Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Guest Licensing Question

This thread has been viewed 1 times
  • 1.  Clearpass Guest Licensing Question

    Posted Jul 25, 2013 12:48 PM

    I got a question regarding this

    Let say i got 25  Guest license.

     

    If i get a visit during the day of 60 users during that day

     

    During the morning there was 20 guest with expiricy of the time 2 hours

    During the afternoon 20 guest more with expiricy of time 2 hours

    During the night 20 more guest more with expiricy of time 2 hours

     

    So never you will have more than 25 at once

    Is this is a possible scenario?

     

    Or does this count total of guest during the day in this case it willl be 60 and im going over the limit.

     

    Can someone clarify me this?

     

    Cheers

    Carlos

     

     



  • 2.  RE: Clearpass Guest Licensing Question

    EMPLOYEE
    Posted Jul 25, 2013 12:52 PM

    Licensing is calculated on a 7 day rolling average. Sounds like you will never hit your max count.



  • 3.  RE: Clearpass Guest Licensing Question

    EMPLOYEE
    Posted Jul 25, 2013 01:06 PM

    Yes...we enact the 7 day moving average to take care of inevitable peaks and valleys in usage of the system.  In the event that you exceed the 25 limit for a trailing 7 days, the system will do the following:

     

    Each month a licensing management feature within ClearPass monitors the 7-day rolling average as described and if capacity is exceeded, then the current month is flagged as “out of policy”.

     

     

    This will trigger a warning message to the administrator that is displayed on the ClearPass Policy Manager dashboard.

     

    If authentications of guests’ devices continue to exceed 25 devices for 4 months out of a 6 month period the next step is to go beyond the warning message described above and actually lock the administrator out of the Policy Manager GUI.

     

    While users will continue to be authenticated, exceeding the warnings will prevent the administrator from making any policy changes, running any usage reports or troubleshooting any connectivity issues that might arise. 



  • 4.  RE: Clearpass Guest Licensing Question

    Posted Jul 25, 2013 01:10 PM

    Does this mean that i cannot have more than 25 diffenrent visitors per week??

     



  • 5.  RE: Clearpass Guest Licensing Question

    EMPLOYEE
    Posted Jul 25, 2013 01:12 PM

    Yes...sort of.  Guest capacity is tracked by the number of authenticated devices, not by the number of registered guests. The same 7-day rolling average will be used to measure license usage.   

     

    If you consistently exceed the 25 limit, than the above will occur.



  • 6.  RE: Clearpass Guest Licensing Question

    Posted Jul 25, 2013 01:15 PM

    Have not considered putting at least 1 day instead of 7? i mean just think an hotel!...

    If they got 200 rooms

     

    2 devices per user minimum

     

    400

     

    Thats in maybe 2 days

    Let say 6 days

    then i would need 1k at least license... which would be really expensive....

    Is there no way to chang e that 7 day rolling average?

     

    Cheers

    Carlos



  • 7.  RE: Clearpass Guest Licensing Question

    EMPLOYEE
    Posted Jul 25, 2013 01:17 PM

    No...there is no way to change that moving average.  



  • 8.  RE: Clearpass Guest Licensing Question

    EMPLOYEE
    Posted Jul 25, 2013 01:18 PM

    The rolling licensing is designed to account for temporary spikes in usage such as a University hosting a large conference once per year. If the business normally has a certain number of devices, it should be licensed appropriately.



  • 9.  RE: Clearpass Guest Licensing Question

    Posted Jul 25, 2013 01:21 PM

    Well that would be really expensive for an hotel.... you would need at least 1k license... i mean not for even a big hotel... maybe for a 200 or 300 room hotel.



  • 10.  RE: Clearpass Guest Licensing Question

    EMPLOYEE
    Posted Jul 25, 2013 01:25 PM

    Please reach out to your Aruba account manager for pricing.  The product will definitely support what you are looking to do.  The 25 starter licenses are essentially for our customers to run pilots, etc.  At scale, we use licensing options based on the application.  This isn't unique to Aruba.



  • 11.  RE: Clearpass Guest Licensing Question

    Posted Jul 25, 2013 01:30 PM

    Another question

    Let say that i got a user which comes monday, then wednesday and then thurdsay wiht the same device... that would count just as 1 not as 3 devices

     

    Cheers

    Carlos



  • 12.  RE: Clearpass Guest Licensing Question

    EMPLOYEE
    Posted Jul 25, 2013 01:32 PM

    @NightShade1 wrote:

    Another question

    Let say that i got a user which comes monday, then wednesday and then thurdsay wiht the same device... that would count just as 1 not as 3 devices

     

    Cheers

    Carlos


    Correct...that is my understanding



  • 13.  RE: Clearpass Guest Licensing Question
    Best Answer

    EMPLOYEE
    Posted Jul 25, 2013 02:39 PM

    Guest uses a daily reset model. If you have 1 appliance and use the starter bundle (25 licenses) all for guest, you can authenticate 25 unique MAC addresses per day that are connected by guests (we support bursting so that if you have not purchased the right level of licenses, users are not denied access). The next day you may see some of the same MAC addresses and new ones. If you stay under or at 25 authentications you have enough licensing (again bursting is supported). 

     

    The problem starts when you consistently see 30/40/90 authentications per day over 3 months. Then it's time to buy the next level license bundle.

     

    Trent

    ClearPass Product Management



  • 14.  RE: Clearpass Guest Licensing Question

    Posted Jul 25, 2013 02:46 PM

    So this is per day NOT per week ?

     

    Cheers

    Carlos



  • 15.  RE: Clearpass Guest Licensing Question

    EMPLOYEE
    Posted Jul 25, 2013 03:06 PM

    Guest is special, the MAC addresses refresh per day. You end up with a weekly view so that you can see a daily average though.  We understand that in guest environments users come and go on a much quicker basis than in the enterprise itself.

     

    The policy manager tracks the unique MAC addresses that it sees on a daily basis, but the refresh is weekly. 

     

    Trent