Forescout Technologies headquartered in San Jose actively defends the Enterprise of Things by identifying, segmenting and enforcing compliance of every connected thing. Forescout boasts a widely deployed, enterprise-class platform at scale across IT, IoT, and OT managed and unmanaged devices. Forescout arms customers with device intelligence, in order to allow organizations across every industry to classify risk, detect anomalies and quickly remediate cyberthreats without disruption of critical…
N/A
HPE Aruba Networking ClearPass Policy Manager
Score 9.1 out of 10
N/A
The HPE Aruba Networking ClearPass Policy Manager provides role- and device-based network access control for employees, contractors and guests across multi-vendor wired, wireless and VPN infrastructures.
It was able to relieve us of some of the duties performed by the operations team as it made it easy to do those tasks. It allows us to view devices that are connected to our network and segregate those that are not company owned and also account for guests' logins as are signed …
Better intergration with patch management tools. Forescount Platfform (CounterAct) is easily compatible with diverse network infrastructure to offer better service and efficiently ensure seamless operations. Its automation capabilities have also enabled us to depend less on the …
Forescout Platform (CounterACT) is capable to perform intelligent device classifications which able to group and segmentize the assets effectively. Besides, the classification techniques can be customized according to the organization requirements. With agentless deployment, …
When I got here, they already had this product in place, so I was not part of the final decision, but after using this for a couple of years, I can say that it was an intelligent decision for the business!!
Heterogeneous compatibility with switches and other network infrastructure setup is a major advantage. There are many companies where there is a legacy network combined with different OEM deployed. Integration of network devices like switches, FW, routers, AP's gives complete …
We selected CounterACT because it didn't require 802.1x and it didn't require any switch upgrades. To use 802.1x we would have to assume all endpoints are guilty until proven innocent. With CounterACT we can detect quickly if endpoints are not compliant and remediate without …
CounterACT was the product that was able to do exactly what we were looking to accomplish and that was to block non-company owned devices from connecting to our network based on our criteria. It will allow us to decide if a blocked device should be allowed on our network …
We currently use Microsoft NPS for various certificate and RADIUS authentications. We have found that when properly utilised Aruba ClearPass offers a whole lot more. Microsoft NPS has been the same for a long time, where Aruba ClearPass has implemented features, logging and …
Clearpass provides seamless protection to the enterprise network without the need of many licenses to be procured. Hardware LAN and Wireless are protected from unwanted or unknown visitors to the network. Unlike other vendors, you don't need multiple licenses, one device or …
Much easier to use, FortiNAC which used to be owned by Bradford was difficult to use. Unintuitive menus made it difficult to use and support was almost nonexistent. It may be different now, but we haven't looked back since using Clearpass. Licensing and support costs aren't bad …
Personally. I haven't used other NAC solutions. There are a few I've researched, but have stayed with Clearpass as my solution based on the features and use case for my organization. One large reason for staying with Clearpass is being an Aruba wireless network customer. Having …
From my experience, ClearPass has been the best NAC server of all I've seen. Even though configuration is somewhat hard and it's hard to get training, once you learn how to configure it it works very well. The policies are very granular and scalable and the interface is a …
ClearPass by far is a more versatile system it seems that it has more features and can configure how you want it. Cisco ISE is extremely complicated to deploy where I felt that ClearPass was more straight forward and user-friendly. Clearpass does what Cisco ISE can do and …
I strongly recommend using it in networks where many machines enter, it is essential to have a capture of all ids, mac etc to prevent and detect unauthorized machines.We are in the technological era and there is a lot of technological robotization looking for weak systems to enter.Invest in greater security and that does not happen to you.
We have quite a few visitors to our campus and we don't want to have a set PSK for the wireless so we have configured a guest network where visitors can create an account and gain access to the internet and we don't have to "manage" it since the accounts will expire after a certain time. We have RF scanners in our warehouses and we want them to be allowed on the network and be put into its own VLAN. ClearPass can do this flawlessly by keying off of the MAC address when it comes online and putting it into the correct VLAN. This makes it so we don't have to add each device individually to the system. The only time ClearPass would not be appropriate is in a small deployment where the cost to value wouldn't make sense.
Getting data out of ClearPass is difficult. You can get some with SNMP but he API is lacking. There is only a limited amount of info that you can get from it. Even some data that shows up in ClearPass Insight is not available to import into a 3rd party application.
In the past, if you have hardware/software issues you could troubleshoot them yourself through the CLI in a Linux type interface but now they have locked everything down and it makes troubleshooting difficult. You have to rely on them for everything. As a person who likes to understand the ins and outs of the systems I manage it is somewhat frustrating.
Steep learning curve, although support can assist and their forums like airheads can be helpful. This is a complex system and can take a while to grasp how everything works and integrates.
Though Aruba ClearPass offers a lot of insight and features, it is not the easiest to navigate. A lot of other systems can be figured out as you go, but Aruba ClearPass often requires a lot of research in order to set something up correctly. It's not always easy to find what you're looking for. Once you learn the basics, it becomes a lot more manageable, but it's definitely worth investing in some sort of training.
They are prompt in their response with a complete resolution once they have identified the problem. Other OEM's generally give stop-gap arrangements and then later come with new upgrade versions. This gives downtime tasks to customers often, which isn't appreciated. Given the criticality of this software, their support is prompt.
This product has consistently provided the results needed from it and when issues arose, Aruba TAC was able to provide support effectively. In the previous question, I stated that Aruba Wireless is used as well. With those systems in place with ClearPass troubleshooting becomes much easier. I am sure other issues may arise if calling support while using another vendor for wireless such as Cisco, Juniper, etc.
CounterACT was the product that was able to do exactly what we were looking to accomplish and that was to block non-company owned devices from connecting to our network based on our criteria. It will allow us to decide if a blocked device should be allowed on our network temporarily
Clearpass provides seamless protection to the enterprise network without the need of many licenses to be procured. Hardware LAN and Wireless are protected from unwanted or unknown visitors to the network. Unlike other vendors, you don't need multiple licenses, one device or cloud setup will get you going to manage and monitor your network
Set and forget. It made a positive contribution in terms of labor and cost without needing much technical support. Since NAC and TACACS features come together, you can meet your needs with a single license.
The number of supporting companies may be limited in the country you are affiliated with. Therefore, agreements with third-party companies are expensive and your support requests may take a long time.