You can configure Arista AGNI as a remediation agent in Device Intelligence. You can use the context based policies to fetch the MAC addresses of the devices and send it to AGNI Client Groups, and AGNI can be configured to take corresponding actions for the Client Group. The list of MAC addresses in the Client Group will be dynamically managed my Device Intelligence.
To do so, you need to follow a few steps:
-
Configure Arista AGNI in Device Intelligence
-
Arista AGNI use cases
-
Arista AGNI UI
Configure Arista AGNI in Device Intelligence
Follow the procedure to configure Arista AGNI in Device intelligence UI:
-
Navigate to the Manage > Configurations menu.
-
Give a unique name to the integration configuration.
-
Add a description.
-
Choose the type of supported remediation integration configurations as NAC.
-
Choose a supported vendor from the dropdown list as Arista AGNI.
-
Provide a valid host IP address or a domain name to connect to the network.
-
Choose token as authentication type and provide a token for configuration.
-
Choose a connection method as HTTPS.
-
Add required extra key-value pair parameters to pass to this configuration.
-
Click Create Configuration button
Once you configure Arista AGNI in Device Intelligence, you can use this as an action for your policies in the next step.
Arista AGNI Use Case
Follow the procedure to create the policy:
-
Navigate to the Policies menu and click on the Create Policy tab.
-
Mark the status of the policy to be active on creation.
-
Give a unique policy name.
-
Select the type as context policy.
-
Give a category of the policy as Computers.
-
Add a description to explain the policy behavior.
-
Define a custom condition to capture devices.
-
Click on Add Rule and select field as Category, condition as Equals, value as Computers and Mobile Phone. This condition will capture computer and mobile phone devices.
-
Click on Add Rule with OR conjunction and select field as OS, condition as Equals, value as IOS and Macos. This condition will capture devices with IOS and MacOS.
-
-
Select the action severity as High.
-
Select the action to take as NAC. Select NAC as the Arista AGNI NAC integration configured in Step 1.
-
Select Action as Segment.
-
Give a Segment Name as “Arista AGNI Segments”.
-
Click Save Policy.
You will see the policy results in Arista AGNI UI when this policy will capture devices.
Arista AGNI UI
Login to the Arista AGNI UI using your credentials, and you will see the devices captured in Device Intelligence policy are listed in Identity > Client > Clients which has a client group attached with segment name “Arista AGNI Segments”.

