Skip to content
Uniqcli

Aruba ClearPass Policy Manager

The multivendor NAC engine behind Aruba's Zero Trust access, hardware, virtual, or GreenLake, sized from 100 to 100,000 endpoints

Overview

HPE Aruba Networking ClearPass Policy Manager is a network access control (NAC) platform that decides who and what gets onto your wired, wireless, and VPN networks, then enforces exactly what they can reach once connected. It is built for security and network teams at federal agencies, SLED organizations, healthcare systems, and enterprises that need one policy engine to authenticate every user and device, profile every endpoint, and apply role-based access, whether the switch underneath is Aruba, Cisco, Juniper, or something else entirely.

ClearPass runs the AAA workload most networks still lack: RADIUS, TACACS+, and RadSec authentication against Active Directory, LDAP, SQL, Kerberos, token servers, Microsoft Entra ID, or Google Workspace, with SAML 2.0 and OAuth2 support for modern identity providers. It ships as the C1000, C2020, or C3010 hardware appliance, or as the Cx000V virtual appliance on VMware, Hyper-V, KVM, AWS, or Azure, and it is licensed by concurrent endpoint count so a 500-seat clinic and a 100,000-endpoint university system both size and pay for exactly what they run.

What separates ClearPass from a generic RADIUS server is what happens after authentication. Device profiling (active scans, passive traffic telemetry, and ClearPass Device Insight's machine-learning classification) identifies printers, cameras, medical equipment, and other IoT that cannot run an agent. OnGuard checks endpoint health before and during a session. Onboard automates certificate-based BYOD enrollment. Guest stands up branded visitor portals. And 150-plus Aruba 360 Security Exchange integrations let a firewall or EDR alert change a device's network access automatically, all without touching the switch it is plugged into.

Request a quote
Aruba ClearPass Policy Manager

A closer look

Aruba ClearPass Policy Manager — view 1
Aruba ClearPass Policy Manager — view 2
Aruba ClearPass Policy Manager — view 3
Aruba ClearPass Policy Manager — view 4

Why Aruba ClearPass Policy Manager

Most breaches start with an unmanaged or over-permissioned device already on the network, and IoT has multiplied the number of things you cannot put an agent on. ClearPass gives security teams one place to authenticate every connection, profile everything attached, and box it into exactly the access its role requires, which shrinks attack surface and gives auditors a clean, certified (FIPS 140-2, Common Criteria) trail. For teams without a dedicated NAC specialist, modular Access/Onboard/OnGuard licensing replaces brittle, port-by-port VLAN work with policy that scales from a single clinic to a hundred-thousand-endpoint campus.

AAA and 802.1X authentication engine

A hardened RADIUS, RadSec, and TACACS+ engine authenticates users and devices against Active Directory, LDAP, SQL, Kerberos, token servers, and certificate stores, so every connection is verified before it is ever trusted.

Agentless, multi-method device profiling

ClearPass fingerprints connecting devices using active scans (Nmap, WMI, SNMP), passive telemetry (DHCP, Netflow, IPFIX, HTTP User-Agent), and ClearPass Device Insight's machine-learning classification, identifying printers, cameras, medical devices, and other IoT that cannot run an agent.

Role-based, identity-driven policy across any vendor

Define access once by role and enforce it consistently on Cisco, Aruba, Juniper, and other multivendor wired, wireless, and VPN infrastructure, so policy follows the user and device instead of being pinned to a switch port or SSID.

Hardware or virtual appliance, your choice

Deploy on the C1000, C2020, or C3010 hardware appliance for dedicated, HPE-supported infrastructure, or run the same ClearPass software as the Cx000V virtual appliance on VMware, Hyper-V, KVM, AWS, or Azure.

FIPS 140-2 and Common Criteria validated

ClearPass carries FIPS 140-2 Level 1 certification and NIAP Common Criteria NDcPPv2.1/NDcPPv2.2e validation, the compliance baseline federal and DoD buyers require before a NAC platform touches CUI or classified networks.

150-plus Aruba 360 Security Exchange integrations

Bidirectional REST API, RADIUS accounting proxy, and Syslog integrations with firewall, EDR, MDM, and SIEM vendors let ClearPass both share device context and act on third-party threat signals to change network access automatically.

What it does

Dynamic Segmentation with Aruba infrastructure

Pair ClearPass with Aruba CX switches, access points, and gateways so traffic lands in the correct segment automatically at connection time, keeping IoT, guest, and contractor traffic away from finance and clinical systems without hand-built VLAN sprawl.

BYOD onboarding (ClearPass Onboard)

A built-in certificate authority issues unique device certificates through a self-guided portal for Windows, macOS, iOS, Android, Chromebook, and Ubuntu, so personal devices enroll without a help-desk ticket, and cloud identity providers like Microsoft Entra ID, Google Workspace, and Okta can drive the enrollment.

Endpoint posture checks (ClearPass OnGuard)

Agentless, dissolvable, and persistent-agent options assess antivirus state, patch level, and configuration before and during a session over wired, wireless, or VPN, then automatically quarantine or remediate endpoints that fall out of compliance.

Guest access (ClearPass Guest)

Branded, mobile-friendly self-registration and sponsor-approval portals deliver credentials by SMS, email, or printed badge, with usage policies and bulk credential creation built in for large public venues, retail, and campus visitor programs.

Wired enforcement without 802.1X (ClearPass OnConnect)

SNMP-based enforcement secures switch ports that cannot run RADIUS-based 802.1X, closing a common gap in older wiring closets and mixed-vendor wired estates.

AI-powered device discovery (ClearPass Device Insight)

A cloud-hosted analyzer ingests communication patterns and behavioral data from on-premises collectors, clusters unknown devices with machine learning, and feeds real-time classification back into Policy Manager for immediate enforcement.

Aruba 360 Security Exchange integrations

REST APIs, a RADIUS accounting proxy, and Syslog ingestion connect ClearPass bidirectionally with 150-plus firewall, EDR, MDM, and SIEM vendors, so a firewall or EDR alert can trigger ClearPass to change a device's access in real time via Change of Authorization.

FIPS 140-2 and Common Criteria certified

ClearPass carries FIPS 140-2 Level 1 certification and NIAP Common Criteria NDcPPv2.1/2.2e validation, the baseline federal agencies and regulated industries look for before a NAC platform touches classified or CUI networks.

The Aruba ClearPass Policy Manager lineup

ClearPass Policy Manager

The core AAA and policy engine: authenticates, authorizes, and enforces role-based, Zero Trust network access on any vendor's wired, wireless, or VPN infrastructure.

RADIUS/TACACS+/RadSec AAA, hardware (C1000/C2020/C3010) or Cx000V virtual appliance, FIPS 140-2 Level 1 and Common Criteria NDcPPv2.1/2.2e certified

ClearPass Onboard

Automates BYOD provisioning with a built-in certificate authority so users securely enroll their own laptops, tablets, and phones without an IT ticket.

Self-service certificate-based onboarding for Windows, macOS, iOS, Android, Chromebook, Ubuntu; integrates with Entra ID, Google Workspace, Okta

ClearPass OnGuard

Endpoint posture assessment over wired, wireless, and VPN connections that auto-remediates or quarantines endpoints violating security or compliance policy.

Agentless, dissolvable, and persistent agent deployment options; continuous posture checks pre- and mid-session

ClearPass Guest

Customizable, branded visitor portals with sponsor approval, bulk credential creation, and usage policies for enterprise, retail, education, and large-venue guest Wi-Fi.

Self-registration, sponsor workflows, credential delivery by SMS, email, or printed badge

ClearPass OnConnect

Extends enforcement to Ethernet ports that cannot run 802.1X, closing a common gap in older or mixed-vendor wired closets.

SNMP-based enforcement for non-802.1X wired switch ports

ClearPass Device Insight

Cloud-hosted, AI-powered device discovery that clusters and classifies unknown endpoints, then feeds classification back into Policy Manager for real-time enforcement.

Machine-learning clustering of behavioral and communication-pattern data from on-premises collectors

C1000 / C2020 / C3010 hardware appliances

Dedicated ClearPass hardware for teams that want the policy engine on HPE-supported infrastructure they control end to end.

C1000 (JZ508A, Unicom S-1200 R4); C2020 (R1V83A, HPE DL360 Gen10); C3010 (R1V82A, HPE DL360 Gen10, 64 GB RAM, RAID-10)

At a glance

Category
Network access control (NAC) / Zero Trust access
Authentication protocols
RADIUS, RADIUS Dynamic Authorization, TACACS+, RadSec, 802.1X-2020, SAML 2.0, OAuth2, WPA3
EAP methods
EAP-TLS, PEAP, TTLS, EAP-FAST, TEAP, PAP, CHAP, MSCHAPv1/v2
Identity sources
Active Directory, any LDAP directory, MySQL/MSSQL/Postgres/Oracle SQL, Kerberos, token servers, Microsoft Entra ID, Google Workspace
Hardware appliances
C1000 (JZ508A), C2020 (R1V83A, HPE DL360 Gen10), C3010 (R1V82A, HPE DL360 Gen10)
Virtual appliance
Cx000V on VMware ESXi, Microsoft Hyper-V, CentOS/Ubuntu KVM, AWS EC2, Microsoft Azure
Licensing
Access license by concurrent endpoints (100 to 100K); perpetual E-LTU or 1/3/5-year E-STU subscription
Certifications
FIPS 140-2 Level 1, NIAP Common Criteria NDcPPv2.1/NDcPPv2.2e, IPv6 Ready (USGv6 r-1)
Device profiling
Active (Nmap, WMI, SSH, SNMP) and passive (MAC OUI, DHCP, Netflow, IPFIX, sFlow, SPAN) methods, plus ClearPass Device Insight ML classification
Ecosystem
150+ certified Aruba 360 Security Exchange integrations (firewall, EDR, MDM, SIEM, IdP)

How to buy Aruba ClearPass Policy Manager

ClearPass is sold as a Platform license plus the modules you need, on hardware you own or as a virtual appliance you deploy on your own hypervisor or cloud account. Government and education buyers typically combine the Access license with Onboard and OnGuard, then layer support and a hardware refresh cadence on top.

Access license (Concurrent Endpoints)

The core RADIUS/TACACS+ policy engine, licensed by concurrent endpoint count: 100, 500, 1K, 2.5K, 5K, 10K, 25K, 50K, or 100K. Available perpetual (E-LTU) or as a 1, 3, or 5-year subscription (E-STU), so a 5,000-seat hospital and a 100,000-endpoint university system both buy exactly the capacity they run.

Hardware appliance (C1000 / C2020 / C3010)

Buy the appliance outright (JZ508A, R1V83A, R1V82A) when you want ClearPass on dedicated, HPE-supported hardware, ideal for regulated environments that require physical control of the policy engine and audit trail.

Virtual appliance (Cx000V)

License the same ClearPass software (JZ399AAE E-LTU) to run on VMware ESXi, Hyper-V, KVM, AWS EC2, or Microsoft Azure, useful for teams standardizing on virtualization or needing to spin up disaster-recovery nodes fast.

Module add-ons: Onboard, OnGuard, Guest

Layer BYOD certificate onboarding, endpoint posture assessment, and branded guest portals on top of the Access license only where you need them, instead of paying for capabilities that sit unused.

GPC, SAP, FAR, GPC direct, and GPC purchasing

As an authorized HPE Aruba Networking reseller, we quote ClearPass via GPC direct, SAP, FAR-based purchase orders, and GSA eBuy for federal and DoD buyers, and we accept GPC card purchases for smaller SLED and agency orders. TAA-compliant configurations are available for Buy American / Trade Agreements Act requirements.

Where it fits

Enforce Zero Trust least-privilege access for employees, contractors, guests, and IoT across one multivendor policy framework
Meet FIPS 140-2 and Common Criteria requirements for NAC on federal and DoD networks handling CUI
Discover and segment unmanaged IoT and OT devices (cameras, sensors, medical, building systems) that cannot run an agent
Stand up secure, self-service guest Wi-Fi with branded portals for higher-ed campuses, hospitals, and public venues
Automate BYOD onboarding with certificate-based enrollment so personal devices connect without an IT ticket each time
Auto-quarantine or remediate endpoints that fail OnGuard health and compliance checks before they can spread risk
Respond to firewall, EDR, or SIEM alerts automatically by changing a device's network access through Change of Authorization

Frequently asked

What is Aruba ClearPass Policy Manager?

ClearPass Policy Manager is HPE Aruba Networking's network access control (NAC) platform. It authenticates every user and device with RADIUS or TACACS+, profiles what is connecting, and enforces role-based, least-privilege access across multivendor wired, wireless, and VPN networks. It is the on-premises and virtual-appliance foundation for Aruba's Zero Trust access story.

What ClearPass hardware appliances are currently available?

The current lineup is the C1000 (JZ508A, up to a few hundred sessions on a compact appliance), the C2020 (R1V83A, HPE DL360 Gen10-based), and the C3010 (R1V82A, also DL360 Gen10-based, for large clustered deployments). All three run ClearPass Policy Manager software and are also available as the Cx000V virtual appliance for VMware, Hyper-V, KVM, AWS, or Azure.

How is ClearPass licensed?

ClearPass uses an Access license metered by concurrent endpoints, from 100 up to 100,000, available as a perpetual E-LTU license or as a 1, 3, or 5-year subscription (E-STU). Onboard, OnGuard, and Guest are separate add-on modules so you only license the capabilities you actually deploy.

Does ClearPass work with non-Aruba switches and access points?

Yes. ClearPass is vendor-neutral and enforces policy using standards like RADIUS, TACACS+, and 802.1X, so it works across Cisco, Aruba, Juniper, and other multivendor wired and wireless infrastructure without requiring an all-Aruba network.

What is the difference between ClearPass and Aruba Central NAC?

ClearPass Policy Manager is the on-premises or virtual-appliance NAC engine you deploy and manage yourself. Central NAC (built on what was previously called Cloud Auth) is a cloud-native NAC delivered through Aruba Central for organizations that want authentication and role assignment handled as a managed cloud service instead. Both integrate with Central NetConductor for policy orchestration, and we can help size which model fits your operations team.

Is ClearPass FIPS and Common Criteria certified?

Yes. ClearPass holds FIPS 140-2 Level 1 certification and NIAP Common Criteria NDcPPv2.1/NDcPPv2.2e validation, which matter directly for federal, DoD, and other regulated buyers evaluating NAC platforms for CUI or classified environments.

What authentication protocols and identity stores does ClearPass support?

ClearPass supports RADIUS, RADIUS Dynamic Authorization, TACACS+, RadSec, 802.1X-2020, SAML 2.0, OAuth2, and EAP methods including EAP-TLS, PEAP, TTLS, and EAP-FAST. Identity sources include Microsoft Active Directory, any LDAP-compliant directory, ODBC SQL databases, Kerberos, token servers, Microsoft Entra ID, and Google Workspace.

How do I get pricing or a quote for ClearPass?

Use our online quote tool at /quote to get pricing on ClearPass hardware, virtual appliances, and Access/Onboard/OnGuard licensing sized to your endpoint count. As an authorized HPE Aruba Networking reseller we quote through GSA MAS (application in progress), SAP/FAR channels, GPC direct, and standard commercial terms, and we accept GPC purchases for smaller orders.

How does ClearPass handle IoT and medical devices that cannot run an agent?

ClearPass profiles unmanaged devices agentlessly using DHCP fingerprinting, active Nmap/WMI/SNMP scanning, and Netflow/IPFIX traffic telemetry, then hands classification to ClearPass Device Insight's machine-learning clustering for anything it cannot immediately identify, before segmenting the device to the access it actually needs.

Works with

ClearPass is the policy engine, not the whole network. It reaches full value paired with the Aruba infrastructure it segments traffic on, the cloud management plane that orchestrates policy at scale, and the adjacent HPE security and consumption offers most ClearPass buyers also need.

Build your HPE bill of materials.

Send us the requirement, the project, or an existing quote to beat. We come back with a validated, TAA-compliant HPE configuration and a real price, often below list.

connect [at] getuniqcli.com · Chicago, IL