Aruba ClearPass
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.

Key Features
- Automatic profiling of 70,000+ device types
- 802.1X and RADIUS for enterprise authentication
- Zero Trust Network Access with microsegmentation
- BYOD onboarding without IT involvement
- Guest access portal with customization
Table of Contents
Why do you need network access control?
Network access control is the point in cybersecurity where the decision is taken before anything happens: either a device gets an address and full visibility of the network, or it lands in a segment from which very little is reachable. NAC answers the question of who takes that decision — an administrator at the wall socket, or a policy that behaves the same at night and in a branch office.
A socket in a meeting room does not ask what is being plugged into it — only an access policy does. Without visibility and control, every IoT device, guest laptop, or employee’s personal phone is a potential threat. Traditional “trust the network” approach doesn’t work in the Zero Trust era.
Aruba ClearPass Policy Manager is a NAC (Network Access Control) platform that profiles over 70,000 device types from its signature database and enforces access policies in real time — on switches and access points from any vendor that speaks RADIUS.
How does it work?
Device Profiling
Automatic identification of every device:
- 70,000+ devices in signature database
- Machine learning for unknown devices
- Continuous profiling - not just at connection
- Threat intelligence integration
Policy Engine
Centralized access policy management:
- Role-based access per user/device/location
- Dynamic Segmentation on switches and APs
- Automatic non-compliance remediation
- Context-aware policies (time, location, posture)
Zero Trust Enforcement
Least privilege principle enforcement:
- Network traffic microsegmentation
- Continuous verification - not just at login
- Automatic isolation of suspicious devices
- Integration with firewalls and SIEM
Main Features
Authentication
- 802.1X with EAP-TLS, PEAP, EAP-TTLS
- RADIUS server for all devices
- TACACS+ for network devices
- MAC Authentication Bypass for IoT
Endpoint Posture
- OnGuard agent for Windows/macOS
- Agentless assessment via network
- AV, patch, configuration checking
- Auto-remediation or quarantine
Guest & BYOD
- Self-service portal for guests
- Employee-sponsored access
- BYOD onboarding with certificates
- Customizable branding and workflow
Integrations
- 150+ technology partners
- Firewalls (Fortinet, Check Point)
- MDM (Intune, Jamf, Workspace ONE)
- SIEM (Splunk, QRadar, Sentinel)
Architecture
Policy Manager: Central policy and RADIUS server
Device Insight: Cloud-based device profiling with AI
OnGuard: Posture assessment agent
Guest: Portal for guests and BYOD
OnBoard: Automatic certificate issuance
Who is it for?
- Organizations implementing Zero Trust Network Access
- Enterprises with BYOD policies
- Environments with large number of IoT devices (healthcare, manufacturing)
- Regulated industries requiring access audit (finance, public sector)
Benefits
For IT: Automatic onboarding, fewer help desk tickets, full device visibility
For security: Zero Trust without network redesign, threat isolation, compliance ready
For business: Secure BYOD, risk-free guest access, regulatory compliance
Specifications
| Deployment | Hardware appliance, VM, cloud |
| High Availability | Active/standby clustering |
| Device database | 70,000+ profiles |
| Integrations | 150+ ecosystem partners |
What access control changes after a breach
NAC is bought for the day something already went wrong. Three questions decide whether it helps on that day:
- What an unknown device is allowed to do before it is identified. The default answer on most networks is “everything”, and that default is the whole problem.
- Whether the policy survives the switch being replaced. Rules kept on individual ports disappear with the hardware; rules kept centrally do not.
- What happens when a device stops meeting the policy — an alert somebody reads on Monday, or an automatic move to a segment where the damage stops.
Access policies, segmentation and their verification are part of network security; how an isolated device is then handled belongs to incident response.
FAQ
Does ClearPass require Aruba devices? No. ClearPass works with switches and APs from any vendor supporting RADIUS.
How many devices can be profiled? Database contains 70,000+ profiles. Unknown devices are classified by ML.
How does licensing work? Per endpoint. Access (basic) or OnGuard (with posture assessment) licenses.
Does ClearPass replace Active Directory? No. Integrates with AD/LDAP as identity and authorization source.
How does BYOD onboarding work? User connects to portal, downloads profile/certificate, and device is automatically configured.
Can I check endpoint security state? Yes. OnGuard checks AV, firewall, patches and can block or fix non-compliance.
How does firewall integration work? ClearPass sends context (user, device, role) to firewall via API or syslog.
Is cloud version available? ClearPass is on-premises. Device Insight (profiling) is in cloud.
What security certifications? Common Criteria, FIPS 140-2, GDPR, HIPAA, PCI DSS compliance.
What about support? HPE Foundation Care. nFlo as a partner provides deployment, integrations, and training.
Inquire about Aruba ClearPass
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Comprehensive Network Infrastructure Implementation
IT Infrastructure
Build a network that doesn't fail. From design through implementation to 24/7 support.
Professional WiFi Penetration Testing
Cybersecurity
One unsecured WiFi network = open backdoor to infrastructure. Test before intruders get in.
Professional WiFi Network Implementation
IT Infrastructure
WiFi without dead zones and half speed. Site survey + professional deployment.
Active Directory Security Audit
Cybersecurity
We find paths to Domain Admin before attackers do.
From Our Knowledge Base
Articles related to this solution
Is ISO 27001 enough for NIS2? What mapping does not cover
An ISO 27001 certificate organises your information security management system, but it does not answer whether your organisation performs the duties imposed by NIS2 and its national implementing act.
Is SIEM enough for NIS2? What remains after the tool is deployed
A deployed SIEM satisfies the requirement to place the information system under continuous monitoring, but it does not satisfy the obligation to manage incidents or to report them within the deadlines set by the Polish National Cybersecurity System Act.
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Related Products
Other solutions you might be interested in
Aruba Access Points
Aruba Networks
Aruba Access Points: Wi-Fi 6/6E/7 for the enterprise. Ultra Tri-Band, AI-driven RF optimization, Zero Trust and built-in IoT radios, run from Aruba Central.
Aruba AirWave
Aruba Networks
Aruba AirWave: on-premises multi-vendor network management. Monitoring, configuration, compliance for existing deployments.
Aruba Central
Aruba Networks
Aruba Central: cloud-native network management with AIOps. Single dashboard for Wi-Fi, switching, SD-WAN. Zero Touch Provisioning.
Aruba CX Switches
Aruba Networks
Aruba CX Switches: next-generation campus and data center switches on AOS-CX. REST API, Network Analytics Engine, VSX high availability without STP.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist