12.07.2015 Views

Aruba ClearPass Access Management System ... - Mayflex

Aruba ClearPass Access Management System ... - Mayflex

Aruba ClearPass Access Management System ... - Mayflex

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

AP-120 SERIES CONFIGURATIONCLEARPASS ACCESS MANAGEMENT SYSTEM – FREQUENTLY ASKED QUESTIONS45. Is there a limit on the number of devices the <strong>ClearPass</strong> Policy server can support?There is a range that is designated by the physical characteristics of the <strong>ClearPass</strong> baselineappliance. To support a greater number of devices, customers can purchase additionalappliances to create a cluster that can support very large numbers of devices. Foradditional details and proper sizing of a <strong>ClearPass</strong> server, check the latest <strong>Aruba</strong> pricelist.46. Can the <strong>ClearPass</strong> solution support policies where non-802.1X capable switches exist?Yes. The use of OnGuard agents, or captive-portal registration, allow organizations thatare migrating to more secure 802.1X-capable devices to deploy policy management in aphased manner.Device Profiling/Provisioning Support47. Can <strong>ClearPass</strong> configure iOS, Windows, Android and Mac OS X devices for 802.1X?Yes. <strong>Aruba</strong> <strong>ClearPass</strong> is the only complete configuration, provisioning and onboardingsolution in the industry.48. Once a device has been onboarded is there any software left on the device?No, the <strong>ClearPass</strong> Onboard executable is purely a configurator, it doesn't actuallyauthenticate you and will still need you to have a valid cert and/or user account which canboth be deleted/revoked if an employee leaves a company49. What happens if someone loses a device, like a phone, that has been configured toaccess the secure enterprise network?<strong>ClearPass</strong> identifies each unique device associated with a user and access can be revokedfor that individual device without having to manipulate the user’s AD or LDAP credentials.50. How does <strong>ClearPass</strong> uniquely identify and manage devices?<strong>ClearPass</strong> issues certificates for IOS and OS X Lion devices and unique credentials for eachWindows and Android device associated with a user so that it can take unique action onthat device. This certificate or credential acts as a unique machine ID.Beyond this we inventory devices and embed data about the device that was enrolledwithin the client certificate/credential such as MAC address, UUID, serial number etc.These unique machine IDs are stored securely within the certificate store.51. Is there an option for users to self-register BYOD devices like smartphones or gamingdevices?ARUBA NETWORKS CHANNEL PARTNER CONFIDENTIAL – DO NOT DISTRIBUTE PAGE 24

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!