Two NAC models, one estate
Aruba gives you two ways to do network access control. ClearPass Policy Manager is the on-premises policy engine. Cloud Auth is cloud-native and built into Central. They sit at different points on a curve of policy depth against operational effort. Picking the wrong one is expensive to undo. This is how we decide.
What ClearPass is for
ClearPass is the heavyweight. It runs RADIUS and TACACS+. It profiles devices in depth. It handles guest, certificate onboarding, and posture through OnGuard. Its policy engine weighs many attributes at once. You can gate a contractor laptop on ownership, patch state, agent, location and time, then assign a role.
That depth costs operational effort. ClearPass is infrastructure you run, on-premises or virtual. It needs sizing, patching, and someone who knows its policy model. The effort pays off with complex wired 802.1X, strict posture, TACACS+, or in-house authentication. For a simple wireless estate it is more than the job needs.
What Cloud Auth is for
Cloud Auth is delivered inside HPE Aruba Networking Central. There is no policy manager to stand up. It authenticates against Microsoft Entra ID or Google. It uses multi pre-shared key (MPSK) to segment headless and IoT devices without certificates. It profiles clients with the same agentless Client Insights data as Central.
For an organisation whose identity lives in the cloud, it covers most access needs with less to run. You give up depth. The multi-attribute conditional policy and heavy posture work stay with ClearPass.
The decision axes that matter
Strip the feature lists and a few questions settle it.
| If you need… | Lean ClearPass | Lean Cloud Auth |
|---|---|---|
| Policy depth | Complex, multi-attribute, conditional | Clean, IdP-driven, role-based |
| Posture assessment | Yes, via OnGuard | Not the strength |
| Device admin (TACACS+) | Yes | No |
| Identity source | On-prem AD, mixed | Cloud IdP (Entra, Google) |
| Operational overhead | You run the platform | Delivered in Central |
| Air-gapped / in-house auth | Yes | Cloud-dependent |
| IoT / headless segmentation | Profiling + policy | MPSK + Client Insights |
Answer them and the choice is usually clear. The trap is buying ClearPass depth you never operate. The other trap is picking Cloud Auth and hitting a posture or TACACS+ need you waved away.
They can coexist
This is not always one or the other. A large estate can run both. Use ClearPass where depth is needed: complex campus, regulated site, wired 802.1X with posture. Use Cloud Auth where identity is cloud-based and needs are simpler. Give each a clear boundary. Do not run both by accident with overlapping responsibility.
Roles and segmentation
The admission decision matters less than the role assigned with it. NAC decides who and what a device is. That identity drives policy across the fabric. In AOS-10 it feeds dynamic segmentation and NetConductor. A role set at authentication becomes enforcement wherever the traffic goes.
This is where network access control meets identity and Zero Trust. Role accuracy depends on device profiling. The agentless Client Insights data feeds both models.
Profiling accuracy is the quiet dependency
Both models depend on device profiling. Misidentify an IoT device and you block something valid or trust something you should not. Get a clear picture of what is on the network before you choose.
How we'd choose
We start from the requirement. How complex does the policy need to be. Are posture and TACACS+ real needs. Where does identity live. Who will run it. Those answers settle most cases. Then we design the role and segmentation model. Then we confirm profiling is solid enough to trust the roles.
We run network access control on both ClearPass and Cloud Auth. If you are choosing, a short design conversation usually settles it.