Try our new research platform with insights from 80,000+ expert users
it_user214254 - PeerSpot reviewer
Senior Network Administrator at a manufacturing company with 1,001-5,000 employees
Vendor
Jan 12, 2016
It helps us to ensure all sites are compliant with a unified set of standards passed down from our corporate headquarters.
Pros and Cons
  • "Providing granular control over which devices are permitted to join our corporate wireless network, as well as in-depth AAA (accounting, in particular) for TACACS+ sessions, is huge."
  • "Technical support was not all that great, actually. They are responsive, but oftentimes are VERY reluctant to initiate a screen-sharing session or give in-depth answers."

What is most valuable?

The most valuable feature for us it the granular, logic-based nesting of objects which gives highly customizable control over AAA for TACACS+ and RADIUS.

Device profiling for basic/intermediate NAC is also highly useful.

How has it helped my organization?

Providing granular control over which devices are permitted to join our corporate wireless network, as well as in-depth AAA (accounting, in particular) for TACACS+ sessions, is huge. We can refer back to these logs at any time, which are especially useful when we undergo organization-wide audits.

Having a global business presence, CPPM helps us to ensure all sites are compliant with a unified set of standards passed down from our corporate headquarters.

What needs improvement?

  • I'd like to see greater ability to customize backups – locations, transfer protocols (SCP/SFTP, etc).
  • Small tweaks like scroll bar distances within large Enforcement Policies. More customization for SNMP traps (types), a well as published MIB files so that we can utilize our network monitoring environment more heavily with polling specific aspects of CPPM.
  • Hardware requirements for VM templates we use (CP-VA-5K) are, quite frankly, absurd (very high disk storage requirements).

For how long have I used the solution?

I've used it for just over three years.

Buyer's Guide
Aruba ClearPass
March 2026
Learn what your peers think about Aruba ClearPass. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,976 professionals have used our research since 2012.

What was my experience with deployment of the solution?

I don't recall any issues with deployment.

What do I think about the stability of the solution?

I don't recall any issues with stability.

What do I think about the scalability of the solution?

I don't recall any issues with scalability.

How are customer service and support?

Technical support was not all that great, actually. They are responsive, but oftentimes are VERY reluctant to initiate a screen-sharing session or give in-depth answers. URL links to knowledge-base articles are very typical for initial answers, which (1) slows resolution, and (2) increases frustration.

It seems, in general, that technical support is more interested in closing new cases than they are in actually solving the root issues. 90% of the questions I’ve had I’ve had solved (for free, mind you, without any maintenance fees) using Aruba’s Airheads online user-based forums.

How was the initial setup?

The solution was implemented before I gained ownership of it. I'm not sure of the history behind it.

What about the implementation team?

A local vendor was used.

What other advice do I have?

Do your due-diligence in understanding how the product works before you deploy. CPPM (and many like it – Cisco ISE and ACS) are very complex in the way they are configured and operate.

If you can design the solution before implementation, you have a much better chance of scaling well, easily, and with little down-time as you grow the product throughout its life cycle in your organization.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Security/Pre-Sales Consultant at a tech services company with 51-200 employees
Consultant
Jan 12, 2016
Its integration with existing tooling/databases improves efficiency and visibility.
Pros and Cons
  • "Security of wired and wireless network increased significantly without any complexity for our user community."
  • "How the licenses-in-use counting works in educational environments could be improved."

Valuable Features:

  • Open standards-based Networks Access Control, 802.1x
  • Excellent API/third party integration module
  • Radius server features
  • Visibility reporting (see who accessed the network with which device, etc.)
  • Onboarding solution for BYOD

Improvements to My Organization:

  • Security of wired and wireless network increased significantly without any complexity for our user community.
  • Integration with existing tooling/databases improved efficiency and visibility.
  • Less components to manage (we phased out MS NPS, Cisco ACS).
  • Guest experience improved while "load" on IT lowered.

Room for Improvement:

How the licenses-in-use counting works in educational environments could be improved.

Also, appliance sizing could be improved, as the gaps from 500 to 5,000 and from 5,000 to 250,000 is too large. There should be 2,500 and 10,000 appliances as well.

Deployment Issues:

No issues with deployment.

Stability Issues:

No issues with stability.

Scalability Issues:

No issues of scalability.

Disclosure: My company has a business relationship with this vendor other than being a customer. I'm a Security Consultant/Pre-Sales Consultant working for a Security Network Integrator. Mobility, Network Access Control, NGFW are a few of the solutions I'm specialized in.
PeerSpot user
Buyer's Guide
Aruba ClearPass
March 2026
Learn what your peers think about Aruba ClearPass. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,976 professionals have used our research since 2012.
PeerSpot user
Principal Network & Security Engineer at a tech services company with 1,001-5,000 employees
Consultant
Jan 12, 2016
It has automated the bring-your-own-device process through the Onboard feature and posture health check validation through the OnGuard module.
Pros and Cons
  • "ClearPass offers a complete NAC solution including standard AAA functions with advanced policy enforcements for multi-vendor wired and wireless networks."
  • "Reporting module has room for improvement. It also need integration with SIEM solutions and Next Generation Firewalls."

Valuable Features

ClearPass offers a complete NAC solution including standard AAA functions with advanced policy enforcements for multi-vendor wired and wireless networks.

It has automated the bring-your-own-device process through the Onboard feature and posture health check validation through the OnGuard module, plus it has a robust and customized guest management experience.

Improvements to My Organization

I’ve designed and implemented ClearPass for several enterprises that were looking for a compete NAC and guest management solution. ClearPass was the best fit to address different client requirements and tailor the security access policy based on their needs.

Room for Improvement

Reporting module has room for improvement. It also need integration with SIEM solutions and Next Generation Firewalls.

Use of Solution

We've used it for three years.

Deployment Issues

There are a few issues here and there but they're not worth mentioning.

Customer Service and Technical Support

It's very good.

Initial Setup

It depends on the scenario, but if the use cases and prerequisites were defined correctly before the implementation then it will be easier to implement.

Implementation Team

I started with an in-house implementation and consulted the vendor team when it’s required.

Other Solutions Considered

ClearPass has competitors, but it has kept its leadership position within the Magic Quadrant for the last three years.

Other Advice

I would advise you to at least include ClearPass in any PoC.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are a tier one platinum Partner.
PeerSpot user
it_user359994 - PeerSpot reviewer
it_user359994Co Founder at a tech services company with 51-200 employees
Consultant

You could integrate ClearPass with Palo alto. Checkout doc at support site.

it_user356799 - PeerSpot reviewer
Information Security Assistant Manager at a financial services firm with 1,001-5,000 employees
Vendor
Jan 4, 2016
It checks the health of computers before granting them access to the network.
Pros and Cons
  • "This product helps the organization to perform the NAC concept and check the health of computers before granting them access to the network."
  • "For ClearPass Insight: it currently has low limits and a lot of use cases couldn’t be applied by the customer which required customization by the Aruba TAC."

What is most valuable?

The most valuable feature is the OnGuard agent which performs posture assessments.

How has it helped my organization?

This product helps the organization to perform the NAC concept and check the health of computers before granting them access to the network.

What needs improvement?

Access Tracker section and ClearPass Insight have rooms of improvements.

For Access Tracker: it would be great if Aruba added more information in the Access Tracker section, such as an endpoint’s IP address, device category, name/description of network device, and SHL name, if any.

For ClearPass Insight: it currently has low limits and a lot of use cases couldn’t be applied by the customer which required customization by the Aruba TAC. This is the thing that consumes the most time and could lead to performance issues for ClearPass Insight.

For how long have I used the solution?

We've used it for two years.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

9/10

Technical Support:

9/10

Which solution did I use previously and why did I switch?

I didn’t use another solution.

How was the initial setup?

When there are a lot of requirements, the initial setup will be complex, so it depends on the organization’s requirements.

What about the implementation team?

It was through a vendor team, and I would advise anyone going to implement this solution to enable all features during the initial setup and try to get some reference from the vendor in order to contact them and ask them about their experience.

What was our ROI?

For licensing, it depends on the organization’s capacity.

Which other solutions did I evaluate?

I didn’t evaluate another solution.

What other advice do I have?

I would advise you to get support directly from the vendor and not use the partner support.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user363603 - PeerSpot reviewer
Professional Services Engineer and Trainer at a tech services company with 51-200 employees
Consultant
Jan 3, 2016
The OnGuard feature checks the compliance of corporate laptops and restricts network access for users who are not compliant with security policies.
Pros and Cons
  • "Our TAC is very responsive and very helpful."
  • "The OnGuard agent requires some enhancements."

What is most valuable?

Our company provides professional services and we implement the features based on the customer requirement. All the features in ClearPass are good and work the way they need to.

How has it helped my organization?

Based on our implementations for many customers, it seems that they're most interested in the OnGuard feature that checks the compliance of corporate laptops and which restricts network access for users who are not compliant with security policies.

The reporting feature in ClearPass has found devices that are non-compliant had has addressed issues during the initial implementation phase.

Our customers also often request the guest feature, which they find very useful.

What needs improvement?

The OnGuard agent requires some enhancements.

For how long have I used the solution?

We've used it for the last three years.

What was my experience with deployment of the solution?

It works best when you plan deployment according to device behavior while integrated in the network.

What do I think about the stability of the solution?

It's been generally stable.

What do I think about the scalability of the solution?

It scales well in our customer network environments.

How are customer service and technical support?

Our TAC is very responsive and very helpful. They are able to provide solutions for all the new requirements by creating customized SQL queries and configs.

Which solution did I use previously and why did I switch?

I worked initially with Cisco ISE, but I didn't really get to know it well. My company currently provides ClearPass solutions only.

How was the initial setup?

We plan deployments considering all the configuring that needs to be done on the other integrated devices. The setup always ends up smooth and straightforward.

What other advice do I have?

You should test all the requirements during the PoC itself so that the planning and deployment will be smooth.

Disclosure: My company has a business relationship with this vendor other than being a customer. We're a distributor of Aruba and we provide professional services.
PeerSpot user
it_user659427 - PeerSpot reviewer
it_user659427Senior Network Engineer at a consultancy with 51-200 employees
Top 20Consultant

i was under wrong impression that WPA2-Enterpsie will perform better than WPA2-PSK Authentication method. this paper says " plain PSK performs better than any
other public key based mechanisms" citeseerx.ist.psu.edu/viewdoc/download

See all 5 comments
it_user347781 - PeerSpot reviewer
Assistant Manager - Solution Design at a tech services company with 1,001-5,000 employees
MSP
Nov 29, 2015
It has improved WiFi security and guest on-boarding to our networks, but it needs to be more vendor independent.
Pros and Cons
  • "The most valuable feature is the guest on-boarding (BYOD provisioning, centralized access policies, posture assessment, etc.)."
  • "The initial setup was quite complex because of the lack of detailed documentation."

What is most valuable?

The most valuable feature is the guest on-boarding (BYOD provisioning, centralized access policies, posture assessment, etc.)

How has it helped my organization?

It has improved WiFi security and guest on-boarding to our networks.

What needs improvement?

It could be more vendor independent.

For how long have I used the solution?

I've used it for one year.

What do I think about the stability of the solution?

I have had issues in regards to the stability.

How are customer service and technical support?

The technical support is satisfactory. However, there is a room for improvement.

Which solution did I use previously and why did I switch?

I did not use any other similar product.

How was the initial setup?

The initial setup was quite complex because of the lack of detailed documentation.

What about the implementation team?

I implemented it in-house. My advice is to first set up the pilot for a small environment and then go all out.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user375078 - PeerSpot reviewer
it_user375078Senior Network Engineer/Mobility Specialist at a tech services company with 51-200 employees
Top 20Real User

I have found technical support to be excellent, but do not be afraid to escalate if you feel you are as proficient or more so than the intial tech.

See all 2 comments
it_user184704 - PeerSpot reviewer
Channel System Engineer-MEA at a tech services company with 501-1,000 employees
Consultant
Top 20
Nov 24, 2015
I implemented it to make all authentication centralized and all vLAN assignments automated along with health checks.
Pros and Cons
  • "Aruba Clearpass has a great set of networking securing features and, with its four modules policy manager, guests, onboard, and insight, it will give you the best NAC solution along with AAA, RADIUS, TACACS+ and BYOD features, which will help you to have a robust security on your network."

    What is most valuable?

    Aruba Clearpass has a great set of networking securing features and, with its four modules policy manager, guests, onboard, and insight, it will give you the best NAC solution along with AAA, RADIUS, TACACS+ and BYOD features, which will help you to have a robust security on your network.

    How has it helped my organization?

    Actually with many projects, I implemented it to make all authentication centralized and all vLAN assignments automated along with health checks to make network security much easier.

    For how long have I used the solution?

    We've been using it for over three years.

    What was my experience with deployment of the solution?

    No issues encountered.

    What do I think about the stability of the solution?

    No issues encountered.

    What do I think about the scalability of the solution?

    No issues encountered.

    How are customer service and technical support?

    Customer Service:

    It's excellent.

    Technical Support:

    It's excellent.

    Which solution did I use previously and why did I switch?

    Compared with all NAC vendors, it is the best.

    How was the initial setup?

    It is complex in a good way that gives you full flexibility to do a lot of scenarios.

    What was our ROI?

    It has the best ROI as it will secure all critical data.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Aditya Buditama - PeerSpot reviewer
    System Engineer - Network at PT.Helios Informatika Nusantara
    Real User
    Dec 10, 2023
    Stable product with an efficient dynamic segmentation feature
    Pros and Cons
    • "Aruba ClearPass's most valuable feature is dynamic segmentation."
    • "The platform's API integration could be better. Additionally, its pricing could be affordable."

    What is our primary use case?

    We use the platform to improve network security.

    What is most valuable?

    Aruba ClearPass's most valuable feature is dynamic segmentation. It assigns the right wired or wireless connections to the right user. We don't have to run the process manually.

    What needs improvement?

    The platform's API integration could be better. Additionally, its pricing could be affordable.

    For how long have I used the solution?

    We have been using Aruba ClearPass for three years.

    What do I think about the stability of the solution?

    It is a stable product.

    What do I think about the scalability of the solution?

    It is scalable for a small company.

    How are customer service and support?

    The technical support team could work on a better process while escalating the issues from one engineer to another. Sometimes, we have to explain the issues from the beginning all over again.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup is straightforward and takes two months to complete.

    What's my experience with pricing, setup cost, and licensing?

    The product is quite expensive. I rate its pricing a seven out of ten.

    What other advice do I have?

    I rate Aruba ClearPass an eight out of ten. It has useful technology and good performance. It needs improvement in terms of pricing and support.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. partner
    PeerSpot user
    Buyer's Guide
    Download our free Aruba ClearPass Report and get advice and tips from experienced pros sharing their opinions.
    Updated: March 2026
    Buyer's Guide
    Download our free Aruba ClearPass Report and get advice and tips from experienced pros sharing their opinions.