Skip to content
EasyPSK

Release Notes

What has changed in EasyPSK for Cisco Networks, newest first.

Bug fixes and routine maintenance are not listed here. The platform release notes cover every service in one feed.

  1. 2026

    New

    Attribute Profiles on an EasyPSK group #

    An EasyPSK group can be given Attribute Profiles from its Group Settings, so the network policy returned at authentication, a VLAN through tunnel attributes or a Cisco security group tag, is set per group. The other EntryPoint variants already worked this way and EasyPSK now matches them.

    Profiles are defined once on the service context and reused across its groups.

    EntryPoint

  2. 2026

    New

    Reconcile a whole Meraki WPN context from one CSV file #

    Batch Group Sync takes a CSV of groups, units and members and reconciles an entire context against it in one run. Groups and users are created, updated, reset or removed so the context ends up matching the file.

    Nothing is applied before you have seen it. The file is parsed and analysed first, then a review step reports the counts per action and asks you to confirm the scope of what the run will change. A file with errors blocks the analysis rather than producing a half-applied run.

    The run is monitored live, survives a page refresh, and can be exported as a CSV when it finishes. Earlier runs are kept in a run history.

    It is reached from the Groups page of a Meraki WPN context. An example file can be downloaded from the upload step, and a context can export its current groups as a CSV to start from.

    Improved

    Optional phone number on a Meraki WPN member #

    A member of a Meraki WPN group can carry a phone number. Administrators set it from the admin console, and group administrators can set or update it in the Self-Service portal.

    The number has to include a country code. It is contact information held with the member and nothing is sent to it.

    Self-Service

  3. 2026

    New

    Reveal and rotate a device key from the Self-Service portal #

    A Self-Service User can see a device key, copy it, and read it as a Wi-Fi QR code together with the network name, without going through an administrator.

    Rotating a key is tied to the user's role and can be switched off for the context, so an administrator decides whether delegated users may regenerate keys at all.

    The device view also shows accounting data for the group, so a delegated administrator can see what is actually connected.

    Self-Service

    Improved

    Better device type identification #

    Device type is derived from more of the profiling data the wireless network reports, so devices that previously showed as unknown are now classified. Apple TV, Apple Watch and HomePod are recognised as their own types rather than being lumped together.

    EntryPoint

    New

    EasyPSK over RADIUS #

    EasyPSK can now be delivered over RADIUS, created and managed as a context variant of EntryPoint, alongside the existing Cisco Meraki WPN path. The key a device presents identifies its group, and the group's network attributes are returned at authentication, so keys resolve at connect time instead of being pushed into the wireless platform in advance.

    This is the primary delivery for Cisco Meraki and Cisco Catalyst 9800. It carries far more keys than the Dashboard API path, which remains available and is capped per Meraki network.

    A group is created with one of three flavours. Instant shares one group key and registers a device on first connect. Approved shares one group key but admits only MAC addresses registered in advance, with optional four-eyes approval. Dedicated gives every device its own key, and both the MAC and the key have to match.

    EntryPoint

  4. 2026

    New

    Private connectivity between the platform and your network #

    An organization can reach the platform over a private IPSec tunnel instead of the public internet. A firewall, or any device on your side that supports IPSec, establishes a single tunnel to a dedicated endpoint on the platform, and the services you bind to it carry their traffic through it.

    EntryPoint's RADIUS path, EasyPSK via RADIUS, the platform's access to an on-premises Cisco ISE, and webhook deliveries can each be bound to the same tunnel. Sign In is not carried this way: it uses the Service Gateway.

    A connector's page shows the settings to apply on your own device, including a worked Cisco IOS-XE example, the routes the connector publishes, and which services and ports are using it. Tunnel status is shown per connector, and the destination of a bound service can be changed without unbinding it first.

    Available to organization administrators and, for partners, in the MSP Portal.

    Service Connector Platform EntryPoint

  5. 2026

    Improved

    See the RADIUS payload behind an authentication #

    The admin console shows the incoming request as it arrived, so an authentication that did not behave as expected can be inspected without taking a packet capture.

    The device list searches across several fields at once, including the called station identifier, and shows a fuller description for 802.1X flows.

    EntryPoint

  6. 2026

    New

    Authentication Log #

    Every RADIUS authentication attempt is recorded with its outcome, and for a denial the specific reason: an unknown RADIUS client, a shared secret that does not match, an unregistered device, a user outside the expected group, or a configuration problem.

    An attempt expands into a timeline of the decision points that led to the outcome, and the request and the response can be inspected as readable tables rather than raw text.

    The log is filtered by time range, by decision and by free text, and it is embedded on the context and group pages as well as available on its own, so it can be reached from the device or group being investigated.

    EntryPoint

  7. 2024

    Changed

    A RADIUS client secret per service #

    The RADIUS client secret is held separately for each service instead of being shared, so a secret can be rotated for one service without disturbing the other.

    EntryPoint

  8. 2024

    New

    Meraki WPN in the Self-Service portal #

    A delegated administrator can manage the devices and members of a Meraki WPN group from the Self-Service portal, without an account in the admin console.

    Self-Service

  9. 2024

    New

    Meraki group policy and access policy strategy #

    A Meraki integration carries a group policy and an access policy strategy, set when the integration is added and changeable afterwards. The group policy can be changed where the strategy is a shared one, and the Meraki API user can be updated without recreating the integration.

Next