Portnox™ CLEAR and Wi-Fi in WatchGuard Cloud Integration Guide

Deployment Overview

This guide demonstrates how to integrate Wi-Fi in WatchGuard Cloud with Portnox™ CLEAR to ensure secure and trusted user access with RADIUS.

Platform and Software

The hardware and software used to complete the steps in this document include:

  • Portnox™ CLEAR
    • Portnox™ CLEAR Account
  • WatchGuard
    • WatchGuard AP330 access point
    • WatchGuard Cloud account

Test Topology

Topology diagram

Portnox™ CLEAR Configuration

  1. Log in to the Portnox™ CLEAR Management Portal.
  2. Select Devices > Accounts.
  3. Click to create a new Portnox™ CLEAR account.
  4. In the Email text box, type an email address that is associated with your organization.
  5. (Optional) In the Description text box, type the description for the account.
  6. Keep all other settings as the default value.

Screenshot of Portnox Clear, Account page

  1. Click Save account.
  2. The email address you specify will receive a notification with a password that you can use with RADIUS authentication.

Screenshot of Portnox Clear, Account details

  1. Select Settings > + CLEAR RADIUS SERVICE > Create new CLEAR RADIUS instance.
  2. From the Location drop-down list, select your location. Click Create.

Screenshot of Portnox Clear, Create Clear RADIUS server page

  1. Record the Cloud RADIUS IP, Authentication port, and the Shared Secret.

Screenshot of Portnox Clear, add Clear RADIUS server page

  1. Select Groups > Create New Group.
  2. In the Group Name text box, type the group name.
  3. In the 802.1X WIRELESS NETWORK ACCESS section, click Add Wi-Fi Network.

Screenshot of Portnox Clear, New Group page

  1. In the Network name text box, type the SSID of the network.
  2. For Allowed authentication types, select the Credentials check box.
  3. From the Device requirement drop-down list, select Agentless or AgentP-based & Agentless.
  4. Click Save.

Screenshot of Portnox Clear, Add Wi-Fi Network page

  1. Click Save.
  2. Select the Members tab.
  3. Expand the CLEAR REPOSITORY.
  4. Select your account and move your account to this group.

Screenshot of Portnox Clear, Clear Repository page

  1. Click Save.

Wi-Fi in WatchGuard Cloud Configuration

For detailed information on WatchGuard Cloud AP deployment, see Get Started with Wi-Fi in WatchGuard Cloud.

Access points can have two different types of settings:

  • Device-level settings — Settings that you apply individually to each access point.

  • Access point site settings — Access point sites enable you to create SSID settings and apply them to multiple access points that subscribe to the site.

Configure Authentication Domain for Portnox CLEAR RADIUS Server In WatchGuard Cloud

  1. Log in to your WatchGuard Cloud account. If you have a Service Provider account, you must select a subscriber account.
  2. Select Configure > Authentication Domains.
  3. Click Add Authentication Domain.
  4. In the Domain Name text box, type a domain name.
  5. Click Next.
  6. In the Add servers section, select RADIUS.
  7. From the Type drop-down list, select Host IPv4.
  8. In the IP Address text box, type the Cloud RADIUS IP Address from Portnox CLEAR.
  9. In the Port text box, type the authentication port number for the RADIUS server from Portnox CLEAR.
  10. In the Shared secret text box, type the shared secret from the Portnox CLEAR server.
  11. In the Confirm shared secret text box, type the shared secret from the Portnox CLEAR RADIUS server.

Screenshot of Add Authentication Domain page in WatchGuard Cloud

  1. Click Save to save the Authentication Domain settings.
  2. Click Done.

Configure the Authentication Domain and SSID Settings for an Access Point (Device Level Configuration)

To configure Authentication Domain and SSID settings for a single access point at the device level configuration:

  1. From WatchGuard Cloud, select Configure > Devices.
  2. Select your Access Point.
  3. Select Device Configuration.
  4. In the Authentication tile, click Domains.
  5. Click Add Authentication Domain.
  6. From the Select an existing Authentication Domain drop-down list, select the domain you created in the previous section.
  7. From the RADIUS Server drop-down list, select the RADIUS server.

Screenshot of the Add Authentication Domain page in WatchGuard Cloud

  1. Click Save.
  2. Click Back to return to the configuration settings.
  3. Click SSIDs.
  4. Click Add SSID.
  5. In the SSID Name text box, type the SSID name.
  6. Select the Broadcast SSID check box.
  7. From the SSID Type drop-down list, select Private.
  8. From the Radio drop-down list, select 2.4 GHz and 5 GHz.
  9. From the Security drop-down list, select WPA2 Enterprise.
  10. From the Authentication Domain drop-down list, select the domain you created in the previous section.
  11. In the Network section, select Bridged.

Screenshot of the Add SSID page in WatchGuard Cloud

  1. Click Save.
  2. Click Schedule Deployment.
  3. Select Deploy changes now.
  4. In the Description text box, type a description for the deployment.

Screenshot of WGC, picture4

  1. Click Deploy.

Configure the Authentication Domain and SSID Settings for an Access Point Site

To configure Authentication Domain and SSID settings and apply the configuration to multiple access points with an Access Point Site:

  1. In WatchGuard Cloud, select Configure > Access Point Sites.
  2. Click Add Site.
  3. In the Name text box, type a name for the site.
  4. Click Add.

Screenshot of the Access Point Site configuration page in WatchGuard Cloud

  1. In the Authentication tile, click Domains.
  2. Click Add Authentication Domain.
  3. From the Select an existing Authentication Domain drop-down list, select the domain you created in the previous section.
  4. From the RADIUS Server drop-down list, select the RADIUS server.

Screenshot of the Add Authentication Domain page in WatchGuard Cloud

  1. Click Save.
  2. Click Back to return to the site configuration settings.
  3. Click SSIDs.
  4. Click Add SSID.
  5. In the SSID Name text box, type the SSID name.
  6. Select the Broadcast SSID check box.
  7. From the SSID Type drop-down list, select Private.
  8. From the Radio drop-down list, select 2.4 GHz and 5 GHz.
  9. From the Security drop-down list, select WPA2 Enterprise.
  10. From the Authentication Domain drop-down list, select the domain you created in the previous section.
  11. In the Network section, select Bridged.

Screenshot of the Add SSID page in WatchGuard Cloud

  1. Click Save.
  2. Click Schedule Deployment.
  3. Select Deploy changes now.
  4. In the Description text box, type a description for the deployment.
  5. Click Deploy.
  6. Click Close.
  7. Click Back to return to the site configuration settings.
  8. Select the Subscribed Devices tab.

Screenshot of WGC, picture8

  1. Click Select Devices.
  2. Select the access points to subscribe to the site.
  3. Click Save.

Test Portnox™ CLEAR Integration

  1. Use a wireless client to connect to the SSID you created. For example: AP330_Portnox_Clear
  2. Type your user name and password that you received in the Portnox configuration.

You should see a 802.1X authentication success notification in the Portnox alerts page.

Screenshot of the Portnox Clear alerts page