ARUBA CLEARPASS POLICY MANAGER

Similar documents
ARUBA CLEARPASS POLICY MANAGER

QuickSpecs. Aruba ClearPass Policy Manager Platform. Overview. Aruba ClearPass Policy Manager Platform The most advanced Secure NAC platform available

ARUBA CLEARPASS POLICY MANAGER

ClearPass Policy Manager

ClearPass Getting Started Guide

ClearPass Policy Manager

ClearPass Deployment Guide

ClearPass Deployment Guide

Secure wired and wireless networks with smart access control

CLEARPASS GUEST. A ClearPass Policy Manager Application DATA SHEET KEY FEATURES THE CLEARPASS ADVANTAGES

CLEARPASS CONVERSATION GUIDE

Cisco ISE Features. Cisco Identity Services Engine Administrator Guide, Release 1.4 1

Provide One Year Free Update!

A. Post-Onboarding. the device wit be assigned the BYOQ-Provision firewall role in me Aruba Controller.

Visibility, control and response

ClearPass Ecosystem. Tomas Muliuolis HPE Aruba Baltics lead

QuickSpecs. Aruba ClearPass Guest Software. Overview. Aruba ClearPass Guest Software A ClearPass Policy Manager Application.

Cisco ISE Features Cisco ISE Features

Cisco Identity Services Engine

ARUBA CLEARPASS NETWORK ACCESS CONTROL

Secure Access - Update

Enterprise Guest Access

ACCP-V6.2Q&As. Aruba Certified Clearpass Professional v6.2. Pass Aruba ACCP-V6.2 Exam with 100% Guarantee

QuickSpecs. Aruba ClearPass OnGuard Software. Overview. Product overview. Key Features

Security and Control for all Devices on the Access Network

TITLE GOES HERE RUCKUS CLOUDPATH ENROLLMENT SYSTEM. The only integrated security and policy management platform that delivers: COMPRISED OF:

Cisco Network Admission Control (NAC) Solution

ARUBA AIRWAVE. Visibility and management for multi-vendor access networks DATA SHEET REAL-TIME MONITORING AND VISIBILITY

Conquering today s bring-your-own-device challenges. A framework for successful BYOD initiatives

CLEARPASS EXCHANGE. Open third party integration for endpoint controls, policy and threat prevention SOLUTION OVERVIEW MAKE BETTER-INFORMED DECISIONS

White paper. Combatant command (COCOM) next-generation security architecture

ClearPass NAC and Posture Assessment for Campus Networks

ARUBA AIRWAVE. Management and monitoring for multi-vendor campus networks DATA SHEET CONNECTIVITY ANALYTICS REAL-TIME MONITORING AND VISIBILITY RAPIDS

ARUBA CLEARPASS NETWORK ACCESS CONTROL

Introducing. Secure Access. for the Next Generation. Bram De Blander Sales Engineer

BYOD: BRING YOUR OWN DEVICE.

With Aruba Central, you get anywhere-anytime access to ensure that your network is up and performing efficiently.

Identity Based Network Access

Security and Control for all Devices on the Access Network

Networks with Cisco NAC Appliance primarily benefit from:

Pulse Policy Secure X Network Access Control (NAC) White Paper

Intelligent Edge Protection

Support Device Access

Aerohive and IntelliGO End-to-End Security for devices on your network

Support Device Access

The Context Aware Network A Holistic Approach to BYOD

HiveManager Local Cloud

The Aruba S3500 Mobility Access Switch

Cisco Exam Implementing Advanced Cisco Unified Wireless Security v2.0 Version: 9.0 [ Total Questions: 206 ]

AIRPLAY AND AIRPRINT ON CAMPUS NETWORKS AN ARUBA AIRGROUP SOLUTION GUIDE

ForeScout ControlFabric TM Architecture

Campus Manager. Out-of-Band Network Access Control for Wired, Wireless and VPN Networks. DataSheet

Reviewer s guide. PureMessage for Windows/Exchange Product tour

ClearPass Design Scenarios

ClearPass QuickConnect 2.0

Question: 1 The NAC Agent uses which port and protocol to send discovery packets to an ISE Policy Service Node?

UCOPIA EXPRESS SOLUTION

UCOPIA EXPRESS SOLUTION

HPE Aruba Focus Areas

ForeScout CounterACT. Configuration Guide. Version 4.3

2012 Cisco and/or its affiliates. All rights reserved. 1

ONE POLICY. Tengku Shahrizam, CCIE Asia Borderless Network Security 20 th June 2013

ClearPass and MaaS360 Integration Guide. MaaS360. Integration Guide. ClearPass. ClearPass and MaaS360 - Integration Guide 1

TECHNICAL NOTE CLEARPASS PROFILING QUICK START GUIDE

ENTERPRISE NETWORKS WLAN Guest Management Software

All of these organizations need a feature-rich, enterprise-grade WLAN that meets a variety of challenges:

NAC Director. Out-of-Band Network Access Control for Wired, Wireless and VPN Networks. DataSheet

Portnox CORE. On-Premise. Technology Introduction AT A GLANCE. Solution Overview

Cisco ISE Ports Reference

ARUBA NETWORKS DESIGNS AND DELIVERS MOBILITY-DEFINED NETWORKS THAT EMPOWER A NEW GENERATION OF TECH-SAVVY USERS

SOLUTION OVERVIEW THE ARUBA MOBILE FIRST ARCHITECTURE

Cisco Exam Questions & Answers

Bring Your Own Design: Implementing BYOD Without Going Broke or Crazy. Jeanette Lee Sr. Technical Marketing Engineer Ruckus Wireless

Forescout. Configuration Guide. Version 4.4

Huawei Agile Controller. Agile Controller 1

Klaudia Bakšová System Engineer Cisco Systems. Cisco Clean Access

GLOBALPROTECT. Key Usage Scenarios and Benefits. Remote Access VPN Provides secure access to internal and cloud-based business applications

Cisco Exam Questions & Answers

ISE Identity Service Engine

Cisco ISE Ports Reference

ForeScout CounterACT. Continuous Monitoring and Mitigation. Real-time Visibility. Network Access Control. Endpoint Compliance.

Aruba Certified Clearpass Professional 6.5

Cisco ISE Ports Reference

SOLUTION OVERVIEW BLUEPRINT FOR THE ALL-WIRELESS WORKPLACE

Cisco NAC Network Module for Integrated Services Routers

What Is Wireless Setup

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Cisco ISE Ports Reference

Huawei Agile Controller. Agile Controller

ForeScout CounterACT Pervasive Network Security Platform Network Access Control Mobile Security Endpoint Compliance Threat Management

The Aruba Mobile Virtual Enterprise for Government. The Next Generation Network Access Architecture for Mobile Technology

Symantec Network Access Control Starter Edition

UCOPIA ADVANCE SOLUTION

ForeScout Extended Module for MobileIron

Cisco Secure Access Control

HP ProCurve Network Access Controller 800

Secure IT consumeration (BYOD), users will like you How to make secure access for smart mobile devices

Symantec Network Access Control Starter Edition

Delivering a Secure BYOD Solution with XenMobile MDM and Cisco ISE

The UCOPIA ADvAnCe SOlUTIOn The UCOPIA express SOlUTIOn

Transcription:

ARUBA CLEARPASS POLICY MANAGER The most advanced policy management platform available The Aruba Policy Manager platform provides role- and device-based network access control for employees, contractors and guests across any multivendor wired, wireless and VPN infrastructure. With a built-in context-based policy engine, RADIUS, TACACS+ protocol support, device profiling and comprehensive posture assessment, onboarding, and guest access options, is unrivaled as a foundation for network security in any organization. For wider security coverage, using firewalls, EMM and other existing solutions, Exchange allows for automated threat protection and workflows to third-party security and IT systems that previously required manual IT intervention. In addition, supports secure self-service capabilities for end user convenience. Users can securely configure their own devices for enterprise use or Internet access. Aruba wireless customers can provide registration of AirPlay-, AirPrint-, DLNA-, and UPnP-enabled devices for sharing. The result is a comprehensive and scalable policy management platform that goes beyond traditional AAA solutions to deliver extensive enforcement capabilities for IT-owned and bring-your-own-device (BYOD) security requirements. KEY FEATURES Role-based network access enforcement for multivendor Wi-Fi, wired and VPN networks. Industry-leading performance, scalability, high availability and load balancing. Intuitive policy configuration templates and visibility troubleshooting tools. Supports multiple authentication/authorization sources (AD, LDAP, SQL db) within one service. Self-service device onboarding with built-in certificate authority (CA) for BYOD Guest access with extensive customization, branding and sponsor-based approvals. Supports NAC, Microsoft NAP, and EMM/MDM integration for mobile device assessments. Comprehensive integration with third party systems such as SIEM, Internet security and EMM/MDM. Single sign-on (SSO) and Aruba Auto Sign-On support via SAML v2.0. Advanced reporting of all user valid authentications and failures. Built-in profiling using DHCP and TCP fingerprinting. Hardware and virtual support for ESXi and Hyper-V appliances. THE CLEARPASS DIFFERENCE The Policy Manager is the only policy solution that centrally enforces all aspects of enterprise-grade mobility and NAC for any industry. Granular network access enforcement is based on a user s role, device type and role, authentication method, EMM/MDM attributes, device health, location, and time-of-day. Offering unsurpassed interoperability, offers extensive multivendor wireless, wired and VPN infrastructure support which enables IT to easily rollout secure mobility policies across any environment. Deployment scalability supports tens of thousands of devices and authentications which surpasses the capabilities offered by legacy AAA solutions. Options exist for small to large organizations, from local to distributed environments.

UNPRECEDENTED SIMPLICITY Centrally-defined policies and enforcement eliminates the need for multiple AAA and policy management systems, which strengthens an organization s overall security architecture. A host of built-in capabilities lets IT quickly adapt to changing network access challenges. is also a valuable security operations and troubleshooting tool that delivers unprecedented visibility to quickly identify network issues, and policy and security vulnerabilities. ADVANCED POLICY MANAGEMENT Employee access Policy Manager offers role-based user and device authentication based on 802.1X, non-802.1x and web portal access methods. Concurrent authentication methods can be used to support a variety of use-cases. Attributes from multiple identity stores such as Microsoft Active Directory, LDAP-compliant directory, ODBC-compliant SQL database, token servers and internal databases across domains can be used within a single policy for finegrained control. Enhanced device profiling A built-in profiling service discovers and classifies all endpoints, regardless of device type or access method wired, wireless or VPN. Contextual data from smart phones and tablets, to IP cameras can be obtained using DHCP, TCP, and other fingerprinting methods to define policies. Device profile changes are dynamically used to modify authorization privileges. For example, if a Windows laptop appears as a printer, policies can automatically revoke or deny access. Access for unmanaged endpoints Unmanaged non-802.1x devices printers, IP phones and other Internet of Things (IoT) can be identified as known or unknown upon connecting to the network. MAC authentication and profiling validate network access privileges and authorization. Secure device configuration of personal devices Onboard provides automated provisioning of any Windows, Mac OS X, ios, Android, Chromebook, and Ubuntu devices via a user driven self-guided portal. Required SSIDs, 802.1X settings and security certificates are automatically configured on authorized devices. Customizable visitor management Guest simplifies workflow processes so that receptionists, employees and other non-it staff to create temporary guest accounts for secure Wi-Fi and wired Internet access. Self-registration, sponsor and bulk credential creation supports any guest access need enterprise, retail, education, large public venue. Device health checks OnGuard, leveraging OnGuard persistent and dissolvable agents or Microsoft NAP, performs advanced endpoint posture assessments over wireless, wired and VPN connections. OnGuard health-check capabilities ensure compliance and network safeguards before devices connect. ADDITIONAL POLICY MANAGEMENT CAPABILITIES Integrate with security and workflow systems Exchange interoperability includes REST-based APIs and forwarding of syslog data flows that can be used to facilitate workflows with MDM, SIEM, firewalls PMS, call centers, admission systems and more. Context is shared between each component for end-to-end policy enforcement and visibility. Connect and work apps are good to go Auto Sign-On capabilities make it infinitely easy to access work apps on mobile devices. A valid network authentication automatically connects users to enterprise mobile apps so they can get right to work. Single sign-on (SSO) support works with Ping, Okta and other identity management tools to improve the user experience to SAML 2.0-based applications.

SPECIFICATIONS Policy Manager Appliances The Policy Manager is available as hardware or a virtual appliance that supports 500, 5,000 and 25,000 authenticating devices. Virtual appliances are supported on VMware ESX/i and Microsoft Hyper-V. ESX 4.0, ESXi 4.1, up to 5.5 Hyper-V 2012 R2 and Windows 2012 R2 Enterprise Virtual appliances, as well as hardware appliances, can be deployed within an active/active cluster to increase scalability and redundancy. Platform Built-in AAA services RADIUS, TACACS+ and Kerberos Web, 802.1X, non-802.1x, RADIUS authentication and authorization Advanced reporting, analytics and troubleshooting tools External captive portal redirect to multivendor equipment Interactive policy simulation and monitor mode utilities Multiple device registration portals Guest, Aruba AirGroup, BYOD, un-managed devices Deployment templates for any network type, identity store and endpoint Admin/Operator access security via CAC and TLS certificates IPSec tunnels Supported identity stores Microsoft Active Directory RADIUS Any LDAP compliant directory Any ODBC-compliant SQL server Token servers Built-in SQL store, static hosts list Kerberos RFC standards 2246, 2248, 2548, 2759, 2865, 2866, 2869, 2882, 3079, 3576, 3579, 3580, 3748, 4017, 4137, 4849, 4851, 5216, 528, 7030 Internet drafts Protected EAP Versions 0 and 1, Microsoft CHAP extensions, dynamic provisioning using EAP-FAST, TACACS+ Information assurance validations FIPS 140-2 Certificate #1747 Profiling methods DHCP, TCP, MAC OUI, Onboard, SNMP, Cisco device sensor Framework and protocol support RADIUS, RADIUS CoA, TACACS+, web authentication, SAML v2.0 EAP-FAST (EAP-MSCHAPv2, EAP-GTC, EAP-TLS) PEAP (EAP-MSCHAPv2, EAP-GTC, EAP-TLS, EAP-PEAP-Public, EAP-PWD) TTLS (EAP-MSCHAPv2, EAP-GTC, EAP- TLS, EAP-MD5, PAP, CHAP) EAP-TLS PAP, CHAP, MSCHAPv1 and 2, EAP-MD5 NAC, Microsoft NAP Windows machine authentication MAC auth (non-802.1x devices) Audit (rules based on port and vulnerability scans) Online Certificate Status Protocol (OCSP) SNMP generic MIB, SNMP private MIB Common Event Format (CEF), Log Event Extended Format (LEEF)

Policy Manager-500 Policy Manager-5K Policy Manager-25K APPLIANCE SPECIFICATIONS CPU (1) Dual Core Pentium (1) Quad Core Xeon (2) Six Core Xeon Memory 4 GB 8 GB 64 GB Hard drive storage APPLIANCE SCALABILITY (1) 3.5 SATA (7K RPM) 500GB hard drive (2) 3.5 SATA (7.2K RPM) 1TB hard drives, RAID-1 controller (6) 2.5 SAS (10K RPM) 600GB Hot-Plug hard drives, RAID-10 controller Maximum devices 500 5,000 25,000 FORM FACTOR Dimensions (WxHxD) 16.8 x 1.7 x 14 17.53 x 1.7 x 16.8 17.53 x 1.7 x 27.8 Weight (Max Config) 14 Lbs 18 Lbs Up to 39 Lbs POWER Power consumption (maximum) 260 watts max 250 watts max 750 watts max Power supply Single Single Dual hot-swappable (optional) AC input voltage 100/240 VAC auto-selecting 100/240 VAC auto-selecting 100/240 VAC auto-selecting AC input frequency 50/60 Hz auto-selecting 50/60 Hz auto-selecting 50/60 Hz auto-selecting ENVIRONMENTAL Operating temperature 10º C to 35º C (50º F to 95º F) 10º C to 35º C (50º F to 95º F) 10º C to 35º C (50º F to 95º F) Operating vibration Operating shock Operating altitude * Virtual appliance sizing must match hardware appliance specifications

ORDERING GUIDANCE Ordering the Policy Manager involves the following steps: 1. Determine the number of authenticated endpoints/devices in your environment. Additionally, select optional functionality, such as guests per day, total BYO devices being configured for enterprise use, and total number of computers requiring health checks. 2. Choose the appropriate platform (either virtual or hardware appliance) sized to accommodate the total number of devices and guests that will require authentication for your deployment. ORDERING INFORMATION Part Number Description CP-HW-500 or CP-VA-500 Aruba Policy Manager 500 hardware platform supporting a maximum of 500 authenticated devices CP-HW-5K or CP-VA-5K Aruba Policy Manager 5K hardware platform supporting a maximum of 5,000 authenticated devices CP-HW-25K or CP-VA-25K Aruba Policy Manager 25K hardware platform supporting a maximum of 25,000 authenticated devices Expandable application software* Onboard device configuration and certificate management OnGuard endpoint device health Guest visitor access management Warranty Hardware 1 year parts/labor** Software 90 days** * Expandable application software is available in the following increments: 100, 500, 1,000, 2,500, 5,000, 10,000, 25,000, 50,000 and 100,000. ** Extended with support contract 1344 CROSSMAN AVE SUNNYVALE, CA 94089 1.866.55.ARUBA T: 1.408.227.4500 FAX: 1.408.227.4550 INFO@ARUBANETWORKS.COM www.arubanetworks.com 2015 Aruba Networks, Inc. Aruba Networks, Aruba The Mobile Edge Company (stylized), Aruba Mobilty Management System, People Move. Networks Must Follow., Mobile Edge Architecture, RFProtect, Green Island, ETIPS, ClientMatch, Bluescanner and The All Wireless Workspace Is Open For Business are all Marks of Aruba Networks, Inc. in the United States and certain other countries. The preceding list may not necessarily be complete and the absence of any mark from this list does not mean that it is not an Aruba Networks, Inc. mark. All rights reserved. Aruba Networks, Inc. reserves the right to change, modify, transfer, or otherwise revise this publication and the product specifications without notice. While Aruba Networks, Inc. uses commercially reasonable efforts to ensure the accuracy of the specifications contained in this document, Aruba Networks, Inc. will assume no responsibility for any errors or omissions. DS_PolicyManager_052215