## HPE Aruba Networking ClearPass Policy Manager

### Key features

- Role based, unified network access enforcement across multendor wireless, wired, and VPN networks
- Intuitive policy configuration templates and visibility troubleshooting tools
- Supports multiple authentication/ authorization sources (AD, DAR, SOL)
- Self-service device onboarding with built-in certificate authority (CA) for bring your own device (BRO)
- Guest access with extensive customization, branding, and sponsor-based approvals
- Integration with key UEM solutions for in-depth device assessments
- Comprehensive integration with the HPE Aruba Networking 360 Security Exchange program
- Single sign-on (SSO) support works with Ping, Okla, and other identity management tools to improve user experience with SAML, LDX-based applications
- FPS 140 2 and CC certified

HPE Aruba Networking ClearPass Policy Manager provides role and device-based secure network access control for Internet of Things (IoT), BYOD, corporate devices, and employees, contractors, and guests across any multivendor wired, wireless and VPN infrastructure.

With a built-in context-based policy engine, Remote Authentication Dial-In User Service (RADIUS), TAQACS+ non-RADIUS enforcement using HPE Aruba Networking ClearPass OnConnect, device profiling, posture assessment, onboarding, and guest access options, HPE Aruba Networking ClearPass is unrivaled as a foundation for network security for organizations of any size.

For comprehensive integrated security coverage and response using firewalls, unified endpoint management (UEM), and other existing solutions, HPE Aruba Networking ClearPass supports the HPE Aruba Networking 360 Security Exchange program. This allows for automated threat detection and response workflows that integrate with third-party security vendors and IT systems previously requiring manual IT intervention.

In addition, HPE Aruba Networking ClearPass supports secure self-service capabilities, making it easier for end users trying to access the network. Users can securely configure their own devices for enterprise use or internet access based on admin policy controls.

The result is detailed visibility of all wired and wireless devices connecting to the enterprise increased control through simplified and automated authentication or authorization of devices, and faster, better incident analysis and response through the integration and orchestration with third-party security solutions. This is achieved with a comprehensive and scalable policy management platform that goes beyond traditional AAA solutions to deliver extensive enforcement capabilities for IT-owned and BYOD security requirements.

### The HPE Aruba Networking ClearPass difference

HPE Aruba Networking ClearPass is the only policy platform that centrally enforces all aspects of enterprise-grade access security for any industry. Granular policy enforcement is based on a user's role, device type and role, authentication method, UEM attributes, device health, traffic patterns, location, and time of day.

Deployment scalability supports tens of thousands of devices and authentications which surpasses the capabilities offered by legacy AAA solutions. Options exist for small to large organizations, from centralized to distributed environments.

### Advanced policy management

#### Enforcement and visibility for wired and wireless

With HPE Aruba Networking ClearPass, organizations can deploy wired or wireless using standards-based 802.1X enforcement for secure authentication. HPE Aruba Networking ClearPass also supports MAC address authentication for IoT and headless devices that may lack support for 802.1X. For wired environments where RADIUS-based authentication cannot be deployed, HPE Aruba Networking ClearPass OnConnect offers an alternative using Simple Network Management Protocol (SNMP)-based enforcement.

HPE Aruba Networking ClearPass Device Insight provides next-generation profiling capabilities to HPE Aruba Networking ClearPass Policy Manager through a cloud-based machine learning algorithm that also leverages deep packet inspection support.

Authentication methods can be used to concurrently support a variety of use cases. It also includes support for multifactor authentication based on login times, posture checks, and other contexts such as new user, new device, and more.

Attributes from multiple identity stores such as Microsoft Active Directory, LDAP-compliant directories, ODBC-compliant SQL databases, token servers, and internal databases across domains can be used within a single policy for fine-grained control.

Contextual data from these profiled devices allows IT to define what devices can access either the wired, VPN, or wireless network. Device profile changes are dynamically used to modify authorization privileges. For example, if a Windows laptop appears as a printer, HPE Aruba Networking ClearPass policies can automatically deny access.

#### Secure device configuration of personal devices

HPE Aruba Networking ClearPass Onboard provides automated provisioning of any Windows, macOS, iOS, Android™, Chromebook™, and Ubuntu devices through a user-driven self-guided portal. Network details, security settings, and unique device identity certificates are automatically configured on authorized devices. Cloud identity services such as Microsoft Azure Active Directory, Google™ G Suite, and Okta can also be leveraged as identity providers with HPE Aruba Networking ClearPass Onboard for secure certificate enrollment.

#### Device health checks

HPE Aruba Networking ClearPass OnGuard delivers endpoint posture assessments over wireless, wired, and VPN connections. HPE Aruba Networking ClearPass OnGuard health check capabilities help ensure endpoints meet security and compliance policies before they connect to the network. HPE Aruba Networking ClearPass OnGuard offers a variety of flexible deployment options including agentless, dissolvable agents, and agent-based configuration.

#### Customizable visitor management

HPE Aruba Networking ClearPass Guest simplifies visitor workflow processes to enable employees, receptionists, and other non-IT staff to create temporary guest accounts for secure wireless and wired access. Highly customizable, mobile-friendly portals provide easy-to-use login processes that include self-registration, sponsor approval, and bulk credential creation support for any visitor needs — enterprise, retail, education, large public venue. Credentials can be delivered by SMS, email, printed badges, or input directly through cloud identity providers such as Facebook or Twitter.

### HPE Aruba Networking 360 Security Exchange program

#### Integrate with security and workflow systems

Support for the HPE Aruba Networking 360 Security Exchange program is an integrated component of HPE Aruba Networking ClearPass. Using features such as REST-based application programming interfaces (APIs), RADIUS accounting proxy, and Syslog ingestion help facilitate workflows with UEM, security information and event management (SIEM), firewalls, help desk systems, and more. Context is shared between each component for end-to-end policy enforcement and visibility.

The HPE Aruba Networking ClearPass Ingress Event Engine provides third-party systems with the means to share information in real time using Syslog. This enables HPE Aruba Networking ClearPass to respond to changing threats for users and devices after they have authenticated to the network.

By utilizing an open dictionary approach, anyone can write a parsing ruleset without the need for costly add-ons or locked in third-party ecosystems.

### Advanced reporting and alerting

HPE Aruba Networking ClearPass Device Insight provides advanced reporting capabilities through customizable reports. Information about authentication trends, profiled devices, guest data, onboarded devices, and endpoint health can also be viewed in an easy-to-use dashboard. HPE Aruba Networking ClearPass Device Insight also has support for granular alerts and a watchlist to monitor specific authentication failures.

### HPE Aruba Networking Central NetConductor

For networks managed by HPE Aruba Networking Central, HPE Aruba Networking Central NetConductor offers cloud-native security services that enable global policy management and network configuration with simple business logic interfaces and workflows. HPE Aruba Networking Central NetConductor uses a distributed EVPN/VXLAN network overlay to facilitate inline policy enforcement across large, globally dispersed networks.

Networks that use HPE Aruba Networking Central NetConductor for policy orchestration can choose either HPE Aruba Networking Client Insights or HPE Aruba Networking ClearPass for authentication and role assignment.

### Technical specifications

#### Appliances

HPE Aruba Networking ClearPass is available as hardware or as a virtual appliance. Virtual appliances are supported on VMware vSphere® Hypervisor (VMware ESXi™), Microsoft HyperV, CentOS KVM, Amazon EC2, and Microsoft Azure.

#### Framework and protocol support

- RADIUS, RADIUS dynamic authorization, TACACS+ web authentication, SAML v2.0
- RadSec (TLS encoded RADIUS)
- 802.1X-2010, 802.1X-2020

### Supported identity stores

- Microsoft Active Directory
- RADIUS
- Any LDAP-compliant directory
- MySQL, Microsoft SQL, PostgreSQL, and Oracle® 11g ODBC-compliant SQL Server
- Token servers
- Built-in SQL store, static hosts list
- Kerberos
- Microsoft Azure Active Directory
- Google G Suite
