Aruba ClearPass Policy Manager
The most comprehensive network access policy enforcement platform for BYOD

Click here to jump to more pricing!
Please Note: All Prices are Inclusive of GST
Overview:
The Aruba ClearPass Policy Manager™ platform makes it easy to secure next-generation mobility services, enhance network access security and compliance, and streamline network operations for wired, wireless and VPN
A comprehensive policy management solution, the ClearPass Policy Manager platform includes ClearPass Guest, ClearPass Onboard and ClearPass OnGuard applications.
It also provides role-based policy management, detailed endpoint profiling, enterprise-grade RADIUS/TACACS+, BYOD and Apple Bonjour-enabled device registration, mobile device management (MDM), and administrative web access.
Whether local or remote, ClearPass makes it effortless to centrally manage and enforce user- and device-based access policies across multivendor campus and distributed network infrastructures, regardless of device ownership or connection method.
The ClearPass Policy Manager platform makes it easy to secure next-generation mobility services, enhance network access security and compliance, and streamline network operations for wired, wireless and VPNs.
The industry's most comprehensive policy management system, ClearPass offers role-based policies, detailed endpoint profiling, enterprise-grade RADIUS/TACACS+, BYOD and Apple Bonjourenabled device registration, mobile device management (MDM), and administrative web access.
ClearPass is available as an enterprise starter bundle with guest access, device onboarding and posture assessment capabilities for up to 25 endpoints. Additional ClearPass Guest, Onboard and OnGuard licenses are available for a larger number of devices.
Whether local or remote, ClearPass makes it effortless to centrally manage and enforce user- and device-based access policies across multivendor campus and distributed network infrastructures, regardless of device ownership or connection method.
The result is consistent, automated and secure network access that meets today's evolving BYOD and IT-managed mobile device requirements - delivered from a single, extensible platform with capabilities that grow and adapt to changing business needs.

The most comprehensive policy management platform for BYOD
ClearPass policy management capabilities can secure tens of thousands of mobile users, devices and applications from one integrated platform. Offering strong network access security and compliance, ClearPass streamlines network operations across wired, wireless and VPNs.
BYOD that does it all
Role-based policy management, device profiling, enterprise-grade AAA with RADIUS/TACACS+, user-driven onboarding, Apple Bonjour device registration, and a mobile device management connector for integration with third-party MDM solutions - all through a single web interface.
Any network, anywhere
ClearPass integrates seamlessly with any multivendor, multisite enterprise network, making it easy for you to roll-out and enforce access policies based on contextual information like user, device, location, application and time of day.
Integrated device profiling
Discover, categorize and maintain a real-time database of endpoints using MAC organizational unique identifiers (OUIs), DHCP fingerprinting, link-layer discovery protocol (LLDP) and CDP, and onboarding inventory to enforce context-aware access policies.
Regulatory compliance
Monitor current and archived network access activity, configure alerts, generate a variety of compliance reports, audit the authentication infrastructure, and obtain analytics based on user roles, class of device and access location.
ClearPass Video Datasheet:
Programs and Features:
- Unsurpassed multivendor wireless and wired interoperability
- Built-in guest, profiling, network access control
- Onboarding of leading endpoint operating systems
- Easy-to-use policy creation and troubleshooting interface
- Proactive policy simulation and testing utilities
- Real-time user and device access logs track each authentication
- Convenient dashboards for user and device authentication analysis
- Published and open API for simple third-party integration
- MDM interoperability via API connector services
- Fully-replicated active clustering for high availability, redundancy and load balancing
- Advanced reporting, analytics, alerts and archiving for compliance and auditing
ClearPass Onboard
An application for the ClearPass Policy Manager platform, ClearPass Onboard automatically provisions and configures personally-owned mobile devices - Windows, Mac OS X, iOS and Android 2.2 and above - enabling them to securely connect to the network.
With ClearPass Onboard, it’s easy for employees, contractors and partners to self-configure their own mobile devices for BYOD. The ClearPass registration portal automatically detects a device’s operating system and presents the user with the appropriate configuration package.
ClearPass Onboard provides an incredibly simple way to configure wireless, wired and VPN settings, apply unique device credentials, and ensure that users securely connect their devices to 802.1X-enabled networks with minimal IT involvement.
The result is a streamlined workflow that allows IT helpdesk personnel to automate and secure multiple processes that are required to successfully carry out BYOD initiatives while improving the user experience.
ClearPass Onboard also significantly increases the amount of actionable information that is captured for troubleshooting, user- and device-based policies, and compliance and reporting requirements.
Key Features
- Enables users to self-register and securely onboard multiple devices.
- Supports Windows, Mac OS X, iOS and Android operating systems.
- Automates the configuration of network settings for wired and wireless endpoints.
- Unique provisioning and revocation of device-specific credentials.
- Contains built-in public key infrastructure (PKI).
- Uses profiling to identify device type, manufacturer and model.
- Provides BYOD visibility and centralized policy management capabilities.
ClearPass Guest
An application for the ClearPass Policy Manager platform, ClearPass Guest is a scalable, easy-to-use visitor management solution that delivers secure wired and wireless network access to guests, employees, contractors and their mobile devices.
Greatly simplifying visitor management, ClearPass Guest streamlines workflow processes, allowing operators or sponsors - receptionists, even coordinators and other non-IT staff - to create temporary accounts for Wi-Fi access.
Guests can also self-register for network access. Once registered, ClearPass Guest delivers account login credentials to users via print, SMS text message or email. Accounts can be set to expire automatically after a specific number of hours or days.
Scalable to satisfy the needs of large enterprises and multisite networks, ClearPass Guest manages secure, role-based access for hundreds of thousands of concurrent users.
ClearPass also enhances the guest experience by enabling organizations to create a branded look and feel on visitor registration pages. Organizations can post news updates, discount offers, upcoming events and other customized content.
- Key Features:
- A ClearPass Policy Manager starter-bundle includes ClearPass Guest.
- Create and modify temporary user accounts; delete or set accounts to automatically expire.
- Scales to support thousands of concurrent users with minimal IT involvement.
- Unique username and password per user.
- Guests and employees can register for access through a customizable web interface.
- Deliver guest account credentials via print, SMS or email to simplify registration.
- Customizable skin technology enables the creation of uniquely branded captive portal and guest login pages.
ClearPass OnGuard
An application for the ClearPass Policy Manager platform, ClearPass OnGuard performs automated endpoint posture assessments on leading computer operating systems to ensure that compliance is met before devices connect to wireless and wired networks.
Running on the ClearPass Policy Manager platform, the advanced network access control (NAC) and network access protection (NAP) framework in ClearPass OnGuard delivers exceptional protection against vulnerabilities.
ClearPass OnGuard supports a wide range of operating systems and versions:
- Microsoft - Support for Windows 7, Windows Vista, Windows XP, Windows 2000 and 2003.
- Apple - Support for Mac OS X.
- Linux - Support for Red Hat Enterprise Linux 4 and above, Community Enterprise Operating System (CentOS) 4 and above, Fedora Core 5 and above, and SUSE Linux 10.x.
In addition to endpoint posture and health checks on anti-virus, anti-spyware and personal firewall applications, OnGuard agents perform advanced health checks that specify how to handle the use of peer-to-peer applications, USB storage devices and bridged network interfaces.
When running persistent OnGuard agents on endpoints, ClearPass Policy Manager can centrally identify and manage health-check settings, send system-wide notifications and alerts, and allow or deny network access.
Key Features:
- Enhanced capabilities for endpoint compliance and control, including NAC and NAP.
- Supports Microsoft, Apple, and Linux operating systems.
- Anti-virus, anti-spyware, firewall checks and more.
- Optional auto-remediation and quarantine capabilities.
- Peer-to-peer application checks, process checks and registry-key checks with remediation.
- System-wide endpoint messaging, notifications and session access control.
- Centrally view the online status of all devices from the ClearPass Policy Manager platform.
Advantage:
ClearPass satisfies the demand for secure and efficient network access, policy enforcement and BYOD deployment. From one easy-to-manage platform, ClearPass presents a complete and accurate view of who and what has connected to wireless and wired network.
- Simplicity - An intuitive web interface for administration and userdriven service portals ensures that mandated security measures are easy to implement and maintain, without requiring additional IT resources, management applications or appliances.
- Operational efficiency - A complete out-of-the-box platform, ClearPass includes differentiated role-based access, enterprisegrade AAA, BYOD provisioning, device profiling, advanced reporting, and MDM capabilities across wireless, wired and VPNs.
- Innovation - ClearPass includes many innovative BYOD capabilities, including uncommonly simple policy management, customizable guest access features, the ability to onboard hundreds of thousands of mobile device, and certificate management applications.
Advanced Enforcement Capabilities:
Broad multivendor support
ClearPass includes a full complement of enforcement options for the largest possible mix of use-cases and does not require a forklift upgrade to the network infrastructure.
Using any 802.1X or non-802.1X-enabled APs or switches, ClearPass enforces a wide range of context-aware policies, including dynamic role-based access, VLAN and ACL assignments, and application-aware quality of service (QoS).
With ClearPass, a single policy can leverage multiple identity stores, including Microsoft Active Directory, LDAP-compliant directories, ODBC-compliant SQL databases, token servers and internal databases.
This enables IT to manage and enforce network access at multiple levels and across domains when merging organizations or departments. Identity stores also can be used for authentication and ongoing authorization of users and devices.
Integrated device profiling
Built-in profiling discovers, categorizes and maintains a real-time database of endpoints, regardless of device type and IP address. The collected data - MAC OUIs, DHCP fingerprinting, CDP/LLDP and onboarding inventory - is then used to enforce context-aware access policies. Profiling offers the visibility to determine mobile device adoption and ownership. It also modifies authorization privileges when device profile changes are detected. So, if a printer appears as a smartphone, ClearPass automatically denies access and quarantines the device.
Built-in BYOD enablement
A fully functional captive portal supports wired and wireless user authentication from a single ClearPass Policy Manager web page, which enhances the BYOD user experience and reduces administrative overhead.
It also includes Aruba AirGroup services, which let users register and share Bonjour-enabled iPads, Apple TVs and printers across VLANs. It optionally supports device registration to enforce policies based on the MAC address of gaming devices, printers and wireless IP cameras.
In BYOD environments with mobile device management, ClearPass can probe MDM databases for jailbroken status, password strength and other device information, and apply it to access policies. This safeguard can be used for any device that connects based on MDM status.
Unmanaged endpoint access
Unmanaged non-802.1X devices - printers, IP phones and IP cameras - can be identified as known or unknown when they connect to the network and their MAC addresses are verified through profiling or against an external or internal database. After this verification process, ClearPass Policy Manager will create policies that enforce differentiated access for these devices whenever they connect to the network and regardless of their location.
Scalable BYOD applications
Built-in endpoint capacity enables IT to fully leverage all ClearPass Policy Manager features and rightsize BYOD deployments to accommodate the number of employees, devices and guests that connect via wireless, wired and VPNs - at no additional cost.
Secure device onboarding
To ensure secure access for BYOD, ClearPass Onboard automatically provisions employee-owned Windows, Mac OS X, iOS and Android devices for 802.1X authentication and issues a unique device credential that can be revoked if a device is lost or stolen.
Additional information collected by ClearPass during the onboarding process - such as device serial number, operating system version and model number - is applied to wireless and wired network access policies.
Customizable guest access and management
ClearPass Guest makes it easy to implement self-registration and sponsor-based registration for guest Wi-Fi access. Sponsor roles let receptionists and non-IT personnel create differentiated and group guest accounts and distribute credentials before visitors arrive.
Self-registration and automated credential delivery streamlines IT operations and efficiency. Accounts can be set to automatically expire after a specific number of hours or days without IT involvement, and login credentials can be dispatched via email, SMS or label printers.
A customizable guest portal simplifies the creation of branded login screens, posting of code-of-conduct messaging, and placement of advertisements and relevant organizational updates based on user role, location, department and venue.
Real-time posture assessments
ClearPass OnGuard runs operating system, anti-virus, antispyware and firewall health checks to ensure compliance and network integrity before guest and employee-owned devices connect. OnGuard enforce policies for Windows, Mac OS X and Linux via persistent or dissolvable agents. ClearPass OnGuard advanced posture checks also allow peerto- peer apps, bridged network interfaces, VM instances, USB storage devices and specific registry key entries. For a seamless user experience, automatic remediation services are available for non-compliant devices.
ClearPass Policy Manager appliances
ClearPass Policy Manager is available as hardware or a virtual appliance. Both have identical functionality and capacity to support 500, 5,000 and 25,000 unique authenticating devices. It can be configured in publisher/subscriber mode for active clustering of multiple appliances.
The ClearPass Policy Manager virtual appliance is optimized to run on 64-bit VMware ESX and ESXi platforms, versions 4.0 (minimum), 5.0 and 5.1.
Specifications:
| Specifications | |
|---|---|
| Aruba ClearPass Policy Manager |
|
| Framework and Protocol Support |
|
| Supported Identity Stores |
|
| RFC Standards | 2246, 2248, 2548, 2759, 2865, 2866, 2869, 2882, 3079, 3579, 3580, 3748, 4017, 4137, 4849, 4851, 5019, 5216, 5280 |
| Internet Drafts | Protected EAP Versions 0 and 1, Microsoft CHAP extensions, dynamic provisioning using EAP-FAST, TACACS+. |
| Appliance Specifications | |||
|---|---|---|---|
| ClearPass Policy Manager-500 |
ClearPass Policy Manager-5000 |
ClearPass Policy Manager-25000 |
|
| CPU | (1) Dual Core Pentium | (1) Quad Core Xeon | (2) Six Core Xeon |
| Memory | 4 GB | 8 GB | 64 GB |
| Hard drive storage | (1) 3.5" SATA (7K RPM) 500GB hard drive | (2) 3.5" SATA (7.2K RPM) 500GB hard drives, RAID-1 controller | 6) 2.5" SAS (10K RPM) 600GB Hot-Plug hard drives, RAID-10 controller |
| Appliance Scalability | |||
| Maximum devices | 500 | 5,000 | 25,000 |
| Form Factor | |||
| Dimensions (W x H x D) |
16.8" x 1.7" x 14" | 17.53" x 1.7" x 26.17" | 17.53" x 1.7" x 26.17" |
| Weight (max config) | 14 Lbs | 39 Lbs | 39 Lbs |
| Power | |||
| Power consumption (maximum) | 260 watts max | 250 watts max | 750 watts max |
| Power supply | Single | Single | Dual hot-swappable (optional) |
| AC input voltage | 110/220 VAC auto-selecting | 110/220 VAC auto-selecting | 110/220 VAC auto-selecting |
| AC input frequency | 50/60 Hz auto-selecting | 50/60 Hz auto-selecting | 50/60 Hz auto-selecting |
| Environmental | |||
| Operating temperature | 10º C to 35º C (50º F to 95º F) | 10º C to 35º C (50º F to 95º F) | 10º C to 35º C (50º F to 95º F) |
| Operating vibration | 0.26 G at 5 Hz to 350 Hz for 5 minutes | 0.26 G at 5 Hz to 350 Hz for 5 minutes | 0.26 G at 5 Hz to 350 Hz for 5 minutes |
| Operating shock | 1 shock pulse of 31 G for up to 2.6 ms | 1 shock pulse of 31 G for up to 2.6 ms | 1 shock pulse of 31 G for up to 2.6 ms |
| Operating altitude | -16 m to 3,048 m (-50 ft to 10,000 ft) |
-16 m to 3,048 m (-50 ft to 10,000 ft) |
-16 m to 3,048 m (-50 ft to 10,000 ft) |
Documentation:
Pricing Notes:
- All Prices are Inclusive of GST
- Pricing and product availability subject to change without notice.
