HPE Aruba ClearPass – More Than Just a RADIUS Server
Identity has become the network’s new security boundary. Not so many years ago, the firewall was considered the protection against external threats on the Internet. Today, devices connect to the company’s network both within the internal network and from locations outside the company’s control, such as homes, hotels, and other public networks.
It is not enough to simply ensure that a device is connected to one of the company’s internal switches or has the correct password for the wireless network.
Today, there are also many more types of devices connecting to the network. In addition to the computers that were most common a few years ago, there are now mobile devices, printers, cameras, sensors, videoconferencing equipment, and more.
For this reason, it has become important for the network to be able to determine both which devices should be connected and how they may use the network once connected.

This requires an authentication server that can communicate using the RADIUS authentication protocol. It is a standardized protocol for network authentication.
Both Windows NPS and HPE Aruba ClearPass are RADIUS servers. The key difference between the products is the level of control each one provides and the amount of information that can be used to determine access.
What is a RADIUS server?
A RADIUS server is located centrally in the network and verifies all connection attempts before a user or device can connect to the network. These checks are based on the device’s identity, such as a certificate or a username and password. Since certificates are the more secure method, they are preferred. Usernames and passwords require the use of older algorithms and protocols that are no longer considered secure, so these should be avoided.
Some types of devices cannot use certificates; in these cases, authentication is limited to the device’s MAC address the unique address assigned to every device on the network.
Network equipment such as switches and wireless access points, etc., communicates with the RADIUS server every time a connection is established, and the RADIUS server makes a decision on how to handle that connection attempt. Its basic function is to approve or reject the connection. However, in addition to approving connections, the RADIUS server can also control a variety of network parameters, such as which VLAN the client should be placed on.
Windows NPS – a fundamental option in Microsoft environments
Microsoft Windows Server includes a service called Network Policy Server (NPS). It is part of the standard Windows services and requires no license other than the Windows Server license.
For an organization that already uses Windows Server, this means that the initial cost is very low. In a small organization, the service will likely be installed on a server that also handles other services, and in a larger organization, a separate server will be installed at a relatively low cost.
NPS requires Active Directory; without it, the service’s functionality is extremely limited. It is therefore best suited for use in environments where Active Directory serves as the foundation for managing identities for both users and computers. However, there is no good way to manage identities that are not normally found in Active Directory.
In NPS, it is possible to create simple rules that use Active Directory group membership to control which access is granted. However, it is not possible to create more advanced rule sets, and there is no support at all for managing MAC addresses and device types that require MAC authentication. Although MAC addresses can be entered manually in Active Directory, this process is not entirely straightforward to administer.
NPS also lacks the ability to create clusters for redundancy, which means that in order to have redundant servers, configuration must be performed on each server, or replication scripts must be created and maintained.
Troubleshooting is often made more difficult by the fact that logs from login attempts are scattered across more than one server and that, in many cases, the logs are difficult to interpret.
HPE Aruba ClearPass – an access control platform
HPE Aruba ClearPass Policy Manager, hereinafter referred to as ClearPass, is a product developed for network authentication and is one of the most powerful Network Access Control (NAC) solutions on the market.
The absolute greatest strengths of HPE Aruba ClearPass are, first, that the product can collect information from multiple sources—both regarding the device and the user—and, based on this, make a more informed decision about how to grant access. Additionally, ClearPass can integrate with other products, both receiving and sending information. This makes it possible to automate workflows and access rights even in, for example, firewalls. ClearPass can also be integrated with equipment from a wide range of manufacturers.
In addition to its core functionality as a RADIUS server, ClearPass includes an integrated feature for managing guest access. It can create temporary guest accounts for visitors, and the pages that visitors see are hosted in ClearPass.
Greater control over users and devices
While NPS verifies that the identity is correct, HPE Aruba ClearPass goes a step further and can also include other information about the device, the user, the location, and more.
Using a feature that identifies the type of device connecting, ClearPass can grant access only to trusted users on a specific type of device, or differentiate access for the same user based on the device from which the access is made.

Through automatic device type identification, even IoT devices that cannot use certificates can be managed by applying rules that identify a specific type of device—such as video conferencing equipment from Crestron—and granting them access without having to manually enter each device’s MAC address.
Clearer and More Flexible Policy Management
In a small environment, NPS can do a good job. Provided that the requirements aren’t too demanding and that all clients are in Active Directory. However, as the environment becomes more heterogeneous—with more client types and increasing demands for various forms of integration with the rest of the network infrastructure and surrounding management systems—a more capable RADIUS server is also required.
This is where HPE Aruba ClearPass fits in naturally, by offering a management interface that is common to an entire cluster of servers. Both policy management and log management are presented in a single interface where all information from every server is handled. These servers can be located in different geographic locations and handle very large volumes of authentication requests.
In environments where users and clients are managed in Entra ID and Intune, for example, these services can be used to authorize devices.
In large organizations, it is desirable to standardize the configuration of switches. It is also advisable to use dynamic configuration of switch ports based on the “colorless ports” concept. This means that no static information is associated with each switch port— For example, which VLAN it belongs to, etc.—instead, all that information is assigned dynamically by the RADIUS server.
Better support for guests, consultants, and private entities
NPS does not include any features for managing guests on the guest network. As mentioned above, HPE Aruba ClearPass also offers a guest solution where both the administration of guest accounts and the web pages that guests see are managed by ClearPass. These web pages can be customized to match the company’s visual identity with the correct colors, images, etc.
Guest accounts can be created in several different ways, the most common of which are:
- Self-registration. This means that the guest connects to the guest network and is directed to a page where they typically enter their name, email address, and possibly some additional information. A guest account is then created for a specific period of time—usually for the current day.
- Self-registration with approval. The process is very similar to the one described above, but the guest also specifies who the host is. That person receives an email with information about the guest and a request to approve access to the guest network.
- Integration with a visitor management system. Through an API integration with an existing visitor management system at the front desk, a guest account is automatically created when a guest registers their visit. The password is either sent via email or printed on a visitor badge.
Accounts with different validity periods can be created if certain guests, such as consultants, need access for longer periods.
Troubleshooting, Traceability, and Reporting
NPS logs contain important information but can be difficult to interpret for someone who does not work with them on a regular basis. Furthermore, in an environment with more than one server, it is difficult to track the logs, as authentication attempts may have been logged on more than one server.
The HPE Aruba ClearPass interface consolidates authentication attempts from all servers in the cluster into a single view. The information is also formatted in a way that makes it easier to interpret than the information available in NPS.
This simplifies troubleshooting if a user or device cannot connect as expected.
Scalability, availability, and mission-critical operations
As mentioned, NPS does not synchronize configurations across servers, which means that every update must be performed on each server. This often leads to errors, and over time, the rule sets on the various servers will not be identical. Alternatively, procedures are needed to replicate the configuration across the servers.
HPE Aruba ClearPass is built from the ground up to operate in a redundant environment where multiple servers share the load and are distributed across multiple geographic locations.
This allows the same set of rules to be implemented across all geographic locations and all parts of the organization with high availability. Different regions serve as redundancy for one another, thereby ensuring very high availability for the authentication service.

Although the same set of rules applies to all servers and locations, it is also possible to create customized rules if there are specific needs at a particular location.
It could be a technology company with operations spread across Europe. However, the company has concentrated its hardware development in two countries, and at those locations, there is a need to manage more types of devices and the ability to assign different VLANs than at the locations where software developers or administrative staff are based. In such a scenario, rules can be created specifically for the locations with special needs.
HPE Aruba ClearPass is well-suited for large organizations with many users, a wide variety of device types, and high traffic on the authentication service.
HPE Aruba ClearPass is available as either physical appliance servers, where extreme capacity is required or where it is not possible to virtualize the servers. Physical servers can also be used to supplement virtual ones.
The virtual servers can run on the most common virtualization platforms, such as VMware, Hyper-V, KVM, and Nutanix. They can also run on AWS and Azure.
When is Windows NPS still a reasonable choice?
NPS can be a cost-effective alternative in small and relatively simple Microsoft environments.
This solution may be sufficient when the organization has few user types, few device types, and limited requirements for dynamic access. NPS may be appropriate when the only requirement is basic RADIUS authentication, such as for a small wireless network or VPN.
At the same time, the organization needs to accept a more limited overview, automation, and device management. The decision should be based on both current needs and expected developments in the coming years.
Summary – That’s Why HPE Aruba ClearPass Is the Better Product
Both NPS and HPE Aruba ClearPass can authenticate users and devices. However, ClearPass offers greater capabilities for both simpler administration and more robust policies. It does this by combining data from multiple sources to inform its decisions.
Implementing ClearPass also makes it easier to manage guest accounts and IoT devices.
For large organizations and in environments with many different types of devices, ClearPass is the best choice. This is because it facilitates the implementation of automated processes, simplified troubleshooting, and the implementation of a standardized set of policies.
Windows NPS primarily answers the question: “Does the user have the correct login credentials?” ClearPass helps the organization answer additional questions: “Who is connecting, what device is being used, is it trusted, and exactly which resources should it have access to?” It is this distinction that makes ClearPass a more robust platform for modern corporate networks.
Om författaren
Jonas Hammarbäck – Nätverksarkitekt på Aranya
Jonas Hammarbäck är nätverksarkitekt på Aranya med lång erfarenhet inom nätverk och IT-säkerhet. Han har djup specialistkompetens inom HPE Aruba Networking, nätverksautentisering och ClearPass och delar regelbundet med sig av sin tekniska kunskap både på Aranya och i HPE Networking Airheads-communityn.
3 främsta aktuella certifieringarna:
HPE Aruba Networking Certified Expert – Network security
HPE Aruba Networking Certified Expert – Campus access architect
Aruba Certified Design Expert (ACDX)










