Articles

What Is Aruba ClearPass? How HPE's NAC Platform Works

Julia Ciarlone Julia Ciarlone
17 minute read

Table of Contents

If you've searched for "Aruba ClearPass" hoping for a straight answer, here's one: it's the policy management platform Aruba, now part of HPE, built to decide who and what gets onto your network, and under what conditions. You'll find it running quietly behind the scenes at organizations that need more than a shared Wi-Fi password to keep their network secure. This guide covers what it does, how it works, and how to tell if it's worth adding to your own network.

What Is Aruba ClearPass?

Aruba ClearPass is a network access control (NAC) platform. In plain terms, that means it sits between a device trying to connect and your actual network, checking who's connecting, what they're connecting with, and whether that combination should be trusted, before any traffic gets through. It's built for exactly the situation most networks are in today: a mix of company laptops, personal phones, contractor devices, and a growing list of connected hardware, all trying to join the same network.


Instead of treating every connection the same way, ClearPass makes three decisions every time a device shows up: who is this, what are they using, and does this specific combination earn access, and if so, how much. That's the difference between a network that just lets devices on and one that actually controls what happens next. The rest of this guide walks through how that works in practice.

From Aruba ClearPass to HPE Aruba Networking

If you're wondering who actually owns ClearPass today, the short answer is HPE. HPE acquired Aruba Networks in 2015, and ClearPass is now officially branded as HPE Aruba Networking ClearPass Policy Manager, though most IT teams (and Hummingbird Networks' own product listings) still just call it Aruba ClearPass. That's a naming update, not a sign the product is being phased out. It's an active, currently sold product line with ongoing releases.

The Problem Aruba ClearPass Solves

Most networks today are carrying more than they were originally built for. Employee laptops and phones, BYOD devices, contractor laptops, guest devices, and a steadily growing list of IoT gear (badge readers, cameras, sensors) are all trying to connect to the same network, often faster than an IT team can manually track and approve each one. That growth usually happens gradually, one device request at a time, until the network is carrying far more variety than it was built for.


Without something deciding what's allowed on and under what conditions, an unmanaged or compromised device can sit on the same network as your servers, file shares, and point-of-sale systems with no real oversight. That's the gap ClearPass exists to close: an automated system that identifies, evaluates, and controls every device before it's trusted, instead of relying on a shared password and hoping for the best. The next section walks through exactly how it does that.


Picture a single networked security camera with outdated firmware, sitting on the same subnet as everything else. On a flat, unmanaged network, that one weak device is a way in. With ClearPass in place, that camera gets identified as a camera, assigned a policy scoped to only what it needs (video traffic to a recording server, nothing else), and flagged if its posture falls out of line.

How Aruba ClearPass Works

Every time a device tries to connect, ClearPass runs it through the same three-stage sequence: identify what's connecting, apply the right policy, and check whether the device is actually healthy enough to trust. Based on all three, it grants full access, restricts access to specific resources, or blocks the connection outright. The three H3 sections below walk through each stage on its own.


This isn't a one-time gate at login. ClearPass keeps reassessing throughout a session, so a device that passes its initial check but later fails a health requirement (say, its antivirus goes out of date mid-session) can be automatically restricted without anyone at IT having to notice and intervene manually. That ongoing check is what makes this an access control system, not just a login screen.

Identifying Every Device That Connects

Before ClearPass can make any policy decision, it needs to know what's actually connecting. It profiles each device using a combination of passive network signals and active queries, building a real inventory of device type, model, and operating system rather than treating every connection as an unknown. That inventory is what makes every later decision possible.

Enforcing Role-Based Access Policies

Once a device is identified, ClearPass applies a policy based on who the user is, what role they hold, what device they're using, and where and when they're connecting from. The result is a specific, scoped level of access, a finance manager's laptop and a guest's phone don't get treated the same way, instead of an all-or-nothing decision at the door. Those policies live in one place, so a change to how a role is treated applies everywhere that role shows up.

Checking Device Health Before Granting Access

Before or during a session, ClearPass can check whether a device actually meets your minimum security bar: current antivirus, up-to-date patches, required security agents installed. A device that fails one of those checks can be automatically restricted or disconnected. ClearPass also integrates with third-party firewalls, MDM and EMM platforms, and SIEM tools, so those health checks and policy decisions can factor into (and pull from) security systems you already run.

Key ClearPass Modules and Features

ClearPass isn't one single tool. It's a policy manager core plus a set of purpose-built modules that handle specific jobs, and understanding those modules is the fastest way to understand what the platform can actually do for your network. Each one plugs into the same core policy engine, so adding a module doesn't mean starting from scratch on configuration.


Not every organization needs every module. Some only need the core Policy Manager and OnGuard for endpoint health checks. Others, especially BYOD-heavy environments or organizations that host a lot of guests and visitors, add OnBoard and Guest on top. The five modules below are the practical building blocks IT teams mix and match based on what their network actually needs.

ClearPass Policy Manager

This is the core platform, the central engine where every access policy gets defined and where every authentication and authorization decision actually runs. It's managed through a web-based interface, so day-to-day configuration and troubleshooting don't require dropping into a command line. It also keeps a running log of every access attempt, successful or failed, which gives IT a real audit trail to check when something needs investigating instead of a gap in the record.

ClearPass OnGuard

OnGuard is the endpoint posture module. It checks a device's health, antivirus status, OS patch level, required software, before and during a session, and it's the module carrying out the health checks described earlier in this guide. It can run these checks two ways: through a small agent installed on managed devices, or agentlessly for devices that can't run one, so a health check doesn't depend on every device being company-owned.

ClearPass OnBoard

OnBoard handles BYOD provisioning. Instead of IT manually configuring every personal device that shows up, employees can self-register their own devices through a portal, and OnBoard issues each one a unique certificate rather than relying on a shared password. That cuts down real, repetitive IT ticket volume for device setup. It also means revoking one employee's access after they leave doesn't mean resetting a password everyone else shares too.

ClearPass Guest

Guest manages network access for visitors and contractors. It supports customizable, branded captive portals, sponsor approval workflows, and credentials that can be set to expire automatically. A sponsor approval workflow lets a specific employee, not IT, approve a visitor's access directly, which keeps guest onboarding moving without adding to IT's queue. If a guest device is reported lost or stolen, IT can revoke its access immediately. For the broader concept of keeping guest traffic separate from your internal network, see Hummingbird Networks' guide to separating guest Wi-Fi from your internal LAN.

ClearPass Device Insight

Device Insight is the profiling and discovery layer, and it earns its keep specifically around IoT. Using both passive traffic analysis and active fingerprinting, it can classify devices that can't run an agent at all, a networked camera or a badge reader, for example, so they still get assigned an appropriate policy instead of sitting on the network as an unknown. It also improves its own accuracy over time as it profiles more devices, which matters as new device types keep showing up. For a primer on what counts as IoT gear on a modern network, see Hummingbird Networks' guide to what IoT is and how it works.

How ClearPass Supports BYOD and Guest Access

For BYOD, OnBoard handles the whole flow end to end. An employee connects a personal device, self-registers through a portal, and gets a unique certificate instead of a shared password, which means IT isn't manually provisioning every phone and laptop that shows up one at a time. The whole process usually takes a few minutes on the employee's side, and it doesn't require an IT ticket to get started.

Guest access works the same way through the Guest module. A visitor or contractor gets a time-boxed account through a branded captive portal, and that access can be set to expire automatically or get revoked immediately if a device is reported lost. That combination, self-service setup plus fast revocation, is what turns guest and BYOD access from a manual chore into something that mostly runs itself.

Deployment Options for Aruba ClearPass

ClearPass isn't locked into one deployment model, so a small single-site business and a distributed multi-site organization can both run it without being forced into the same infrastructure choice. Your existing infrastructure, and how much of it you want to own directly, usually decides which option fits. None of the three options below change what ClearPass does, only where and how it runs. Many ClearPass deployments also pair with Aruba wireless access points and controllers, which enforce that same policy right at the network edge where devices actually connect.

The three options below run from most hands-on to least, so you can weigh infrastructure ownership against control over where policy decisions get made. It's also worth revisiting as your network grows. A deployment model that fit a single site doesn't always fit once a business adds a second or third location.

Hardware Appliance

A dedicated physical appliance running ClearPass on-site is the traditional deployment model, built for organizations that want policy decisions made entirely on infrastructure they own and control directly. It's a common choice for organizations with strict data-residency requirements or a preference for keeping every policy decision on hardware inside their own building. If you're evaluating specific appliance models, confirm current availability first, since several older ClearPass hardware generations have moved through end-of-sale cycles over the years.

Virtual Appliance

ClearPass can also run as a virtual machine on infrastructure you already have. This is a common choice for organizations that already run a virtualized data center and don't want to rack new dedicated hardware just for network access control. It also scales more easily than a physical appliance. Adding capacity is a matter of allocating more resources to the virtual machine, not ordering and installing another physical box.

Cloud-Hosted Deployment

ClearPass also supports a cloud-hosted deployment for organizations that want policy management without owning the underlying infrastructure at all. That's especially useful for a distributed or multi-site organization that doesn't want a physical appliance sitting at every location. It also shifts patching and platform maintenance onto the hosting provider, which is worth weighing if your team would rather spend its time on other projects than maintaining the policy engine itself.

Aruba ClearPass and Zero Trust Network Access

Under a zero trust model, no device or user gets trusted by default just because it's already sitting on the network. Every connection gets evaluated on its own merits, identity, device health, and context, every time it happens, not just once at login. ClearPass is already doing exactly that each time it identifies a device and checks its health, which is why it fits naturally into a zero trust rollout.

It's worth being precise here: ClearPass is one piece of a zero trust architecture, the access control and policy enforcement layer, not the entire architecture by itself. A full rollout also touches identity management, segmentation, and monitoring, areas ClearPass supports but doesn't replace. For the fuller picture, Hummingbird Networks has a complete guide to Zero Trust Network Access that walks through the rest of it.

Aruba ClearPass Licensing: What to Know Before You Buy

ClearPass licensing is modular, which is good news and a real planning consideration at once. Cost depends on which modules you actually need (Policy Manager, OnGuard, OnBoard, Guest, Device Insight), how many endpoints or users you're licensing, and your term length. Two organizations both running ClearPass can end up with very different bills depending on which pieces they've turned on.

That variability is exactly why you won't see a single number quoted here. Actual licensing needs may vary based on deployment size and features used. None of ClearPass's modules are optional once you actually need their functionality, so it's worth mapping out which ones your network requires before you start pricing anything out. If you want a sense of how Aruba structures licensing more broadly, Hummingbird Networks' Aruba Central licensing explainer covers the same modular approach on a sibling product.

Who Aruba ClearPass Is Built For

ClearPass isn't the right fit for every network size. It's built for organizations with real device diversity and enough scale that manually tracking and approving every connection has stopped being realistic. A very small, simple network usually doesn't need it yet, and that's fine; the platform earns its keep once complexity actually shows up.

In practice, that tends to mean one of two situations, and they don't always look alike from the outside. One is about sheer device count and variety piling up in a single, growing network. The other is about the same access-control problem spread thin across multiple sites instead of concentrated in one place. Both point back to the same underlying issue: manual, one-off device approval that stops scaling once a network passes a certain size or spread.

Growing SMB Networks With Multiple Device Types

A growing SMB juggling employee laptops, BYOD phones, and a rising count of IoT devices, cameras, sensors, badge readers, eventually hits a point where manually tracking every connected device stops scaling. Adding a spreadsheet or a second person to manage device approvals is a stopgap, not a fix. That's the point where a platform like ClearPass starts paying for itself in time saved, not just in security posture.

Multi-Site and Distributed Organizations

An organization running several locations with one dedicated IT person, or none on-site at some locations, benefits from centralized policy management. Set a policy once, and it applies consistently everywhere, instead of getting reconfigured location by location every time something changes. That consistency matters most when something needs to change fast, like restricting access after a security incident, since there's one place to make the change rather than a list of sites to update one at a time.

ClearPass ComponentPrimary PurposeBest Fit
Policy ManagerCentralizes authentication, authorization and access policiesOrganizations needing consistent network access control
OnGuardChecks endpoint security posture and device healthNetworks with endpoint compliance requirements
OnBoardAutomates BYOD enrollment and certificate provisioningBusinesses supporting employee-owned devices
GuestManages visitor and contractor network accessOffices with frequent guests, vendors or contractors
Device InsightProfiles and identifies connected devicesNetworks with IoT, cameras, sensors and other unmanaged devices

How Aruba ClearPass Compares to Other NAC Options

If you're comparing NAC platforms, you deserve an honest answer, not a sales pitch for ClearPass over everything else. Here's where it actually sits relative to two common alternatives. Both comparisons below focus on practical differences that actually affect a purchase decision, not just feature checklists.

In practice, the right choice usually comes down to what your network already runs and how much on-site infrastructure your team wants to manage, more than any one platform being objectively better than another. Cost matters too, but it's rarely the deciding factor once you're comparing platforms at this level, since all three options in this comparison require a real licensing investment. What usually settles it is which tradeoffs your team is actually equipped to live with day to day. If your network already runs Meraki gear, Hummingbird Networks' look at how Meraki handles NAC is worth reading alongside this comparison.

Aruba ClearPass vs. Cisco ISE

Both are enterprise-grade, on-premises-capable NAC platforms with deep feature sets, and both support similar core functions: device profiling, role-based policy enforcement, and posture checking. For most SMBs, the practical difference comes down to which vendor ecosystem you're already standardized on. Aruba and HPE networking gear pairs naturally with ClearPass, Cisco gear with ISE, plus each platform has its own administrative learning curve worth factoring in.

Aruba ClearPass vs. Cloud-Native NAC Platforms

Newer cloud-native NAC options trade some on-premises control for lower administrative overhead and faster setup. ClearPass leans the other way: deeper control and on-premises or hybrid flexibility, at the cost of more hands-on administration. Switching platforms later isn't free either, since moving an established policy set and certificate infrastructure takes real planning. Neither tradeoff is automatically the right one, it depends on how much control your team wants versus how much time your team has to manage it.

FAQs

What is Aruba ClearPass used for?

It's used to control which devices and users get onto a network and what they can access once they're there. That covers everything from employee laptops and BYOD phones to guest devices and IoT hardware, all evaluated and granted access based on identity, device health, and policy.

Who owns Aruba ClearPass now?

HPE, following its 2015 acquisition of Aruba Networks. ClearPass is officially branded today as HPE Aruba Networking ClearPass Policy Manager, though "Aruba ClearPass" remains the name most IT teams use.

How much does Aruba ClearPass cost?

It depends on which modules you license, how many endpoints or users you cover, and your term length, so there's no single flat price to quote. Pricing may vary by model, license level, and active promotions. The most accurate number comes from mapping your actual device count and required modules against current licensing.

Does Aruba ClearPass support BYOD and guest access?

Yes. The OnBoard module lets employees self-register personal devices with a unique certificate instead of a shared password, and the Guest module handles visitor and contractor access through branded portals with credentials that expire automatically or can be revoked on demand.

How does Aruba ClearPass handle IoT devices?

The Device Insight module profiles devices using passive traffic analysis and active fingerprinting, which matters because many IoT devices, cameras and badge readers among them, can't run a software agent at all. Device Insight can still classify them and assign an appropriate policy instead of leaving them as an unknown on the network.

Is Aruba ClearPass worth it, or should you consider an alternative?

For a network with real device diversity and enough scale that manual access tracking has stopped working, yes, it's a mature, well-supported platform. If your network is small and simple, or your team wants to trade on-premises control for a lighter cloud-native setup, it's worth weighing ClearPass against alternatives like Cisco ISE or a cloud-native NAC platform before committing.

Is Aruba ClearPass Right for Your Network?

Think back to the device mix this guide opened with: employee laptops, BYOD phones, guest devices, and a growing pile of IoT hardware. Once that mix is large enough that keeping track of it by hand has stopped working, ClearPass's module setup and licensing planning stop feeling like overhead and start feeling like the obvious next step. If your network hasn't reached that point yet, that's not a strike against ClearPass, it just means now isn't the moment to take it on.

If it does sound like where you're headed, the harder questions are usually about licensing (which modules do you actually need) and deployment (appliance, virtual, or cloud), not whether ClearPass itself is capable. Getting those two decisions right up front is what keeps a ClearPass rollout from turning into an expensive guessing game later. That's exactly where a second set of eyes helps before you commit to a purchase.


See what a ClearPass deployment or license review could look like on your network. Contact Hummingbird Networks to help review your setup, device mix, and policy gaps to better understand which modules may fit your needs before you buy. 

« Back to Articles