Security

last person joined: 21 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

clearpass appliance

This thread has been viewed 1 times
  • 1.  clearpass appliance

    Posted Nov 12, 2013 09:14 AM

    Hi, i have one question.

     

    I need to have a growth of 100 users,  should purchase a 5k or purchase hardware 2 of 500

     

    Regards,



  • 2.  RE: clearpass appliance

    EMPLOYEE
    Posted Nov 12, 2013 09:36 AM

    How many unique devices will be authenticating?  If it's 500 or less at capacity per day, then the 500 will be fine.



  • 3.  RE: clearpass appliance

    Posted Nov 12, 2013 09:52 AM

    Hi.

    The projection is to have up to 1000 per day.

     

    I can have two appliances scalability 500

     

    Thanks!!!



  • 4.  RE: clearpass appliance

    EMPLOYEE
    Posted Nov 12, 2013 09:54 AM

    No...If all auths are being sent to a single 500 appliance, then I would recommend a 5K instead. 



  • 5.  RE: clearpass appliance

    Posted Nov 12, 2013 09:58 AM

    Ok.

     

    If I have the following scheme:

    One appliance 5K
    2 appliance 500
    License Guest 2500
    A growing need future up to 6000 users just adding licenses, which give me suggestion.

     

    Thanks



  • 6.  RE: clearpass appliance

    Posted Nov 14, 2013 07:49 PM
    That's a lot of guest licensees but then again I'm not sure what type of business you are supporting.

    Keep in mind that active directory authentications or external SQL database do not count as a guest license.


  • 7.  RE: clearpass appliance

    EMPLOYEE
    Posted Nov 14, 2013 11:30 PM

    A couple notes on this.

     

    1. If your expecting a total of 1000 users I would never use two 500. You are are the risk of going over and you now have no room for groth. 
    2. Just like sdr53 mentioned you may have 1000 devices but does that include all of your standard .1x, mac auth, and guests?
    3. f you do use 2 500 CPPMs then you want to make sure you have a proper data retention policy and network design. The publisher is where all the guest will reside and all of the accounting accounting data. If you have a lot of turn over on the guest users you will see quite a bit of accounting packets comming in.