniques described herein. One or more processors 406 may be, be part of, or include processing circuitry that performs operations according to one or more aspects of this disclosure.
[0107] Memory 412 includes one or more devices configured to store programming modules and / or data associated with the operation of NAS device 400. For example, memory 412 may include a computer-readable storage medium, such as a non-transitory computer-readable medium including storage devices (e.g., disk drives or optical drives) or memory (such as flash memory or RAM) or any other type of volatile or non-volatile memory, which stores instructions to cause one or more processors 406 to perform the techniques described herein.
[0108] In this example, memory 412 stores executable software, including an application programming interface (API) 440, a communication manager 442, configuration settings 450, a device status log 452, a policy cache 460, an authentication module 462, an authorization module 466, and a certificate storage device 464. Device status log 452 includes a list of events specific to the NAS device 400. Events can include logs of normal and error events, such as memory status, reboot or restart events, crash events, cloud disconnection and self-recovery events, low link speed or link speed oscillation events, Ethernet port status, Ethernet interface packet errors, upgrade failure events, firmware upgrade events, configuration changes, etc., along with a timestamp and date stamp for each event.
[0109] Input / output (I / O) 410 represents physical hardware components (such as buttons, displays, etc.) that enable interaction with the user. Although not shown, memory 412 typically stores executable software for controlling the user interface regarding input received via I / O 410. Communication manager 442 includes program code that, when executed by processor(s) 406, allows NAS device 400 to communicate with client device 148 and / or network(s) 134 via interfaces(s) 430 and / or any of 420A-420C. Configuration settings 450 include any device settings for NAS device 400, such as radio settings for each of the wireless interfaces(s) 420A-420C. These settings can be configured manually or remotely monitored and managed by NMS 130 to optimize wireless network performance periodically (e.g., hourly or daily).
[0110] As described herein, NAS device 400 can measure network data and report network data from status log 452 to NMS 130. Network data may include event data, telemetry data, and / or other SLE-related data. Network data may include various parameters indicating the performance and / or status of the wireless network. These parameters may be measured and / or determined by one or more client devices and / or one or more APs in the wireless network. NMS 130 / 300 may determine one or more SLE metrics based on SLE-related data received from APs in the wireless network and store the SLE metrics as network data 137. Figure 1B ).
[0111] According to one or more techniques disclosed herein, NAS device 400 may include memory 412, which includes a policy cache 460 having entries for one or more client devices, wherein each entry includes the last policy action previously identified by NAC system 180 for the corresponding client device. NAS device 400 includes authentication module 462, which authenticates the user upon receiving an access request for a wireless network from a client device.
[0112] Authentication module 462 enables certificate-based authentication of client device 148. When NAS device 400 receives an access request for the wireless network from client device 148, NAS device 400 can authenticate client device 148 to access wireless network 106 based on the exchange of authentication certificates associated with NAC system 180 and client device 148. Authentication can be sufficient to indicate that the client device is a known device (e.g., NAS device 400 can assume that the authenticated client device is a company or employee device), so NAS device 400 can grant the client device default policy access when NAC system 180 is unavailable, which can be greater than guest-only access to the wireless network.
[0113] NAS device 400 can store a list of server certificates for NAC system 180 and client device certificates in certificate storage device 464. Authentication module 462 can send the NAC system's server certificate to client device 148. Based on client device 148's verification of the server certificate, authentication module 462 can receive client device certificates from client device 148. Authentication module 462 can verify client device certificates based on the stored list of client certificates.
[0114] Authentication module 462 can implement password authentication. Authentication module 462 can locally cache username and password hash pairs, and then use the password to authenticate client device 148. Authentication module 462 can ensure that client device 148 provides the correct username and password pair. Authentication module 462 can securely store password hashes, hash received passwords, and compare the received password hash with the stored password hash.
[0115] After the NAS device 400 authenticates the client device 148, the authorization module 466 can determine whether the client device 148 is in the policy cache 460. Based on the client device being in the policy cache 460, the authorization module 466 can authorize the client device 148 to access the wireless network according to the last policy action for the client device in the policy cache 460.
[0116] Since client device 148 is not in policy cache 460, authorization module 466 can send an access authorization request for client device 148 to NAC system 180. NAC system 180 can then send, and NAS device 400 can receive, the current policy action based on one or more access policy rules for the wireless network maintained at NAC system 180, identified against the client device. NAS device 400 can add an entry to policy cache 460 for the client device, which includes the current policy action as the last policy action previously identified by NAC system for client device 148. Policy cache 460 thus retains the latest policy action for client device 148.
[0117] When client device 148 is in policy cache 460 and NAC system 180 is available, authorization module 466 can authorize client device 148 based on access policy actions in the policy cache. Authorization module 466 can then send an access authorization request for client device 148 to NAC system 180. NAS device 400 can then receive from NAC system 180 a current policy action identified by client device 148 based on one or more access policy rules for the wireless network maintained at NAC system 180. Authorization module 466 can compare the current policy action for client device 148 with the last policy action for client device 148. Authorization module 466 can invalidate an entry in the client device's policy cache to trigger re-authentication if the current policy action differs from the last policy action. NAS device 400 can update policy cache 460 using the current policy action from NAC system 180.
[0118] When NAC system 180 is unavailable (e.g., when the WAN link between NAS device 400 and NAC system 180 is interrupted), authorization module 466 can authorize client device 148 to access the wireless network according to the default policy, based on the fact that client device 148 is not in the policy cache. Since authentication module 462 has already authenticated client device 148, authorization module 466 can set the default policy at a level higher than the guest access level.
[0119] NAS device 400 can synchronize policy cache 460 with the policy caches of one or more other NAS devices at the site. NAS device 108 can maintain a list of neighboring NAS devices and notify neighboring NAS devices whenever NAS device 400 modifies policy cache 460, so that neighboring NAS devices can update their policy caches accordingly.
[0120] The technology disclosed herein provides one or more technical advantages and practical applications. Policy cache 460 allows NAS device 400 to provide access actions to client device 148, providing resilience and reduced latency even when access to NAC system 180 is unavailable. Policy cache 460 at NAS device 400 ensures consistent access to policies maintained by NAC system 180. Policy cache 460 reduces latency in obtaining policy decisions because it is site-local, unlike NAC system 180 which is remote. Furthermore, authentication module 462 at NAS device 400 can significantly reduce cloud utilization and associated costs of NAC system 180 compared to NAS devices that rely on NAC system 180 for certificate authentication.
[0121] Figure 5 This is a block diagram illustrating an example edge device 500 according to one or more technologies disclosed herein. Edge device 500 includes a cloud-managed wireless local area network (LAN) controller. Edge device 500 may implement, for example... Figure 1A , Figure 1B Any edge device 150. In this example, edge device 500 includes a local device at site 102 that is connected to NMS 130 and one or more local NAS devices 108 (e.g., from...). Figure 1A , Figure 1B It communicates with one or more APs 142, switches 146, or routers 147. An edge device 500 with an NMS 130 can operate to extend certain microservices from the NMS 130 to a local NAS device 108, while using the NMS 130 and its distributed software architecture for scalable and resilient operation, management, troubleshooting, and analysis.
[0122] In this example, edge device 500 includes a wired interface 502 (e.g., an Ethernet interface), a processor 506, input / output 508 (e.g., a display, buttons, keyboard, keypad, touchscreen, mouse, etc.), and memory 512 coupled together via bus 514. These various components can exchange data and information via bus 514. The wired interface 502 couples edge device 500 to a network (such as...). Figure 1A (Network 134 and / or any local area network shown). Wired interface 502 includes receiver 520 and transmitter 522, through which edge device 500 receives / sends data and information from / to any of NAS device 108 and NMS 130 and / or NAC system 180. Although only one interface is shown by way of example, edge device 500 may have multiple communication interfaces and / or multiple communication interface ports.
[0123] The memory 512 stores executable software applications 532, an operating system 540, and data / information 530. The data 530 may include system logs and / or error logs storing event data (including behavioral data) for the edge device 500.
[0124] According to one or more techniques disclosed herein, if the edge device 500 is at a site, the CRL checking module 555 can maintain CRLs for client devices at the site. The NAS device 108 can check the edge device 500 during certificate authentication to see if the certificate for the client device has been revoked. The edge device 500 can receive CRL lists and updates to the CRL lists from the NAC system 180 or NMS 130.
[0125] When NAC system 180 is unavailable, policy module 550 can also implement a version of policy checking to evaluate certain policies. Policy module 550 does not need to have full policy checking functionality, but it can provide additional policy checking capabilities when NAC system 180 is unavailable. NMS 500 can supply policy configuration data for policy module 550 to edge device 500. When NAC system 180 is unavailable, NAS device 108 can check policy actions against client device 148 with edge device 150.
[0126] Figure 6 This is a flowchart illustrating an example policy access process according to one or more technologies disclosed herein. The NAS device 108, client device 148, NAC system 180, and... Figures 1A to 1B Other components to describe Figure 6 Example operation. In other examples, Figure 6 The operation can be performed by other computing systems or devices.
[0127] NAS device 108 authenticates client device 148 based on the exchange of authentication certificates associated with NAC system 108 and client device 148 (602). NAS device 108 may send the server certificate of NAC system 180 to client device 148. In some examples, NAS device 108 may send the server certificate received from NMS 130. Based on the received server certificate, client device 148 may verify the server certificate. After client device 148 verifies the server certificate, NAS device 108 receives the client certificate from client device 148. Based on the client certificate received from client device 148, NAS device 108 verifies the client certificate of client device 148 based on the stored list of client certificates.
[0128] After authentication of client device 148, NAS device 108 may check whether its policy cache includes a policy action for client device 148 (604). If the policy cache includes client device 148 (the "Yes" branch of 604), NAS device 108 authorizes client device 148 to access the wireless network (such as wireless network 106A) based on the last policy action in the policy cache for client device 148 (606). NAS device 108 receives the current policy action for client device 148 from one or more NAC systems in NAC system 180 (607). Based on the received current policy action, NAS system 108 may check with NAC system 180 to obtain any updated policy actions for client device 148. If the policy action obtained from NAC system 180 differs from the cached policy action from the policy cache, NAS device 108 invalidates the entry for client device 148 in the policy cache and triggers re-authentication of client device 148 (608). NAS device 108 can provide an updated access response to client device 148 and update the policy cache at NAS device 108 to store the new policy action. If NAC system 180 is not immediately accessible, NAS device 108 can wait until NAC system 180 becomes available and allow client device 148 to access it using the cached policy access.
[0129] If the policy cache at NAS device 108 does not include client device 148 (the "No" branch of 604), then NAS device 108 can check if a connection to NAC system 180 is available (610). If a connection to NAC system 180 is unavailable (the "No" branch of 610), then NAS device 108 can authorize client device 148 to access wireless network 106A according to the default policy (612). If a connection to NAC system 180 is available (the "Yes" branch of 610), then NAS device 108 can receive the current policy action for client device 148 from NAC system 180 (614). NAS device 108 can authorize client device 148 to access wireless network 106A according to the current policy action for client device 148 (615). NAS device 108 can then add an entry for client device 148 to the policy cache, which includes the current policy action as the last policy action for client device 148 (616).
[0130] Figure 7 This is a flowchart illustrating an example operation 700 of a network access server policy caching according to one or more techniques of this disclosure. This document relates to... Figures 1A to 1B The NAS device 108, client device 148, and NAC system 180 are described Figure 7 Example operation 700. In other examples, Figure 7 The operation 700 can be performed by other computing systems or devices.
[0131] When NAS device 108 receives an access request for a wireless network (such as wireless network 106A at a site) from client device 148, it can authenticate client device 148 (702). For example, NAS device 108 can implement certificate-based and / or password-based authentication. Because NAS device 108 implements authentication, NAS device 108 can authenticate client device 148 even when NAC system 180 is unavailable.
[0132] After authentication of client device 148, NAS device 108 can determine whether client device 148 is in the policy cache at NAS device 108, which has entries for one or more client devices 148, wherein each entry includes the last policy action (704) previously identified by NAC system 180 for the corresponding client device 148.
[0133] Based on the policy cache of client device 148, NAS device 108 can authorize client device 148 to access wireless network 106A (706) according to the last policy action against client device 148. Authorization is permitted when NAC system 180 is unavailable.
[0134] The techniques described herein can be implemented in hardware, software, firmware, or any combination thereof. Various features described as modules, units, or components can be implemented together in an integrated logic device, or individually as discrete but interoperable logic devices or other hardware devices. In some cases, various features of an electronic circuit arrangement can be implemented as one or more integrated circuit devices (such as integrated circuit chips or chipsets).
[0135] If implemented in hardware, this disclosure may relate to devices such as processors or integrated circuit devices (such as integrated circuit chips or chipsets). Alternatively or additionally, if implemented in software or firmware, the technology may be implemented at least in part by a computer-readable data storage medium including instructions that, when executed, cause a processor to perform one or more of the methods described above. For example, the computer-readable data storage medium may store such instructions for processor execution.
[0136] Computer-readable media can form part of a computer program product, which may include packaging materials. Computer-readable media may include computer data storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), flash memory, magnetic or optical data storage media, etc. In some examples, the article of manufacture may include one or more computer-readable storage media.
[0137] In some examples, computer-readable storage media may include non-transitory media. The term "non-transitory" can indicate that the storage medium is not contained in a carrier or propagating signal. In some examples, non-transitory storage media may store data that can change over time (e.g., in RAM or cache).
[0138] The code or instructions can be software and / or firmware executed by processing circuitry, which includes one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other equivalent integrated or discrete logic circuits. Therefore, the term "processor" as used herein can refer to any of the foregoing structures or any other structure suitable for implementing the techniques described herein. Furthermore, in some aspects, the functionality described in this disclosure can be provided within software or hardware modules.
Claims
1. A network access server (NAS) device on a wireless network at a site, the NAS device comprising: The memory includes a policy cache having entries for one or more client devices, wherein each entry includes the last policy action previously identified by the network access control (NAC) system for the respective client device; as well as Processing circuit, the processing circuit being configured to: Upon receiving an access request for the wireless network from a client device, authenticate the client device; After the client device is authenticated, it is determined whether the client device is included in the policy cache; as well as Since the client device is included in the policy cache, the client device is authorized to access the wireless network according to the last policy action for the client device.
2. The NAS device of claim 1, wherein the processing circuitry is configured to operate based on the client device not being included in the policy cache: Send an access authorization request for the client device to the NAC system; and Receives a current policy action from the NAC system, based on one or more access policy rules for the wireless network maintained at the NAC system, and targeting the client device.
3. The NAS device of claim 2, wherein the processing circuitry is configured to add an entry for the client device to the policy cache, the entry including the current policy action as the last policy action previously identified by the NAC system for the client device.
4. The NAS device of claim 1, wherein the processing circuitry is configured to be included in the policy cache based on the client device: Send an access authorization request for the client device to the NAC system; Receive from the NAC system the current policy action identified by the client device based on one or more access policy rules for the wireless network maintained at the NAC system; The current policy action for the client device is compared with the last policy action for the client device; as well as Since the current policy action is different from the last policy action, the entry in the policy cache for the client device is invalidated to trigger re-authentication.
5. The NAS device of claim 1, wherein the wide area network (WAN) link between the NAS device and the NAC system is disconnected, and wherein the processing circuitry is configured to authorize the client device to access the wireless network according to a default policy based on the fact that the client device is not included in the policy cache.
6. The NAS device according to any one of claims 1 to 5, wherein the processing circuitry is configured to synchronize the policy cache with the policy caches of one or more other NAS devices at the site.
7. The NAS device according to any one of claims 1 to 6, wherein the processing circuitry authenticates the client device based on the exchange of authentication certificates associated with the NAC system and the client device.
8. The NAS device of claim 7, wherein the memory is configured to store a list of server certificates for the NAC system and client certificates for client devices, and wherein the processing circuitry is configured to: [The text abruptly ends here, so the translation stops here as well.] Send the server certificate of the NAC system to the client device; Based on the verification of the server certificate by the client device, the client certificate of the client device is received from the client device; as well as The client certificate of the client device is verified based on the stored list of client certificates.
9. The NAS device of claim 8, wherein the processing circuitry is configured to receive from a network management system (NMS) the server certificate of the NAC system and the client certificate list of the client devices, the NMS being configured to manage multiple NAS devices across one or more sites and one or more NAC systems.
10. The NAS device according to any one of claims 1 to 9, wherein the processing circuitry authenticates the client device based on password authentication with the client device.
11. A system comprising: A network access control (NAC) system that communicates with multiple network access server (NAS) devices for wireless networks at one or more sites, the NAC system being configured to maintain access policy rules for the wireless networks; as well as For the NAS device among the plurality of NAS devices in the wireless network at the site, the NAS device is configured as follows: Upon receiving an access request for the wireless network from a client device, authenticate the client device; After the client device is authenticated, it is determined whether the client device is included in the policy cache at the NAS device, the policy cache having entries for one or more client devices, wherein each entry includes the last policy action previously identified by the NAC system for the corresponding client device; as well as Since the client device is included in the policy cache, the client device is authorized to access the wireless network according to the last policy action for the client device.
12. The system of claim 11, wherein the NAS device is configured based on the client device not being included in the policy cache: Send an access authorization request for the client device to the NAC system; and Receives a current policy action from the NAC system, based on one or more access policy rules for the wireless network maintained at the NAC system, and targeting the client device.
13. The system of claim 12, wherein the NAS device is configured to add an entry for the client device to the policy cache, the entry including the current policy action as the last policy action previously identified by the NAC system for the client device.
14. The system of claim 11, wherein the NAS device is configured to be included in the policy cache based on the client device being included: Send an access authorization request for the client device to the NAC system; Receive from the NAC system the current policy action identified by the client device based on one or more access policy rules for the wireless network maintained at the NAC system; The current policy action for the client device is compared with the last policy action for the client device; as well as Since the current policy action is different from the last policy action, the entry in the policy cache for the client device is invalidated to trigger re-authentication.
15. The system of claim 11, wherein the wide area network (WAN) link between the NAS device and the NAC system is disconnected, and wherein the NAS device is configured to authorize the client device to access the wireless network according to a default policy based on the fact that the client device is not included in the policy cache.
16. The system according to any one of claims 11 to 15, wherein the NAS device is configured to synchronize the policy cache with the policy caches of one or more other NAS devices at the site.
17. A method comprising: When a client device receives an access request for a wireless network at a site, the client device is authenticated by a network access server (NAS) device on the wireless network; After the client device is authenticated, the NAS device determines whether the client device is included in the policy cache at the NAS device. The policy cache has entries for one or more client devices, wherein each entry includes the last policy action previously identified by the NAC system for the corresponding client device. as well as Since the client device is included in the policy cache, the NAS device authorizes the client device to access the wireless network according to the last policy action for the client device.
18. The method of claim 17, further comprising: based on the fact that the client device is not included in the policy cache: The NAS device sends an access authorization request for the client device to the NAC system; and The NAS device receives from the NAC system a current policy action identified by the client device based on one or more access policy rules for the wireless network maintained at the NAC system.
19. The method of claim 18, further comprising adding an entry for the client device to the policy cache, the entry including a current policy action as the last policy action previously identified by the NAC system for the client device.
20. The method of any one of claims 17 to 19, further comprising synchronizing the policy cache at the NAS device with the policy caches of one or more other NAS devices at the site.
21. A computer-readable storage medium encoded with instructions for configuring one or more programmable processors as a NAS device according to any one of claims 1 to 10, or as a system according to any one of claims 11 to 16, or as performing a method according to any one of claims 17 to 20.
Citation Information
Patent Citations
Intent-based analytics
US10756983B2
Method for conveying AP error codes over BLE advertisements
US10862742B2
Method for spatio-temporal monitoring
US10958537B2
Methods and apparatus for facilitating fault detection and / or predictive fault detection
US10958585B2
Systems and methods for a virtual network assistant
US10985969B2