Before ClearPass we were using the native captive-portal on our Wi-Fi controllers (Aruba) to authenticate users but this was causing httpd daemons to overload the CPU on the controllers. This situation created a denial of service condition on the Wi-Fi which was a major call driver for us.
Network and Systems Specialist at a university with 501-1,000 employees
The interface is a little confusing as is setting up some of the options but this is partially due to the flexibility of the product. There are wizards available to create policy which is helpful.
Pros and Cons
- "Our existing wireless infrastructure is Aruba so it made sense to use their solution for AAA."
- "The licensing model wasn't explained terribly well to us so we vastly under-purchased; this has unfortunately caused us a bit of trouble over the last year."
What is most valuable?
How has it helped my organization?
Before ClearPass we were using the native captive-portal on our Wi-Fi controllers (Aruba) to authenticate users but this was causing httpd daemons to overload the CPU on the controllers. This situation created a denial of service condition on the Wi-Fi which was a major call driver for us.
What needs improvement?
Ability to drill down on items like “System CPU Utilization” or “Device Family” stats from the dashboard. As of right now you need to pick up to 5 items listed on the Dashboard but they seem to be static.
The interface is a little confusing as is setting up some of the options but this is partially due to the flexibility of the product. There are wizards available to create policy which is helpful. We’re primarily using it for RADIUS based AAA for 802.1x Wireless.
For how long have I used the solution?
One and a half years primarily using the Policy Manager module, and one year using the Guest module. No Onboarding use as of yet.
Buyer's Guide
Aruba ClearPass
May 2026
Learn what your peers think about Aruba ClearPass. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,311 professionals have used our research since 2012.
What was my experience with deployment of the solution?
MS AD integration was a bit of a problem at the beginning until our SE realized that the ClearPass servers need to be joined to the domain before AD lookups can be done.
What do I think about the stability of the solution?
I haven't experienced any issues.
What do I think about the scalability of the solution?
I haven't experienced any issues.
How are customer service and support?
Mixed – our current SE does not seem to have much knowledge about configuration of ClearPass and I have been referred to their “ClearPass Expert” on a couple of occasions but I have yet to speak to him/her. Aruba TAC has been able to help the few times I’ve called.
Which solution did I use previously and why did I switch?
Our existing wireless infrastructure is Aruba so it made sense to use their solution for AAA. We did a trial with Win Server 2012 RADIUS and that worked as well, however it does not offer as many options as ClearPass does.
How was the initial setup?
Initial setup was fairly straightforward following the “Start Here” wizard. Our only real “snag” was the Active Directory integration, but that was remedied by our SE.
What was our ROI?
The licensing model wasn’t explained terribly well to us so we vastly under-purchased. This has unfortunately caused us a bit of trouble over the last year. The licensing numbers are based on unique connected authenticating endpoints per day, averaged over 7 days. When we purchased the product we were under the impression that the licensed nodes were concurrent devices, of which we typically see 8000+ in the middle of the day. Our licensing ended up being 19000+ unique devices and we’ve had to put together a cluster of 4 Clearpass nodes to accommodate this.
What's my experience with pricing, setup cost, and licensing?
The licensing model wasn't explained terribly well to us so we vastly under-purchased. This has unfortunately caused us a bit of trouble over the last year. The licensing numbers are based on unique connected authenticating endpoints per day, averaged over 7 days. When we purchased the product we were under the impression that the licensed nodes were concurrent devices, of which we typically see 8000+ in the middle of the day. Our licensing ended up being 19000+ unique devices and we’ve had to put together a cluster of 4 ClearPass nodes to accommodate this.
What other advice do I have?
Tread carefully when estimating the number of unique device nodes for licensing. If using Active Directory for MSCHAPv2 authentication make sure that you add Clearpass to the Windows Domain.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Information Security Specialist at a energy/utilities company with 10,001+ employees
It has eliminate unauthorized access to the corporate network, hence minimizing the threat level.
Pros and Cons
- "There are many features of ClearPass that are worth mentioning -- mainly the extensive support of almost all networking protocols and mobile platforms, the flexibility to integrate with other systems, the debugging and logging facilities, and finally the ability to fully customize web login and payment pages."
- "If the UI is simplified and improved, bugs are minimized, and the support becomes more responsive, it would be perfect."
What is most valuable?
There are many features of ClearPass that are worth mentioning -- mainly the extensive support of almost all networking protocols and mobile platforms, the flexibility to integrate with other systems, the debugging and logging facilities, and finally the ability to fully customize web login and payment pages.
How has it helped my organization?
It has eliminated unauthorized access to the corporate network, hence minimizing the threat level.
What needs improvement?
If the UI is simplified and improved, bugs are minimized, and the support becomes more responsive, it would be perfect.
For how long have I used the solution?
I've used it for two years.
What do I think about the stability of the solution?
There were major bugs that caused us to spend an extensive amount of time for recovering the configurations. Aruba has fixed it upon our request and provided details.
How are customer service and technical support?
It's very good, but not excellent.
Which solution did I use previously and why did I switch?
No, we did not.
How was the initial setup?
It was extremely complex in our heterogeneous, scattered environment. To be able to deploy a NAC solution without causing downtime is a tedious task.
What about the implementation team?
It was a mixed team working together.
What's my experience with pricing, setup cost, and licensing?
Sizing is very important as the licenses of Aruba ClearPass are quite expensive.
What other advice do I have?
Use the DHCP options for a long time to profile all types of devices communicating on a network. Keep ClearPass in monitoring mode and start blocking profiled devices in batch.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Aruba ClearPass
May 2026
Learn what your peers think about Aruba ClearPass. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,311 professionals have used our research since 2012.
Senior Network Administrator at a manufacturing company with 1,001-5,000 employees
It helps us to ensure all sites are compliant with a unified set of standards passed down from our corporate headquarters.
Pros and Cons
- "Providing granular control over which devices are permitted to join our corporate wireless network, as well as in-depth AAA (accounting, in particular) for TACACS+ sessions, is huge."
- "Technical support was not all that great, actually. They are responsive, but oftentimes are VERY reluctant to initiate a screen-sharing session or give in-depth answers."
Valuable Features
The most valuable feature for us it the granular, logic-based nesting of objects which gives highly customizable control over AAA for TACACS+ and RADIUS.
Device profiling for basic/intermediate NAC is also highly useful.
Improvements to My Organization
Providing granular control over which devices are permitted to join our corporate wireless network, as well as in-depth AAA (accounting, in particular) for TACACS+ sessions, is huge. We can refer back to these logs at any time, which are especially useful when we undergo organization-wide audits.
Having a global business presence, CPPM helps us to ensure all sites are compliant with a unified set of standards passed down from our corporate headquarters.
Room for Improvement
- I'd like to see greater ability to customize backups – locations, transfer protocols (SCP/SFTP, etc).
- Small tweaks like scroll bar distances within large Enforcement Policies. More customization for SNMP traps (types), a well as published MIB files so that we can utilize our network monitoring environment more heavily with polling specific aspects of CPPM.
- Hardware requirements for VM templates we use (CP-VA-5K) are, quite frankly, absurd (very high disk storage requirements).
Use of Solution
I've used it for just over three years.
Deployment Issues
I don't recall any issues with deployment.
Stability Issues
I don't recall any issues with stability.
Scalability Issues
I don't recall any issues with scalability.
Customer Service and Technical Support
Technical support was not all that great, actually. They are responsive, but oftentimes are VERY reluctant to initiate a screen-sharing session or give in-depth answers. URL links to knowledge-base articles are very typical for initial answers, which (1) slows resolution, and (2) increases frustration.
It seems, in general, that technical support is more interested in closing new cases than they are in actually solving the root issues. 90% of the questions I’ve had I’ve had solved (for free, mind you, without any maintenance fees) using Aruba’s Airheads online user-based forums.
Initial Setup
The solution was implemented before I gained ownership of it. I'm not sure of the history behind it.
Implementation Team
A local vendor was used.
Other Advice
Do your due-diligence in understanding how the product works before you deploy. CPPM (and many like it – Cisco ISE and ACS) are very complex in the way they are configured and operate.
If you can design the solution before implementation, you have a much better chance of scaling well, easily, and with little down-time as you grow the product throughout its life cycle in your organization.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security/Pre-Sales Consultant at a tech services company with 51-200 employees
Its integration with existing tooling/databases improves efficiency and visibility.
Pros and Cons
- "Security of wired and wireless network increased significantly without any complexity for our user community."
- "How the licenses-in-use counting works in educational environments could be improved."
Valuable Features:
- Open standards-based Networks Access Control, 802.1x
- Excellent API/third party integration module
- Radius server features
- Visibility reporting (see who accessed the network with which device, etc.)
- Onboarding solution for BYOD
Improvements to My Organization:
- Security of wired and wireless network increased significantly without any complexity for our user community.
- Integration with existing tooling/databases improved efficiency and visibility.
- Less components to manage (we phased out MS NPS, Cisco ACS).
- Guest experience improved while "load" on IT lowered.
Room for Improvement:
How the licenses-in-use counting works in educational environments could be improved.
Also, appliance sizing could be improved, as the gaps from 500 to 5,000 and from 5,000 to 250,000 is too large. There should be 2,500 and 10,000 appliances as well.
Deployment Issues:
No issues with deployment.
Stability Issues:
No issues with stability.
Scalability Issues:
No issues of scalability.
Disclosure: My company has a business relationship with this vendor other than being a customer. I'm a Security Consultant/Pre-Sales Consultant working for a Security Network Integrator. Mobility, Network Access Control, NGFW are a few of the solutions I'm specialized in.
Principal Network & Security Engineer at a tech services company with 1,001-5,000 employees
It has automated the bring-your-own-device process through the Onboard feature and posture health check validation through the OnGuard module.
Pros and Cons
- "ClearPass offers a complete NAC solution including standard AAA functions with advanced policy enforcements for multi-vendor wired and wireless networks."
- "Reporting module has room for improvement. It also need integration with SIEM solutions and Next Generation Firewalls."
Valuable Features
ClearPass offers a complete NAC solution including standard AAA functions with advanced policy enforcements for multi-vendor wired and wireless networks.
It has automated the bring-your-own-device process through the Onboard feature and posture health check validation through the OnGuard module, plus it has a robust and customized guest management experience.
Improvements to My Organization
I’ve designed and implemented ClearPass for several enterprises that were looking for a compete NAC and guest management solution. ClearPass was the best fit to address different client requirements and tailor the security access policy based on their needs.
Room for Improvement
Reporting module has room for improvement. It also need integration with SIEM solutions and Next Generation Firewalls.
Use of Solution
We've used it for three years.
Deployment Issues
There are a few issues here and there but they're not worth mentioning.
Customer Service and Technical Support
It's very good.
Initial Setup
It depends on the scenario, but if the use cases and prerequisites were defined correctly before the implementation then it will be easier to implement.
Implementation Team
I started with an in-house implementation and consulted the vendor team when it’s required.
Other Solutions Considered
ClearPass has competitors, but it has kept its leadership position within the Magic Quadrant for the last three years.
Other Advice
I would advise you to at least include ClearPass in any PoC.
Disclosure: My company has a business relationship with this vendor other than being a customer. We are a tier one platinum Partner.
Information Security Assistant Manager at a financial services firm with 1,001-5,000 employees
It checks the health of computers before granting them access to the network.
Pros and Cons
- "This product helps the organization to perform the NAC concept and check the health of computers before granting them access to the network."
- "For ClearPass Insight: it currently has low limits and a lot of use cases couldn’t be applied by the customer which required customization by the Aruba TAC."
What is most valuable?
The most valuable feature is the OnGuard agent which performs posture assessments.
How has it helped my organization?
This product helps the organization to perform the NAC concept and check the health of computers before granting them access to the network.
What needs improvement?
Access Tracker section and ClearPass Insight have rooms of improvements.
For Access Tracker: it would be great if Aruba added more information in the Access Tracker section, such as an endpoint’s IP address, device category, name/description of network device, and SHL name, if any.
For ClearPass Insight: it currently has low limits and a lot of use cases couldn’t be applied by the customer which required customization by the Aruba TAC. This is the thing that consumes the most time and could lead to performance issues for ClearPass Insight.
For how long have I used the solution?
We've used it for two years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
9/10
Technical Support:9/10
Which solution did I use previously and why did I switch?
I didn’t use another solution.
How was the initial setup?
When there are a lot of requirements, the initial setup will be complex, so it depends on the organization’s requirements.
What about the implementation team?
It was through a vendor team, and I would advise anyone going to implement this solution to enable all features during the initial setup and try to get some reference from the vendor in order to contact them and ask them about their experience.
What was our ROI?
For licensing, it depends on the organization’s capacity.
Which other solutions did I evaluate?
I didn’t evaluate another solution.
What other advice do I have?
I would advise you to get support directly from the vendor and not use the partner support.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Professional Services Engineer and Trainer at a tech services company with 51-200 employees
The OnGuard feature checks the compliance of corporate laptops and restricts network access for users who are not compliant with security policies.
Pros and Cons
- "Our TAC is very responsive and very helpful."
- "The OnGuard agent requires some enhancements."
What is most valuable?
Our company provides professional services and we implement the features based on the customer requirement. All the features in ClearPass are good and work the way they need to.
How has it helped my organization?
Based on our implementations for many customers, it seems that they're most interested in the OnGuard feature that checks the compliance of corporate laptops and which restricts network access for users who are not compliant with security policies.
The reporting feature in ClearPass has found devices that are non-compliant had has addressed issues during the initial implementation phase.
Our customers also often request the guest feature, which they find very useful.
What needs improvement?
The OnGuard agent requires some enhancements.
For how long have I used the solution?
We've used it for the last three years.
What was my experience with deployment of the solution?
It works best when you plan deployment according to device behavior while integrated in the network.
What do I think about the stability of the solution?
It's been generally stable.
What do I think about the scalability of the solution?
It scales well in our customer network environments.
How are customer service and technical support?
Our TAC is very responsive and very helpful. They are able to provide solutions for all the new requirements by creating customized SQL queries and configs.
Which solution did I use previously and why did I switch?
I worked initially with Cisco ISE, but I didn't really get to know it well. My company currently provides ClearPass solutions only.
How was the initial setup?
We plan deployments considering all the configuring that needs to be done on the other integrated devices. The setup always ends up smooth and straightforward.
What other advice do I have?
You should test all the requirements during the PoC itself so that the planning and deployment will be smooth.
Disclosure: My company has a business relationship with this vendor other than being a customer. We're a distributor of Aruba and we provide professional services.
i was under wrong impression that WPA2-Enterpsie will perform better than WPA2-PSK Authentication method. this paper says " plain PSK performs better than any
other public key based mechanisms" citeseerx.ist.psu.edu/viewdoc/download
Assistant Manager - Solution Design at a tech services company with 1,001-5,000 employees
It has improved WiFi security and guest on-boarding to our networks, but it needs to be more vendor independent.
Pros and Cons
- "The most valuable feature is the guest on-boarding (BYOD provisioning, centralized access policies, posture assessment, etc.)."
- "The initial setup was quite complex because of the lack of detailed documentation."
What is most valuable?
The most valuable feature is the guest on-boarding (BYOD provisioning, centralized access policies, posture assessment, etc.)
How has it helped my organization?
It has improved WiFi security and guest on-boarding to our networks.
What needs improvement?
It could be more vendor independent.
For how long have I used the solution?
I've used it for one year.
What do I think about the stability of the solution?
I have had issues in regards to the stability.
How are customer service and technical support?
The technical support is satisfactory. However, there is a room for improvement.
Which solution did I use previously and why did I switch?
I did not use any other similar product.
How was the initial setup?
The initial setup was quite complex because of the lack of detailed documentation.
What about the implementation team?
I implemented it in-house. My advice is to first set up the pilot for a small environment and then go all out.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
it_user375078Senior Network Engineer/Mobility Specialist at a tech services company with 51-200 employees
Top 20Real User
I have found technical support to be excellent, but do not be afraid to escalate if you feel you are as proficient or more so than the intial tech.
Buyer's Guide
Download our free Aruba ClearPass Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Network Access Control (NAC)Popular Comparisons
Cisco Identity Services Engine (ISE)
Forescout Platform
Fortinet FortiNAC
ThreatLocker Zero Trust Platform
F5 BIG-IP Access Policy Manager (APM)
ExtremeCloud IQ
Portnox
Sophos Network Access Control
macmon Network Access Control
Ruckus Cloudpath
Ivanti NAC
SecureW2 JoinNow
ExtremeControl
Genian NAC
Impulse Point SafeConnect
Buyer's Guide
Download our free Aruba ClearPass Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Aruba ClearPass and FortiNAC?
- Comparison of Aruba Clearpass, Bradford Networks and Forescout NACs
- What is the biggest difference between Aruba ClearPass and Cisco ISE?
- What are the differences between FortiAuthenticator and FortiNAC?
- Which is better - Aruba Clearpass or Cisco ISE?
- Which vendors provide POCs for Aruba ClearPass in India?
- PRICING FOR FORESCOUT CT10K APPLIANCE
- When evaluating Network Access Control, what aspect do you think is the most important to look for?
- Which is the best choice of Zero Trust Network Access (ZTNA)?
- What is your recommended Network Access Control (NAC) solution for an enterprise?
















You could integrate ClearPass with Palo alto. Checkout doc at support site.