12.07.2015 Views

Aruba ClearPass Access Management System ... - Mayflex

Aruba ClearPass Access Management System ... - Mayflex

Aruba ClearPass Access Management System ... - Mayflex

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

AP-120 SERIES CONFIGURATIONCLEARPASS ACCESS MANAGEMENT SYSTEM – FREQUENTLY ASKED QUESTIONS11. I already have a RADIUS server. Why would I need to buy <strong>ClearPass</strong> Policy Manager?<strong>ClearPass</strong> Policy Manager is required to run the Profile, Guest, Onboard and OnGuardsoftware licenses. Although there may be some overlap in functionality, the PolicyManager provides policy management functionality not provided by standard RADIUSservers. The Policy Manager can co-exist with existing AAA infrastructure by acting as aproxy if needed. Customers can continue to run the two systems in parallel or canmigrate to <strong>ClearPass</strong> as the primary RADIUS server.12. Why is <strong>ClearPass</strong> Policy Manager better than my existing RADIUS server?Many existing AAA that include RADIUS and TACACS+ servers are legacy platforms wheremany releases have reached their end of life. Examples are Cisco’s ACS and Juniper’s SteelBelted RADIUS. In each case, customers are required to migrate to a new platform ormaintain two separate products. If you have experienced problems or if you areconcerned about continuing support of the existing platform, you should investigate<strong>Aruba</strong> <strong>ClearPass</strong>. In addition, the requirements for AAA and NAC have changeddramatically with the emergence of new demands on access security driven by BYODinitiatives. Legacy platforms are not equipped to deal with this new paradigm. Here aresome of the differences between <strong>Aruba</strong> <strong>ClearPass</strong> and other AAA offeringsCisco ACS Many Releases Discontinued and EOL’d by Cisco No integrated NAC (Posture/health based enforcement) Performance issues when scaling for large deployments Weak multi-vendor network device support Poor reporting functionality Inflexible policy model – trouble supporting multiple auth sources & types Difficult to configure, manage, and deploy No integrated guest management functionJuniper UAC Difficult to install and manage (Customer feedback) Most expensive solution on the market Works best with Juniper devices. Many features are not available in a multi-vendornetwork infrastructure Very basic guest management functionality No built-in endpoint device audit capabilities Must use the UAC Client (former Odyssey client) for advanced health capabilities Limited clustering for single management and scalability No utility for self-provisioning and configuration for user endpointsARUBA NETWORKS CHANNEL PARTNER CONFIDENTIAL – DO NOT DISTRIBUTE PAGE 11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!