12.07.2015 Views

Aruba ClearPass Access Management System ... - Mayflex

Aruba ClearPass Access Management System ... - Mayflex

Aruba ClearPass Access Management System ... - Mayflex

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

AP-120 SERIES CONFIGURATIONCLEARPASS ACCESS MANAGEMENT SYSTEM – FREQUENTLY ASKED QUESTIONSMicrosoft NPS No support for captive portals Only supports AD as an auth source (no SQL, no LDAP, no Token server, etc.) No context-based policies. <strong>Access</strong> can only be grated on identity - not location,device, time of day, etc. Only VLAN-based enforcement – Limited VSAs and no downloadable ACLs,TACACS+, or web-based enforcement Limited windows-only health checks with NAP NO VM deployment option13. I already have Active Directory to authenticate users, why would I need this?In order to satisfy the many of today’s usage scenarios while increasing the level ofsecurity provided, an identity based policy management system would be the bestapproach. A full featured solution like <strong>Aruba</strong>’s can provide many more capabilities toimprove overall security and offload your IT staff from having to manage many aspects ofaccess control, guest management and helpdesk activities.14. I already have a NAC solution and want to use <strong>ClearPass</strong> for provisioning devices. Whatcan I do?For <strong>ClearPass</strong> Onboard the NAC solution would first scan the device for vulnerabilities andonly pass validated clients to <strong>ClearPass</strong> Onboard for provisioning.<strong>ClearPass</strong> QuickConnect can be used to configure devices prior to connecting to 802.1Xnetworks. The existing NAC solution would then perform a basic health check once thedevice authenticates onto the network.15. Will <strong>ClearPass</strong> work for users that connect to public cellular networks?Yes, for clients that use VPN clients such as <strong>Aruba</strong>’s VIA client, a mobile device will alwaysredirect enterprise data back to the enterprise network and be subject to policies definedfor that network.In the case of <strong>Aruba</strong>’s VIA client, the VPN session is setup automatically, without requiringthe user to initiate. This is very important as many devices today that have both Wi-Fi andcellular capabilities will tend to roam between the two networks without alerting theuser.16. Is <strong>ClearPass</strong> NAC? Is it competitive for NAC opportunities?While the definition for Network <strong>Access</strong> Control varies, <strong>ClearPass</strong> can be considered a NACoffering. However, unlike traditional point NAC solutions, <strong>ClearPass</strong> brings together role-ARUBA NETWORKS CHANNEL PARTNER CONFIDENTIAL – DO NOT DISTRIBUTE PAGE 12

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!