Skip to content
Cybersecurity Aruba Networks

Aruba ClearPass

Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.

Sales Representative
Przemysław Widomski

Przemysław Widomski

Sales Representative

Key Features

  • Automatic profiling of 70,000+ device types
  • 802.1X and RADIUS for enterprise authentication
  • Zero Trust Network Access with microsegmentation
  • BYOD onboarding without IT involvement
  • Guest access portal with customization
Available now
Przemysław Widomski

Przemysław Widomski

Sales Representative

Send inquiry
Table of Contents

Why do you need network access control?

Network access control is the point in cybersecurity where the decision is taken before anything happens: either a device gets an address and full visibility of the network, or it lands in a segment from which very little is reachable. NAC answers the question of who takes that decision — an administrator at the wall socket, or a policy that behaves the same at night and in a branch office.

A socket in a meeting room does not ask what is being plugged into it — only an access policy does. Without visibility and control, every IoT device, guest laptop, or employee’s personal phone is a potential threat. Traditional “trust the network” approach doesn’t work in the Zero Trust era.

Aruba ClearPass Policy Manager is a NAC (Network Access Control) platform that profiles over 70,000 device types from its signature database and enforces access policies in real time — on switches and access points from any vendor that speaks RADIUS.

How does it work?

Device Profiling

Automatic identification of every device:

  • 70,000+ devices in signature database
  • Machine learning for unknown devices
  • Continuous profiling - not just at connection
  • Threat intelligence integration

Policy Engine

Centralized access policy management:

  • Role-based access per user/device/location
  • Dynamic Segmentation on switches and APs
  • Automatic non-compliance remediation
  • Context-aware policies (time, location, posture)

Zero Trust Enforcement

Least privilege principle enforcement:

  • Network traffic microsegmentation
  • Continuous verification - not just at login
  • Automatic isolation of suspicious devices
  • Integration with firewalls and SIEM

Main Features

Authentication

  • 802.1X with EAP-TLS, PEAP, EAP-TTLS
  • RADIUS server for all devices
  • TACACS+ for network devices
  • MAC Authentication Bypass for IoT

Endpoint Posture

  • OnGuard agent for Windows/macOS
  • Agentless assessment via network
  • AV, patch, configuration checking
  • Auto-remediation or quarantine

Guest & BYOD

  • Self-service portal for guests
  • Employee-sponsored access
  • BYOD onboarding with certificates
  • Customizable branding and workflow

Integrations

  • 150+ technology partners
  • Firewalls (Fortinet, Check Point)
  • MDM (Intune, Jamf, Workspace ONE)
  • SIEM (Splunk, QRadar, Sentinel)

Architecture

Policy Manager: Central policy and RADIUS server

Device Insight: Cloud-based device profiling with AI

OnGuard: Posture assessment agent

Guest: Portal for guests and BYOD

OnBoard: Automatic certificate issuance

Who is it for?

  • Organizations implementing Zero Trust Network Access
  • Enterprises with BYOD policies
  • Environments with large number of IoT devices (healthcare, manufacturing)
  • Regulated industries requiring access audit (finance, public sector)

Benefits

For IT: Automatic onboarding, fewer help desk tickets, full device visibility

For security: Zero Trust without network redesign, threat isolation, compliance ready

For business: Secure BYOD, risk-free guest access, regulatory compliance

Specifications

DeploymentHardware appliance, VM, cloud
High AvailabilityActive/standby clustering
Device database70,000+ profiles
Integrations150+ ecosystem partners

What access control changes after a breach

NAC is bought for the day something already went wrong. Three questions decide whether it helps on that day:

  • What an unknown device is allowed to do before it is identified. The default answer on most networks is “everything”, and that default is the whole problem.
  • Whether the policy survives the switch being replaced. Rules kept on individual ports disappear with the hardware; rules kept centrally do not.
  • What happens when a device stops meeting the policy — an alert somebody reads on Monday, or an automatic move to a segment where the damage stops.

Access policies, segmentation and their verification are part of network security; how an isolated device is then handled belongs to incident response.

FAQ

Does ClearPass require Aruba devices? No. ClearPass works with switches and APs from any vendor supporting RADIUS.

How many devices can be profiled? Database contains 70,000+ profiles. Unknown devices are classified by ML.

How does licensing work? Per endpoint. Access (basic) or OnGuard (with posture assessment) licenses.

Does ClearPass replace Active Directory? No. Integrates with AD/LDAP as identity and authorization source.

How does BYOD onboarding work? User connects to portal, downloads profile/certificate, and device is automatically configured.

Can I check endpoint security state? Yes. OnGuard checks AV, firewall, patches and can block or fix non-compliance.

How does firewall integration work? ClearPass sends context (user, device, role) to firewall via API or syslog.

Is cloud version available? ClearPass is on-premises. Device Insight (profiling) is in cloud.

What security certifications? Common Criteria, FIPS 140-2, GDPR, HIPAA, PCI DSS compliance.

What about support? HPE Foundation Care. nFlo as a partner provides deployment, integrations, and training.

Inquire about Aruba ClearPass

Contact your product specialist and get a custom quote.

Sales Representative
Przemysław Widomski

Przemysław Widomski

Sales Representative

Response within 24 hours
Free technical consultation
Custom quote and configuration

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist