Product Overview
RG-SMP+ is Ruijie Networks' next-generation identity-based intelligent admission management platform for all types of terminals, dedicated to building the first line of defense in network security.
RG-SMP+ can seamlessly integrate Ruijie Networks' hardware devices, including campus switches, access controllers (ACs), egress gateways, routers, and firewalls, and is compatible with third-party switches and ACs. It provides comprehensive Network Admission Control (NAC) solutions tailored to customer requirements.
The platform provides authentication, access control, accounting, log management, and unified external interfaces in one system. It supports comprehensive identity authentication policy management based on factors such as users/user groups, authentication methods, access types, and access locations in Bring Your Own Device (BYOD) scenarios, significantly reducing investment costs and improving management efficiency.
In terms of technologies, RG-SMP+ adopts the microservices architecture, boasts excellent stability and high availability, and can support large-scale network access scenarios with more than 300,000 terminals.
Platform features:
● Flexible identity authentication and terminal admission processes
● Fine-grained access permission management based on users, terminals, and regions
● Detailed command-level auditing, ensuring transparency
● Powerful log management and service auditing tools
● Intelligent terminal identification based on dual engines: Rules + large language model (LLM)
● Full-lifecycle management of terminals and room-level precise locating
● Multiple authentication modes, including Single Sign-on (SSO), username/password authentication, MAC authentication, and Private Pre-Shared Key (PPSK)
● Interconnection with multiple identity sources, including Microsoft AD, Google Workspace, Lightweight Directory Access Protocol (LDAP), and eduroam
● Flexible self-service guest registration and authentication
● Fine-grained Internet access permission management
● Source tracing
RG-SMP+ is designed to provide global customers with a reliable and efficient network security management tool to cope with increasingly complex network environments.
Product Features
Authentication
RG-SMP+ supports a rich variety of authentication methods to meet the diversified identity authentication requirements of different industries and scenarios.
Authentication Protocols
● A variety of authentication protocols, including IEEE 802.1X (WPA2/WPA3), Portal (Captive Portal, Central Web Authentication [CWA], and CMCC web authentication), and MAC authentication bypass (MAB)
● A variety of identity authentication protocols, including Password Authentication Protocol (PAP), Challenge-Handshake Authentication Protocol [CHAP], MS-CHAP v1/v2, Extensible Authentication Protocol-Message Digest 5 (EAP-MD5), EAP-Transport Layer Security (EAP-TLS), and Protected EAP (PEAP), such as MS-CHAP v2, Generic Token Card (GTC), and MD5
Authentication Methods
● Web-based authentication, 802.1X authentication, SMS authentication, QR code authentication, USB key authentication, and One-Time Password (OTP) authentication
● PPSK authentication
● Third-party identity sources, such as eduroam, Microsoft AD, Google Workspace, and LDAP
● Social media account authentication (for example, Facebook and WhatsApp) for guest scenarios
SSO for Unified Authentication
● RG-SMP+ supports integration over Security Assertion Markup Language (SAML), Open Authorization 2.0 (OAuth2), and Central Authentication Service (CAS) protocols (for example, SourceID, Google Workspace, Microsoft AD, and Office 365).
Identity Sources
● Local accounts, AD domains, LDAP, and digital certificates (CA)
● Microsoft AD, Google Workspace, LDAP, eduroam, eDirectory, and third-party RADIUS servers
Multi-Factor Authentication (MFA)
● Username/password + SMS verification code, or username/password + OTP
Guest Authentication
● Self-service registration and approval-based registration for guests
● Guest registration based on social media accounts (Facebook and WhatsApp)
● One-click terms acceptance for guest authentication
● SMS-based registration/login, WeChat mini program authentication, receptionist-assisted guest registration through QR code scanning, and voucher authentication
● Guest account management (account creation in batches, and automatic disconnection and account deletion upon expiration)
Access Control
● RG-SMP+ supports user identity-based network access control, time-scheduled switching of security zones, and authorization with custom RADIUS attributes.
● RG-SMP+ supports user/IP-based bandwidth management and quota policies, which interoperate with Ruijie's devices for optimized network control.
Others
● eduroam authentication
● ACL bypass and recovery
● Terminal Access Controller Access Control System+ (TACACS+) for device-level access control, including login authentication, Enable authentication, command authorization, and command auditing
Fine-grained Access Permission
● Fine-grained access permission management based on users, terminals, and regions, assigning differentiated network access permissions to different identities and scenarios
Source Tracing
● Detailed authentication logs, including username, MAC address, IP address, SSID, and AP for source tracing
● Real-time tracking of user connection status and trajectory, allowing administrators to obtain real-time behavior data
Detailed Internet Access Logs
● Internet access authentication logs
● Internet access detail logs
● Administrator operation logs
● Syslog forwarding
Operation Management
● Online user management, user behavior analysis, log management, and wireless roaming management, as well as real-time online user dashboards with automatic refresh
● Powerful data export capabilities: Exporting online user data to Excel for offline verification and sharing with external systems or organizations
Log and O&M Monitoring
● Internet access authentication logs, Internet access detail logs, and administrator operation logs
● Service health scoring: Real-time evaluation of system health
● Near-real-time dashboards: Online users, authentication concurrency, accounting concurrency, and authentication failure statistics updated every 30 seconds
● Automatic data clearing: Automatic deletion of over 30 types of logs, and retention of online logs for up to 1,095 days (180 days by default)
Standard APIs
● User management APIs
● Log query APIs
● MAB management APIs

