Dell Networking W ClearPass Access Management System 500
Real-time network access security and endpoint control for BYOD
Sorry, this product is no longer available, Please, contact us for a replacement product!
Overview:
The W-ClearPass Access Management System provides role- and device-based network access control for employees, contractors and guests across any wired, wireless and VPN infrastructure.
- Role-based network access enforcement for Wi-Fi, Wired and VPN networks.
- Industry leading performance, scalability, high availability and load balancing.
- Web-based interface simplifies policy configuration and troubleshooting.
- Supports NAC and Microsoft NAP posture and health checks.
- Single sign-on (SSO) and federated identity via SAML and Okta support.
- Advanced reporting of all user activity, authentications and failures.
- Comprehensive API integration with third-party MDM solutions.
- Device onboarding, profiling, guest access, and compliance reporting all included.
Built-in RADIUS, TACACS+, profiling, onboarding, guest access and health checks – plus the ability to leverage third-party mobile device management solutions – ensure seamless policy enforcement across the entire network.
Centrally-managed network access policies provide the comprehensive authentication capabilities that are required for today's highly mobile workforce, regardless of device type or device ownership.
Automated services let users securely onboard their own devices, register AirPlay- and AirPrint-enabled devices for sharing, and create guest access credentials.
The result is a consistent and scalable network access control solution that exceeds bring-your-own-device (BYOD) and ITmanaged device security requirements.
The Clearpass Difference
The W-ClearPass Access Management System is the only network access control solution that centrally enforces all aspects of BYOD from a single platform. Granular network access privileges are granted based on a user's role, device type, MDM attributes, device health, location, and time-of-day.
Offering unsurpassed interoperability, ClearPass supports an extensive collection of multivendor wireless and wired networking equipment which enables IT to easily rollout BYOD across any infrastructure.
With flexible deployment options, IT can start by providing sponsored guest access and also allow employees to onboard their own devices, and later add device profiling and application management. ClearPass is capable of scaling to support tens of thousands of devices and users.
Unprecedented Simplicity
Centrally-defined policies and enforcement eliminates the need for multiple policy and device management systems, which strengthens an organization's overall security architecture. A host of built-in capabilities lets IT quickly adapt to changing BYOD challenges.
A simple-to-use template-based interface provides an efficient way to create network access and authentication services, regardless of the identity store currently in use, authentication method or enforcement model.
W-ClearPass Access Management System is also a valuable security operations and troubleshooting system that delivers unprecedented visibility to quickly identify network issues, and policy and security vulnerabilities.
Advanced Policy Management
Employee access
The Access Management System provides user and device authentication based on 802.1X, non-802.1X and web portal access methods. Multiple authentication protocols like PEAP, EAP-FAST, EAP-TLS, and EAP-TTLS can be used concurrently to strengthen security in any environment.
Attributes from multiple identity stores such as Microsoft Active Directory, LDAP-compliant directory, ODBC-compliant SQL database, token servers and internal databases can be used within a single policy for fine-grained control.
Additionally, posture assessments and remediation can be added to existing policies at any time.
Mobile device and application management
The ClearPass MDM Connector makes it easy to use attributes collected by third-party MDM solutions to enforce network policies. A device can be denied Wi-Fi access if it is jailbroken, running blacklisted apps or if the owner does not appear in an authorization database.
Handling access for unmanaged endpoints
Unmanaged non-802.1X devices – printers, IP phones and IP cameras – can be identified as known or unknown upon connecting to the network. The identity of these devices is based on the presence of their MAC address in an external or internal database.
Built-in ClearPass profiling ensures that these devices are accurately fingerprinted and match the characteristics on subsequent profiling scans. Policies can be tailored to provide full or limited access to secure resources.
Secure device provisioning
ClearPass with Onboard fully automates the provisioning of any Windows, Mac OS X, iOS, and Android devices via a built-in captive portal. Users are re-directed to a template based interface to provision required SSID, 802.1X settings, and download unique device credentials.
Additional capabilities include the ability for IT to revoke and delete credentials for lost or stolen devices, and the ability to configure mobile email settings for Exchange ActiveSync and VPN clients on some device types.
Customizable visitor management
ClearPass with Guest simplifies workflow processes, allowing receptionists, employees and other non-IT staff to create temporary accounts for Wi-Fi and wired network access.
Once registered, users receive account login credentials via SMS text messages or email. Guest network access accounts can be set to expire automatically after a specific number of hours or days.
Customizable captive portal capabilities let IT and marketing organizations create a branded guest login experience with targeted advertising and user code-of-conduct messaging. Self-registration and automated credential delivery also streamlines IT operations.
Device health checks
ClearPass with OnGuard and separate OnGuard persistent or dissolvable agents perform advanced endpoint posture assessments. Traditional NAC health check capabilities ensure compliance and network safeguards before devices connect. Information about endpoint integrity – such as status of anti-virus, anti-spyware, firewall, and peer-to-peer applications – can be used to enhance authorization policies. Automatic remediation services are also available for non-compliant devices.
Additional Policy Management Capabilities
Built-in device profiling
ClearPass is the only profiling service that discovers and classifies all endpoints, regardless of device type. A variety of contextual data – MAC OUIs, DHCP fingerprinting and other identity-centric device data – can be obtained and used within policies.
Stored profiling data is also used to identify device profile changes and to dynamically modify authorization privileges. For example, if a printer appears as a Windows laptop, Access Management System can automatically deny access.
Extensive captive portal support
The ClearPass solution provides a central captive portal for authentication that works on any multivendor wired and wireless network. This eliminates the need for separate Wi-Fi and wired captive portals.
Also, built-in web-based device registration services let users self-register their devices, such as Apple Bonjour capable devices, game consoles, and other personal devices to automatically capture MAC address, device type and operating system version for IT.
W-ClearPass Access Management System appliances
The W-ClearPass Access Management System is available as hardware or virtual appliances that support 500, 5,000 and 25,000 authenticating devices. Virtual appliances are supported on VMware ESX and ESXi platforms, versions ESX 4.0, ESXi 4.0 and 5.0. Virtual appliances, as well as the hardware appliances, can be deployed within a cluster for scalability and redundancy.
- Pricing and product availability subject to change without notice.